<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=selfhosting+codecov+with+gitlab%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 30 Jul 2026 10:16:39 +0200</lastBuildDate>
<pubDate>Thu, 30 Jul 2026 10:16:39 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=selfhosting+codecov+with+gitlab%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=selfhosting+codecov+with+gitlab%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[GitLab Vulnerabilities Allow Attackers to Execute Remote Code on Default GitLab Installations]]></title>
<description><![CDATA[A newly disclosed exploit chain in GitLab shows how two long-buried memory-safety flaws in a Ruby JSON parsing library, Oj, could be combined to achieve remote code execution on default GitLab installations, exposing source code, Rails secrets, and internal services. As part of the Open Defense I...]]></description>
<link>https://tsecurity.de/de/3694685/it-security-nachrichten/gitlab-vulnerabilities-allow-attackers-to-execute-remote-code-on-default-gitlab-installations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694685/it-security-nachrichten/gitlab-vulnerabilities-allow-attackers-to-execute-remote-code-on-default-gitlab-installations/</guid>
<pubDate>Sat, 25 Jul 2026 19:42:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly disclosed exploit chain in GitLab shows how two long-buried memory-safety flaws in a Ruby JSON parsing library, Oj, could be combined to achieve remote code execution on default GitLab installations, exposing source code, Rails secrets, and internal services. As part of the Open Defense Initiative, Depthfirst researcher Yuhang Wu used the automated analysis […]</p>
<p>The post <a href="https://cybersecuritynews.com/gitlab-vulnerabilities-enable-code-execution/">GitLab Vulnerabilities Allow Attackers to Execute Remote Code on Default GitLab Installations</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab-Sicherheitslücke: Remote Code Execution über Jupyter-Notebooks]]></title>
<description><![CDATA[Rockwell Automation hat Sicherheitsupdates für seine Arena-Simulationssoftware veröffentlicht, um vier als hochriskant eingestufte Schwachstellen zu ...]]></description>
<link>https://tsecurity.de/de/3694266/it-security-nachrichten/gitlab-sicherheitsluecke-remote-code-execution-ueber-jupyter-notebooks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694266/it-security-nachrichten/gitlab-sicherheitsluecke-remote-code-execution-ueber-jupyter-notebooks/</guid>
<pubDate>Sat, 25 Jul 2026 18:52:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Rockwell Automation hat Sicherheitsupdates für seine Arena-Simulationssoftware veröffentlicht, um vier als hochriskant eingestufte Schwachstellen zu ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git]]></title>
<description><![CDATA[Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update.

Any authenticated user who can push to a project can run it....]]></description>
<link>https://tsecurity.de/de/3694232/it-security-nachrichten/researcher-publishes-gitlab-rce-poc-letting-authenticated-users-run-commands-as-git/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694232/it-security-nachrichten/researcher-publishes-gitlab-rce-poc-letting-authenticated-users-run-commands-as-git/</guid>
<pubDate>Sat, 25 Jul 2026 18:52:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update.

Any authenticated user who can push to a project can run it. The attacker commits a crafted Jupyter notebook and opens its commit diff, which leaks a heap]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab 19.2, Kotlin feiert Geburtstag, Unity CLI]]></title>
<description><![CDATA[Kleine, aber interessante Meldungshäppchen vom News-Buffet zu GitLab, Kotlin, Unity, WebAuthn, Nuxt, Angular, distr, Apache Arrow, VS Code und GitHub.]]></description>
<link>https://tsecurity.de/de/3693395/it-nachrichten/gitlab-192-kotlin-feiert-geburtstag-unity-cli/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693395/it-nachrichten/gitlab-192-kotlin-feiert-geburtstag-unity-cli/</guid>
<pubDate>Sat, 25 Jul 2026 09:55:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kleine, aber interessante Meldungshäppchen vom News-Buffet zu GitLab, Kotlin, Unity, WebAuthn, Nuxt, Angular, distr, Apache Arrow, VS Code und GitHub.]]></content:encoded>
</item>
<item>
<title><![CDATA[v3.96.0]]></title>
<description><![CDATA[What's Changed

[INS-355] Added Hashicorp vault token detector by @MuneebUllahKhan222 in #4819
Tighten JiraToken v1 verification by @shahzadhaider1 in #5122
[INT-718] Add TargetNotFoundError for targeted scan targets missing from the source by @bill-rich in #5123
Fix GitLab project metadata cache...]]></description>
<link>https://tsecurity.de/de/3692297/it-security-tools/v3960/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692297/it-security-tools/v3960/</guid>
<pubDate>Fri, 24 Jul 2026 20:37:39 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>[INS-355] Added Hashicorp vault token detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087349241" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4819" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4819/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4819">#4819</a></li>
<li>Tighten JiraToken v1 verification by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shahzadhaider1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shahzadhaider1">@shahzadhaider1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4857561874" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5122" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5122/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5122">#5122</a></li>
<li>[INT-718] Add TargetNotFoundError for targeted scan targets missing from the source by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bill-rich/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bill-rich">@bill-rich</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4858092823" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5123" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5123/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5123">#5123</a></li>
<li>Fix GitLab project metadata cache and switch to LRU by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kashifkhan0771/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kashifkhan0771">@kashifkhan0771</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3890961533" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4727" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4727/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4727">#4727</a></li>
<li>Log analyze errors for Anthropic Analyzer by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kashifkhan0771/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kashifkhan0771">@kashifkhan0771</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4844292265" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5120" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5120/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5120">#5120</a></li>
<li>Add metrics for chunks and results by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mcastorina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mcastorina">@mcastorina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4880771609" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5128" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5128/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5128">#5128</a></li>
<li>Update Cloudflare detectors for 2026+ prefixed credential formats (include upstream PR changes) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kashifkhan0771/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kashifkhan0771">@kashifkhan0771</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4817025959" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5111" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5111/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5111">#5111</a></li>
<li>[INS-312] Duo API Secret Key Detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3994103061" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4771" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4771/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4771">#4771</a></li>
<li>[Feature] Added SonarQube Cloud "Scoped Organization Token" Detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nabeelalam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nabeelalam">@nabeelalam</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3925861219" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4739" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4739/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4739">#4739</a></li>
<li>[INS-255] Updated datadog detector to set verificationError in case of a verification error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3812485778" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4661" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4661/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4661">#4661</a></li>
<li>Log analyze errors for Postgres analyzer by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kashifkhan0771/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kashifkhan0771">@kashifkhan0771</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4890144471" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5131" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5131/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5131">#5131</a></li>
<li>Log analyze errors for HuggingFace analyzer by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kashifkhan0771/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kashifkhan0771">@kashifkhan0771</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4889921966" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5130" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5130/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5130">#5130</a></li>
<li>Engine - Config.SourceManager doc by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amanfcp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amanfcp">@amanfcp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4563649430" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5002" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5002/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5002">#5002</a></li>
<li>Update module github.com/go-git/go-git/v5 to v5.19.1 [SECURITY] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/renovate/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/renovate">@renovate</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4642514134" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5034" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5034/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5034">#5034</a></li>
<li>Retry git clone on transient network errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shahzadhaider1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shahzadhaider1">@shahzadhaider1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4894687674" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5132" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5132/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5132">#5132</a></li>
<li>Fix <code>scan_all_installations</code> Rejecting Org Member Personal Repos by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shahzadhaider1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shahzadhaider1">@shahzadhaider1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4930360573" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5142" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5142/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5142">#5142</a></li>
<li>updated detector to include underscore char by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattbrady-1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattbrady-1">@mattbrady-1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4856829937" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5121" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5121/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5121">#5121</a></li>
<li>[chore] Change job_id in metric to source_type by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mcastorina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mcastorina">@mcastorina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4953017010" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5149" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5149/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5149">#5149</a></li>
<li>Posthog regex update by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattbrady-1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattbrady-1">@mattbrady-1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4902316600" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5133" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5133/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5133">#5133</a></li>
<li>fix(handlers): apk handler now doesnt check for apk extension since json-enumerator and other byte stream methods wouldnt have it by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/johannestaas-trufflesec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/johannestaas-trufflesec">@johannestaas-trufflesec</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4954699768" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5151" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5151/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5151">#5151</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattbrady-1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattbrady-1">@mattbrady-1</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4856829937" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/5121" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/5121/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/5121">#5121</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/trufflesecurity/trufflehog/compare/v3.95.9...v3.96.0"><tt>v3.95.9...v3.96.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NetworkManager update advances IPv6-only support, Wi‑Fi management, and security for Linux-based operating systems]]></title>
<description><![CDATA[Networking is core to any operating system, and when it comes to Linux, it’s actually a combination of several key components. The Linux kernel handles the data plane, moving packets, and holding live device state. NetworkManager is the network configuration service, operating as the control plan...]]></description>
<link>https://tsecurity.de/de/3690083/it-security-nachrichten/networkmanager-update-advances-ipv6-only-support-wifi-management-and-security-for-linux-based-operating-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690083/it-security-nachrichten/networkmanager-update-advances-ipv6-only-support-wifi-management-and-security-for-linux-based-operating-systems/</guid>
<pubDate>Thu, 23 Jul 2026 21:34:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Networking is core to any operating system, and when it comes to Linux, it’s actually a combination of several key components. The Linux kernel handles the data plane, moving packets, and holding live device state. NetworkManager is the network configuration service, operating as the control plane, deciding what a device’s configuration should be.</p>



<p class="wp-block-paragraph"><a href="https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/releases/1.58.0">NetworkManager 1.58</a> was released this week, following more than five months of development and 407 commits since version 1.56. The release covers three areas: expanded support for IPv6-only networks, a set of Wi-Fi management updates, and a round of security hardening.</p>



<p class="wp-block-paragraph">IPv4 address exhaustion remains the pressure behind the first of those areas, pushing more networks toward IPv6-only operation every year.</p>



<p class="wp-block-paragraph">“More networks, mobile carriers, cloud providers, and anyone squeezed by IPv4 exhaustion are running IPv6-only by default,” <a href="https://www.linkedin.com/in/vanhoof/">Chris Van Hoof</a>, director of Linux engineering, platform enablement at Red Hat, told <em>Network World</em>.</p>



<h2 class="wp-block-heading">Advancing IPv6-only support</h2>



<p class="wp-block-paragraph">Dual stack networking, running IPv4 and IPv6 in parallel, has been the default IPv6 transition strategy for years. Dual stack networking, however, has a structural problem in that it still requires an IPv4 address on every device, so it does nothing to relieve address exhaustion pressure.</p>



<p class="wp-block-paragraph">An alternative model called IPv6-mostly addresses that gap. It is defined in RFC 8925, “IPv6-Only-Preferred Option for DHCPv4,” and lets capable clients drop IPv4 entirely while legacy hosts that still need it keep receiving it on the same network segment.</p>



<p class="wp-block-paragraph">“NetworkManager can also now auto-signal RFC 8925’s IPv6-only-preferred option, telling the network a host is fine skipping an IPv4 lease entirely,” Van Hoof said.</p>



<p class="wp-block-paragraph">For the traffic that still needs IPv4, NetworkManager 1.58 adds support for CLAT, short for customer-side translator. CLAT is the client-side half of 464XLAT, a mechanism defined in RFC 6877, “464XLAT: Combination of Stateful and Stateless Translation.”</p>



<p class="wp-block-paragraph">464XLAT pairs CLAT on the endpoint, which performs stateless header translation, with a stateful NAT64 translator on the provider side, letting IPv4-only apps keep functioning on a network that has no IPv4 of its own.</p>



<p class="wp-block-paragraph">“CLAT is the translation layer that lets legacy IPv4-only apps and services keep working on those networks without bolt-on middleware,” Van Hoof said.</p>



<h2 class="wp-block-heading">Wi-Fi management updates</h2>



<p class="wp-block-paragraph">NetworkManager 1.58 also brings a set of changes to how the daemon handles Wi-Fi connections and configuration.</p>



<ul class="wp-block-list">
<li><strong>Band selection: </strong>The band property of Wi-Fi connections now accepts a 6GHz value, and a Wi-Fi scan run through nmcli, NetworkManager’s command line tool, now shows each access point’s band as well.</li>



<li><strong>Credential handling:</strong> WPS credentials with a 64 character hex PSK are now accepted, matching what some access points return.</li>



<li><strong>Text interface improvements:</strong> nmtui, NetworkManager’s menu driven text interface, picked up several usability additions. A new device select button lets you choose a physical interface from a list instead of typing its name. The activation screen gained a rescan Wi-Fi button, and secret prompts now include a show password checkbox. There is also a share QR code option, mirroring the existing nmcli device wifi show-password command.</li>
</ul>



<h2 class="wp-block-heading">Security hardening</h2>



<p class="wp-block-paragraph">The release fixes vulnerabilities and tightens several defaults tied to DHCP handling and connection permissions.</p>



<ul class="wp-block-list">
<li><strong>CVE-2026-10805: </strong>Hostnames and MUD URLs are now validated before being written to the dhclient configuration file, rejecting characters that could alter the config syntax.</li>



<li><strong>DHCPv4 client fix: </strong>An out-of-bounds read in the internal DHCPv4 client, triggerable by an on-link attacker with a malformed UDP packet, has been fixed.</li>



<li><strong>Router option validation: </strong>The internal DHCPv4 client now ignores DHCP option 3, the Router option, when a lease also contains option 121, the Classless Static Route option, following the recommendation in RFC 3442.</li>



<li><strong>Permission checks and deprecations:</strong> For private connections that restrict access to specific users, NetworkManager now verifies that the user can access the referenced 802.1X certificates and keys.</li>
</ul>



<h2 class="wp-block-heading">Tunneling and automation updates</h2>



<p class="wp-block-paragraph">Two smaller but practical additions round out this release: a new tunnel type for virtualized networks, and a fix that closes a gap in how NetworkManager’s state survives a reboot.</p>



<p class="wp-block-paragraph">NetworkManager 1.58 also adds support for creating and managing GENEVE tunnel interfaces. GENEVE, short for Generic Network Virtualization Encapsulation, is a tunneling protocol that wraps Ethernet frames inside UDP packets, letting virtualized or overlay networks run on top of physical Layer 3 infrastructure. It shows up mainly in virtualization and cloud environments, where a hypervisor or container networking layer needs to build a virtual network segment across physical hosts. Previously, NetworkManager could not create or manage these interfaces directly.</p>



<p class="wp-block-paragraph">The release also adds persisted managed state. NetworkManager tracks whether it is responsible for a given network device, a setting called its managed state. Until now, that setting reset on every reboot, so provisioning tools had to reapply it each time a system restarted. NetworkManager 1.58 lets the managed state survive a reboot when it is set through nmcli or the D-Bus API.</p>



<p class="wp-block-paragraph">“It’s a small change but closes a real automation gap: Provisioning tools and cloud-init style workflows can set a device’s state once via D-Bus or nmcli and trust it survives a reboot, instead of reapplying config every time,” Van Hoof said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Alpha Release: Tor Browser 16.0a9]]></title>
<description><![CDATA[Tor Browser 16.0a9 is now available from the Tor Browser download page and also from our distribution directory.
This version includes important security updates to Firefox.
⚠️ Reminder: The Tor Browser Alpha release-channel is for testing only. As such, Tor Browser Alpha is not intended for gene...]]></description>
<link>https://tsecurity.de/de/3689969/it-security-tools/new-alpha-release-tor-browser-160a9/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689969/it-security-tools/new-alpha-release-tor-browser-160a9/</guid>
<pubDate>Thu, 23 Jul 2026 20:25:02 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article class="blog-post">
    <picture>
      <source media="(min-width:415px)" srcset="https://blog.torproject.org/new-alpha-release-tor-browser-160a9/lead.webp" type="image/webp">
<source srcset="https://blog.torproject.org/new-alpha-release-tor-browser-160a9/lead_small.webp" type="image/webp">

      <img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/new-alpha-release-tor-browser-160a9/lead.png">
    </picture>
    <div class="body"><p>Tor Browser 16.0a9 is now available from the <a href="https://www.torproject.org/download/alpha/">Tor Browser download page</a> and also from our <a href="https://www.torproject.org/dist/torbrowser/16.0a9/">distribution directory</a>.</p>
<p>This version includes important <a href="https://www.mozilla.org/en-US/security/advisories/">security updates</a> to Firefox.</p>
<p>⚠️ <strong>Reminder</strong>: The Tor Browser Alpha release-channel is for <a href="https://community.torproject.org/user-research/become-tester/">testing only</a>. As such, Tor Browser Alpha is not intended for general use because it is more likely to include bugs affecting usability, security, and privacy.</p>
<p>Moreover, Tor Browser Alphas are now based on Firefox's betas. Please read more about this important change in the <a href="https://blog.torproject.org/future-of-tor-browser-alpha/">Future of Tor Browser Alpha</a> blog post.</p>
<p>If you are an at-risk user, require strong anonymity, or just want a reliably-working browser, please stick with the <a href="https://www.torproject.org/download/">stable release channel</a>.</p>
<h2>It's ESR transition season again!</h2>
<p>Well actually, it has been ESR transition season throughout this entire release cycle! As described in the aforementioned <a href="https://blog.torproject.org/future-of-tor-browser-alpha/">Future of Tor Browser Alpha</a> blog post, we have been incrementally rebasing our Alpha channel on Firefox betas since December of last year. As a result, we now stand before you with Tor Browser 16.0a9 which is based on Firefox ESR 153.</p>
<p>We will continue rebasing Tor Browser 17.0 Alpha branches on Firefox betas throughout the remainder of the Tor Browser 16.0 release cycle. However, new feature-work for now must be put on hold for a few reasons:</p>
<ul>
<li>We must focus our attention on resolving our Bugzilla Audit issues to ensure the features we have inherited from upstream comply Tor Browser's <a href="https://gitlab.torproject.org/tpo/applications/wiki/-/wikis/Design-Documents/Tor-Browser-Design-Doc">threat model</a> and to patch any changes which do not.</li>
<li>Feature work targeting 16.0 stable would need to be cherry-pick'd onto our 17.0 Alpha branches to ensure we don't lose any work. The more invasive a feature patch is, the harder it will be to port to newer versions. This would also be a potentially error-prone process and there is some risk we would lose patches along the way.</li>
<li>We need to finish stabilizing as soon as possible as we have hard external deadlines which cannot be moved: the end-of-life of Firefox ESR 140 on October 13th and the Google Play Minimum Target API Level requirement on November 1st</li>
</ul>
<h2>Challenges and Triumphs</h2>
<h3>💍 Sharing the Load</h3>
<p>Rebasing the hundreds of Tor Browser patches onto newer versions of Firefox is a challenging task. It is like maintaining the structural stability of sand-castle at high-tide with the waves crashing all around you.</p>
<p>As such, it quickly become clear early in this new process that we would need to do something if we wanted to avoid burning out the few developers typically involved in this work. To mitigate this, we shared the knowledge internally and spread the work out across all eight members of the team. This way, each developer was only responsible for at most two or three rebases throughout the entire release cycle.</p>
<h3>🎨 UI Code Churn</h3>
<p>Over the past year, Firefox has developed and integrated two major changes to the UI in Firefox: a <a href="https://blog.mozilla.org/en/firefox/firefox-settings/">redesign</a> of about:preferences in Firefox Desktop and a <a href="https://www.androidsage.com/2026/02/24/firefox-browser-updated-with-new-ui-and-material-3-expressive-hint/">migration</a> from Material 2 to Material 3 in Firefox Android.</p>
<p>Adapting to these types of changes to the frontend are typically rather time-consuming for us, as many (if not the majority) of our patches modify Firefox's UI in some way. For example, we have an entire preferences page on Tor Browser desktop dedicated to configuring how the browser connects to the Tor Network. On Android, we similarly have various additions to the menus, configuration options, and custom UI.</p>
<p>Whenever Mozilla modifies their design systems and Firefox's user interface, we necessarily have to adapt our own custom additions to match. Otherwise, our Tor Browser-specific UI elements would look completely out of place and potentially confuse users (as well as simply looking unprofessional). Therefore, each of these upstream changes requires collaboration with the Tor Project's UX team to update our features' designs and of course development time to implement.</p>
<p>In addition to the time-cost associated with the extra engineering and UX collaboration, very often our old patches simply do not apply cleanly due to the amount of code which has changed. For example, the about:preferences changes on Firefox Desktop are essentially a complete re-write which means we also have to completely re-write our own settings changes without regressing in functionality.</p>
<p>On the plus side, one benefit of our new processes is that we have been able to spread out this work over the entire release cycle. In the past way of doing things, we would have discovered all UX elements which needed to be fixed, updated our designs, and re-implemented in the course of a few months during the old ESR transition season. Under this new way of working, we have been able to incrementally fix things throughout the development cycle.</p>
<p>The benefits of working this way does not just apply to UX of course. It is much easier to find regressions across the entire stack when rebasing between one major Firefox version at a time instead of across 12 or 13. It is also <em>much</em> easier for developers to fix individual regressions one at a time compared to diagnosing, disentangling, and fixing multiple bugs concurrently (divide et impera!).</p>
<h3>⚙️ Pending Google Target API Level Requirements</h3>
<p>Every year, Google requires new Android app releases to target an updated minimum API level. This means, we would not be able to upload new versions of Tor Browser Stable past a certain date (usually August 1st with an extension to November 1st typically possible) without first updating the app to support the new minimum target API level. Fortunately, we inherit most of the required changes from Mozilla when rebasing to the next major ESR.</p>
<p>However, this requirement does impose a hard deadline for the absolute latest we can responsibly stabilize Tor Browser Alpha and promote it to Stable. We've been fortunate in the past few years to make the deadline with a few days to spare (October 28th for Tor Browser 15, October 22nd for Tor Browser 14, etc). Given how far ahead of the curve we are this year, we are hoping to release about a month earlier in September (fingers crossed!).</p>
<h3>🤖 Android APKs too big</h3>
<p>The Google Play Store has a strict size limit of about 100 megabytes for Android applications. New functionality added to Firefox Android over the past year means a larger application which results in new headaches for Tor Browser developers. This release cycle was no exception to this rule and we have had to get <em>creative</em> with our size reductions.</p>
<p>In the past, we have been able reduce our package size though various methods including:</p>
<ul>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/work_items/41500">Using custom size-reducing compiler flags</a></li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/work_items/-41407">Compiling multiple pluggable-transports into a single unified binary to de-duplicate shared dependencies</a></li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/work_items/42386">Removing unused Firefox assets from the build</a></li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/work_items/42669">Replacing unused (but still linked) libraries with no-op stubs</a></li>
<li>and <a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/work_items/42607">countless other methods over there years</a></li>
</ul>
<p>Our most recent effort has been the most invasive yet! For some background, the Firefox application consists of (among other things): various shared libraries, the Firefox executable, a library known as 'xul' which contains most of Firefox's natively compiled functionality, and finally a file known as <code>omni.ja</code>. This <code>omni.ja</code> file is a <code>zip</code> archive which contains the JavaScript, HTML, images, and other assets used in Firefox.</p>
<p>This time around, to reduce the size of our Android package we have<a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/work_items/45086">changed how this archive is compressed</a>. We modified the Firefox build system to compress this archive with <code>xz</code> and we modified Firefox itself to decompress this archive at runtime. This work did require a few iterations to get right. In the end, we got back about 3 megabytes with these changes and got us once again under Google's imposed size budget.</p>
<h3>📉 Even Less Telemetry</h3>
<p>Over the years, we have worked to incrementally remove dependencies from Tor Browser Android as part of the aforementioned size reduction work. We of course inherit most of these dependencies from Firefox Android and unfortunately some of them can be labeled as 'trackers'. While we do disable telemetry by default at runtime, the code which implements it remains in the codebase.</p>
<p>We're happy to report that as of Tor Browser 16.0a8, are down to only 1 'tracker' library in the Tor Browser Android codebase: <code>Mozilla Telemetry</code>. Again, this telemetry <em>is</em> disabled at runtime, but this is one more unused dependency which we can <a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/work_items/41295">hopefully remove in the future</a> (and maybe get some more bytes back!).</p>
<h2>Current Status</h2>
<p>We have:</p>
<ul>
<li>incrementally rebased Tor Browser and Tor Browser for Android to Firefox ESR 153 from Firefox ESR 140</li>
<li>updated the build systems with the latest dependencies and fixed a few reproducibility issues</li>
<li>triaged <em>most</em> of the upstream changes from the past year and flagged over 250 issues for further review (triaging of Firefox 153 is in progress)</li>
<li>resolved about half of these triaged issues</li>
</ul>
<p>For the remainder of this release cycle, we will be focusing on auditing these issues and fixing bugs until the 16.0 alpha series is ready to become Tor Browser Stable 16.0. We are optimistically targeting a September release, which would put us one month ahead of schedule compared to last year.</p>
<h2>Known Issues</h2>
<h3>🦊 Firefox Branding</h3>
<p>In some places in the browser there may be Firefox branding (e.g. logos, cute little foxes, etc) instead of Tor Browser branding. We're currently tracking one known instance in <a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/work_items/44998">tor-browser#44998</a>. If you discover any other instances lurking about, please <a href="https://support.torproject.org/misc/bug-or-feedback/">open an issue</a>!</p>
<h3>🌐 All websites marked 'insecure' on Tor Browser Android</h3>
<p>Currently, the identity block in the URL bar on Tor Browser Android will always report insecure (e.g. a shield icon with a slash through it). For now, you can tap this icon and verify the certificate manually. This issue is being tracked in <a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/work_items/45115">tor-browser#45115</a></p>
<h2>Send us your feedback</h2>
<p>Now is a great time to <a href="https://blog.torproject.org/vounteer-as-an-alpha-tester/">become an alpha tester</a>! If you find a bug or have a suggestion for how we could improve this release, <a href="https://support.torproject.org/misc/bug-or-feedback/">please let us know</a>.</p>
<h2>Full changelog</h2>
<p>The <a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/raw/main/projects/browser/Bundle-Data/Docs-TBB/ChangeLog.txt">full changelog</a> since Tor Browser 16.0a8 is:</p>
<ul>
<li>All Platforms<ul>
<li>Updated NoScript to 13.6.30.90201984</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/43819">Bug tor-browser#43819</a>: Show custom security level on android</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44748">Bug tor-browser#44748</a>: Revert Funding the Commons Implementations</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44811">Bug tor-browser#44811</a>: Remove the lock on pdfjs.disable.</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45101">Bug tor-browser#45101</a>: Rebase Tor Browser onto 153.0esr</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45131">Bug tor-browser#45131</a>: Security level is using an unsafe getBoolPref</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41831">Bug tor-browser-build#41831</a>: Update libevent to 2.1.13</li>
</ul>
</li>
<li>Windows + macOS + Linux<ul>
<li>Updated Firefox to 153.0esr</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44439">Bug tor-browser#44439</a>: Remove translate action from urlbar</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44883">Bug tor-browser#44883</a>: Remove urlbar quick action for labs</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45029">Bug tor-browser#45029</a>: Convert connection status settings to new design and config approach</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45055">Bug tor-browser#45055</a>: Rename --color-gray-05 to --color-gray-0</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45081">Bug tor-browser#45081</a>: Use the new "Acorn" icons on desktop</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45110">Bug tor-browser#45110</a>: Disable the settings redesign until ready for us</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45112">Bug tor-browser#45112</a>: Missing CSS border tokens in 153</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45132">Bug tor-browser#45132</a>: nsAppFileLocationProvider.cpp: use of undeclared identifier 'XRE_EXECUTABLE_FILE'</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41800">Bug tor-browser-build#41800</a>: Create a script that adapts the Tor Browser manual HTMLs to work in Tor Browser</li>
</ul>
</li>
<li>macOS<ul>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45108">Bug tor-browser#45108</a>: Artifact generation fails due to missing .DS_Store in the branding directories</li>
</ul>
</li>
<li>Android<ul>
<li>Updated GeckoView to 153.0esr</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/43820">Bug tor-browser#43820</a>: Use SecurityLevel integration on android</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44157">Bug tor-browser#44157</a>: Remove secret setting toggle for Tab Management Redesign</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45045">Bug tor-browser#45045</a>: Remove moz asset in Downloads screen</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45103">Bug tor-browser#45103</a>: Disable broken "tab management"</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45109">Bug tor-browser#45109</a>: No value passed for parameter 'jsEnabled'</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45118">Bug tor-browser#45118</a>: Audit and disable Mozilla VPN promo</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45130">Bug tor-browser#45130</a>: Clean up TorHomePage padding</li>
</ul>
</li>
<li>Build System<ul>
<li>All Platforms<ul>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41838">Bug tor-browser-build#41838</a>: Update personal_access_tokens URL in tools/fetch_changelogs.py</li>
</ul>
</li>
<li>Windows + Linux + Android<ul>
<li>Updated Go to 1.26.5</li>
</ul>
</li>
<li>Windows<ul>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41819">Bug tor-browser-build#41819</a>: Fix windows-rs URL in projects/firefox/config</li>
</ul>
</li>
</ul>
</li>
</ul>

    </div>
  <div class="categories">
    <ul><li>
        <a href="https://blog.torproject.org/category/applications">
          applications
        </a>
      </li><li>
        <a href="https://blog.torproject.org/category/releases">
          releases
        </a>
      </li></ul>
  </div>
  </article>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Release: Tails 7.10]]></title>
<description><![CDATA[New features
New shutdown procedure
Tails now uses the standard shutdown procedure from GNOME.
The standard shutdown procedure
is a bit slower, but better prevents data loss.
For example, the Power Off confirmation dialog informs you if an
application needs to be closed or an open document needs ...]]></description>
<link>https://tsecurity.de/de/3688527/it-security-tools/new-release-tails-710/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688527/it-security-tools/new-release-tails-710/</guid>
<pubDate>Thu, 23 Jul 2026 11:24:32 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article class="blog-post">
    <picture>
      <source media="(min-width:415px)" srcset="https://blog.torproject.org/new-release-tails-7_10/lead.webp" type="image/webp">
<source srcset="https://blog.torproject.org/new-release-tails-7_10/lead_small.webp" type="image/webp">

      <img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/new-release-tails-7_10/lead.jpg">
    </picture>
    <div class="body"><h2>New features</h2>
<h3>New shutdown procedure</h3>
<p>Tails now uses the standard shutdown procedure from GNOME.</p>
<p>The <a href="https://tails.net/doc/first_steps/shutdown/">standard shutdown</a> procedure
is a bit slower, but better prevents data loss.</p>
<p>For example, the <strong>Power Off</strong> confirmation dialog informs you if an
application needs to be closed or an open document needs to be saved before
shutting down.</p>
<p><a href="https://tails.net/doc/first_steps/shutdown/power_off_with_inhibitor.png"><img src="https://tails.net/doc/first_steps/shutdown/power_off_with_inhibitor.png" alt=""></a></p>
<p>Even without confirming or saving the open documents, Tails will shut down
after 60 seconds.</p>
<p>You can still use the faster <a href="https://tails.net/doc/first_steps/shutdown/#emergency">emergency
shutdown</a> as before.</p>
<h3><em>Celluloid</em> video player</h3>
<p>We replaced <em>GNOME Videos</em> with <em>Celluloid</em> , a more modern and reliable video
player.</p>
<p><a href="https://tails.net/news/version_7.10/celluloid.png"><img src="https://tails.net/news/version_7.10/celluloid.png" alt=""></a></p>
<p>For added security, <em>Celluloid</em> cannot access the network. You can either:</p>
<ul>
<li>Open online videos, like MP4 and AVI files, in <em>Tor Browser</em>.</li>
<li>Open online streaming addresses, like IPTV and HLS addresses, in <em>VLC</em> , installed as <a href="https://tails.net/doc/persistent_storage/additional_software/">additional software</a>.</li>
</ul>
<p><em>Celluloid</em> doesn't work on some computer from 2011 or earlier.</p>
<p>You can use <em>VLC</em> instead, installed as <a href="https://tails.net/doc/persistent_storage/additional_software/">additional
software</a>.</p>
<h2>Changes and updates</h2>
<ul>
<li><p>Update <em>Tor Browser</em> to <a href="https://blog.torproject.org/new-release-tor-browser-15019/">15.0.19</a>.</p>
</li>
<li><p>Update some firmware packages. This improves support for newer hardware: graphics, Wi-Fi, and so on.</p>
</li>
</ul>
<p>For more details, read our
<a href="https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog">changelog</a>.</p>
<h2>Get Tails 7.10</h2>
<h3>To upgrade your Tails USB stick and keep your Persistent Storage</h3>
<ul>
<li><p>Automatic upgrades are available from Tails 7.0 or later to 7.10.</p>
</li>
<li><p>If you cannot do an automatic upgrade or if Tails fails to start after an automatic upgrade, please try to do a <a href="https://tails.net/doc/upgrade/#manual">manual upgrade</a>.</p>
</li>
</ul>
<h3>To install Tails 7.10 on a new USB stick</h3>
<p>Follow our <a href="https://tails.net/install/">installation instructions</a>.</p>
<p>The Persistent Storage on the USB stick will be lost if you install instead of
upgrading.</p>
<h3>To download only</h3>
<p>If you don't need installation or upgrade instructions, you can download Tails
7.10 directly:</p>
<ul>
<li><p><a href="https://tails.net/install/download/">For USB sticks (USB image)</a></p>
</li>
<li><p><a href="https://tails.net/install/download-iso/">For DVDs and virtual machines (ISO image)</a></p>
</li>
</ul>
<h2>Support and feedback</h2>
<p>For support and feedback, visit the <a href="https://tails.net/support/">Support
section</a> on the Tails website.</p>

    </div>
  <div class="categories">
    <ul><li>
        <a href="https://blog.torproject.org/category/tails">
          tails
        </a>
      </li><li>
        <a href="https://blog.torproject.org/category/releases">
          releases
        </a>
      </li></ul>
  </div>
  </article>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tails 7.10]]></title>
<description><![CDATA[New features


New shutdown procedure

Tails now uses the standard shutdown procedure from GNOME.

The standard shutdown procedure is a bit slower,
but better prevents data loss.

For example, the Power Off confirmation dialog informs you if an
application needs to be closed or an open document n...]]></description>
<link>https://tsecurity.de/de/3688478/it-security-tools/tails-710/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688478/it-security-tools/tails-710/</guid>
<pubDate>Thu, 23 Jul 2026 11:07:50 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>New features</h1>


<h2>New shutdown procedure</h2>

<p>Tails now uses the standard shutdown procedure from GNOME.</p>

<p>The <a href="https://tails.net/doc/first_steps/shutdown/index.en.html">standard shutdown</a> procedure is a bit slower,
but better prevents data loss.</p>

<p>For example, the <strong>Power Off</strong> confirmation dialog informs you if an
application needs to be closed or an open document needs to be saved before
shutting down.</p>

<p><a href="https://tails.net/doc/first_steps/shutdown/power_off_with_inhibitor.png"><img alt="" class="screenshot" height="406" src="https://tails.net/doc/first_steps/shutdown/power_off_with_inhibitor.png" width="472"></a></p>

<p>Even without confirming or saving the open documents, Tails will shut down
after 60 seconds.</p>

<p>You can still use the faster <a href="https://tails.net/doc/first_steps/shutdown/index.en.html#emergency">emergency
shutdown</a> as before.</p>

<h2><em>Celluloid</em> video player</h2>

<p>We replaced <em>GNOME Videos</em> with <em>Celluloid</em>, a more modern and reliable video
player.</p>

<p><a href="https://tails.net/news/version_7.10/celluloid.png"><img alt="" class="screenshot" height="675" src="https://tails.net/news/version_7.10/celluloid.png" width="751"></a></p>

<div class="note">

<p>For added security, <i>Celluloid</i> cannot access the network. You can
either:</p>

<ul>

  <li>Open online videos, like MP4 and AVI files, in <i>Tor Browser</i>.

  </li><li>Open online streaming addresses, like IPTV and HLS addresses, in
  <i>VLC</i>, installed as <a href="https://tails.net/doc/persistent_storage/additional_software/index.en.html">additional
  software</a>.</li>

</ul>

</div>




<div class="bug">

<p><i>Celluloid</i> doesn't work on some computer from 2011 or earlier.</p>

<p>You can use <i>VLC</i> instead, installed as <a href="https://tails.net/doc/persistent_storage/additional_software/index.en.html">additional
software</a>.</p>

</div>




<h1>Changes and updates</h1>


<ul>
<li><p>Update <em>Tor Browser</em> to <a href="https://blog.torproject.org/new-release-tor-browser-15019/">15.0.19</a>.</p></li>
<li><p>Update some firmware packages. This improves support for newer
hardware: graphics, Wi-Fi, and so on.</p></li>
</ul>


<p>For more details, read our <a href="https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog">changelog</a>.</p>

<h1>Get Tails 7.10</h1>


<h2>To upgrade your Tails USB stick and keep your Persistent Storage</h2>

<ul>
<li><p>Automatic upgrades are available from Tails 7.0 or later to 7.10.</p></li>
<li><p>If you cannot do an automatic upgrade or if Tails fails to start after an
automatic upgrade, please try to do a <a href="https://tails.net/doc/upgrade/index.en.html#manual">manual upgrade</a>.</p></li>
</ul>


<h2>To install Tails 7.10 on a new USB stick</h2>

<p>Follow our <a href="https://tails.net/install/index.en.html">installation instructions</a>.</p>

<div class="caution"><p>The Persistent Storage on the USB stick will be lost if
you install instead of upgrading.</p></div>


<h2>To download only</h2>

<p>If you don't need installation or upgrade instructions, you can download
Tails 7.10 directly:</p>

<ul>
<li><p><a href="https://tails.net/install/download/index.en.html">For USB sticks (USB image)</a></p></li>
<li><p><a href="https://tails.net/install/download-iso/index.en.html">For DVDs and virtual machines (ISO image)</a></p></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab 19.2: KI-Agenten für Security-Reviews & Fixes - BigData-Insider]]></title>
<description><![CDATA[Täglich die wichtigsten Infos zu Big Data, Analytics & AI ... Mit Klick auf „Newsletter abonnieren“ erkläre ich mich mit der Verarbeitung und Nutzung ...]]></description>
<link>https://tsecurity.de/de/3688298/it-security-nachrichten/gitlab-192-ki-agenten-fuer-security-reviews-fixes-bigdata-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688298/it-security-nachrichten/gitlab-192-ki-agenten-fuer-security-reviews-fixes-bigdata-insider/</guid>
<pubDate>Thu, 23 Jul 2026 09:42:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Täglich die wichtigsten Infos zu Big <b>Data</b>, Analytics &amp; AI ... Mit Klick auf „Newsletter abonnieren“ erkläre ich mich mit der Verarbeitung und Nutzung ...]]></content:encoded>
</item>
<item>
<title><![CDATA[[Stable Update] 2026-07-23 - Kernels, Mesa, VirtualBox, Gambas3, COSMIC, Plasma, KDE Frameworks]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected end of July or beginning of August. Development speed may be a little slower the upcoming weeks. However, still let us know any ...]]></description>
<link>https://tsecurity.de/de/3688271/unix-server/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688271/unix-server/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/</guid>
<pubDate>Thu, 23 Jul 2026 09:31:27 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected end of July or beginning of August. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may found thus far.</p>
<h3><a name="p-867467-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-867467-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-867467-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-867467-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/189137/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/189137/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/189137/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 7.0.14, the 7.0 series is now EOL (End Of Life). Please install 7.1, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/189137/1">(click for more details)</a>
<h2><a name="p-867467-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-867467-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>Kernels</strong></li>
<li><strong>Mesa</strong> <a href="https://docs.mesa3d.org/relnotes/26.1.5.html">26.1.5</a></li>
<li><strong>VirtualBox</strong> <a href="https://www.virtualbox.org/wiki/Changelog-7.2">7.2.14</a></li>
<li><strong>Gambas3</strong> <a href="https://gambaswiki.org/wiki/doc/release/3.22.0">3.22.0</a></li>
<li><strong>Qemu</strong> <a href="https://wiki.qemu.org/ChangeLog/11.0">11.0.2</a></li>
<li><strong>PipeWire</strong> <a href="https://gitlab.freedesktop.org/pipewire/pipewire/-/releases/1.6.8">1.6.8</a></li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/en-US/firefox/152.0.6/releasenotes/">152.0.6</a></li>
<li><strong>KDE Frameworks</strong> <a href="https://kde.org/announcements/frameworks/6/6.28.0/">6.28.0</a></li>
<li><strong>KDE Plasma</strong> <a href="https://kde.org/announcements/plasma/6/6.7.3/">6.7.3</a></li>
<li><strong>COSMIC</strong> Epoch <a href="https://github.com/pop-os/cosmic-epoch/releases/tag/epoch-1.3.0">1.3.0</a></li>
<li><strong>GStreamer</strong> <a href="https://gstreamer.freedesktop.org/releases/1.28/#1.28.5">1.28.5</a></li>
<li><strong>Wine</strong> <a href="https://www.winehq.org/news/2026071001">11.13</a></li>
</ul>
<h2><a name="p-867467-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-867467-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/189137/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/189137/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.177</li>
<li>linux66 6.6.144</li>
<li>linux612 6.12.96</li>
<li>linux618 6.18.39</li>
<li>linux71 7.1.4</li>
<li>linux72 7.2.0-rc4</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (7/22/26 05:45 CEST)</p>
<ul>
<li>stable core x86_64:  71 new and 71 removed package(s)</li>
<li>stable extra x86_64:  1982 new and 2071 removed package(s)</li>
<li>stable multilib x86_64:  32 new and 32 removed package(s)</li>
</ul>
<p>A list of all package changes can be found <a href="https://gist.github.com/hphilm/2af362883e023aba0750a9455d3fbd2f/raw">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/189137/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>3 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/stable-update-2026-07-23-kernels-mesa-virtualbox-gambas3-cosmic-plasma-kde-frameworks/189137">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Digitale Selbstbestimmung: OnionHop leitet euren gesamten Datenverkehr durch das Tor-Netzwerk (Linux/Win/Mac)]]></title>
<description><![CDATA[OnionHop – Überblick OnionHop — route your traffic through Tor, with clear controls ist ein moderner plattformübergreifender Desktop-Client (für Windows, Linux und macOS) mit starkem Fokus auf Privatsphäre. Er ermöglicht es Nutzern, ihren Datenverkehr über das Tor-Netzwerk zu leiten. Es handelt s...]]></description>
<link>https://tsecurity.de/de/3687868/it-security-nachrichten/digitale-selbstbestimmung-onionhop-leitet-euren-gesamten-datenverkehr-durch-das-tor-netzwerk-linuxwinmac/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687868/it-security-nachrichten/digitale-selbstbestimmung-onionhop-leitet-euren-gesamten-datenverkehr-durch-das-tor-netzwerk-linuxwinmac/</guid>
<pubDate>Thu, 23 Jul 2026 04:14:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><h1>OnionHop – Überblick</h1> <p><a href="https://www.onionhop.de/">OnionHop — route your traffic through Tor, with clear controls</a> ist ein moderner plattformübergreifender Desktop-Client (für Windows, Linux und macOS) mit starkem Fokus auf Privatsphäre. Er ermöglicht es Nutzern, ihren Datenverkehr über das Tor-Netzwerk zu leiten. Es handelt sich um ein unabhängiges Open-Source-Projekt, das nicht offiziell mit dem <a href="https://www.torproject.org/">Tor Project | Anonymity Online</a> verbunden ist. Die OnionHop Oberfläche bietet 8 Sprachen (Englisch, Deutsch, Französisch, Chinesisch, Russisch, Persisch, Aserbaidschanisch und Sorani Kurdisch).</p> <p>Melden Sie sich freiwillig als Snowflake-Proxy helfen Sie zensierten Benutzern, Tor direkt von den Einstellungen aus zu erreichen (siehe Einstellungen).</p> <h1>Hauptfunktionen</h1> <ul> <li><strong>Proxy-Modus:</strong> Leitet den Datenverkehr ressourcenschonend über einen lokalen SOCKS-Proxy um, ohne dass Administratorrechte benötigt werden. Ein Knopfdruck auf "System Proxy: On" und alle gängigen Browser benutzen das Tor Netzwerk.</li> <li><strong>TUN-Modus (eigene virutelle Netzwerkkarte):</strong> Leitet den Datenverkehr des gesamten Systems (alle Apps) mit einem Klick über das Tor-Netzwerk um.</li> <li><strong>Split-Tunneling:</strong> Ermöglicht die individuelle Auswahl, welche Apps über Tor laufen und welche direkte Verbindungen nutzen.</li> <li><strong>Kill-Switch:</strong> Blockiert den ausgehenden Datenverkehr sofort, wenn die Tor-Verbindung abbricht, um ungeschützte Datenlecks zu verhindern.</li> <li><strong>DNS-Steuerung:</strong> Erzwingt DNS-Anfragen über Tor und verhindert Lecks zum Internetanbieter (inklusive QUIC/UDP-Leckschutz).</li> <li><strong>Länder- &amp; Seiten-Routing:</strong> Erlaubt direkte Verbindungen für bestimmte Länder oder das Blockieren von Domains basierend auf automatisch aktualisierten Listen.</li> <li><strong>CLI-Client:</strong> Bietet eine Kommandozeilenversion ohne grafische Oberfläche, ideal für Server und Automatisierungen. Zensurumgehung und Netzwerktechnologien</li> <li><strong>Smart Connect:</strong> Wählt automatisch die optimale Engine, Route und Bridge für das aktuelle Netzwerk.</li> <li><strong>Integrierter Bridge-Scanner:</strong> Sucht und testet automatisch funktionierende Brücken (Bridges) in restriktiven Netzwerken, sodass keine manuelle Eingabe erforderlich ist.</li> <li><strong>Pluggable Transports:</strong> Unterstützt Protokolle wie obfs4, snowflake, webtunnel, conjure, meek, dnstt und vanilla, um Netzwerkblockaden zu umgehen.</li> <li><strong>Tor-Engines:</strong> Nutzt Classic (tor), Arti (<a href="https://gitlab.torproject.org/tpo/core/arti/-/blob/main/CHANGELOG.md"><em>A Rust Tor Implementation</em></a> <em>(Gitlab Changelog) oder</em> <a href="https://arti.torproject.org/"><em>https://arti.torproject.org/</em></a> <em>für die Nerds</em> <a href="https://dspacemainprd01.lib.uwaterloo.ca/server/api/core/bitstreams/538e4dac-759f-4677-a8f6-10cc83482165/content#:~:text=We%20illustrate%20an%20example%20of%20this%20occurrence,our%20proposal%2C%20and%20details%20about%20its%20implementation">Improving Tor using a TCP-over-DTLS Tunnel (PDF, englisch)</a><em>, bald schon mit UDP Unterstützung</em> <a href="https://spec.torproject.org/proposals/348-udp-app-support.html">339 / 348-udp-app-support - Tor design proposals</a> <em>(Tor Architektur), dies ist die Zukunft von Tor, weg von C mit seinen historisch vielen Buffer Overflows ~65% aller Tor Sicherheitslücken, mit RPC-Schnittstelle (Remote Procedure Call / Methodenaufruf auf entfernten Systemen / Software) und UDP für moderne Anwendungen)</em></li> </ul> <p>Da Transparenz bei Software für die informationelle Selbstbestimmung das Wichtigste ist, ist das gesamte Projekt <strong>quelloffen (Open Source)</strong>. Ihr könnt euch den Quellcode jederzeit auf GitHub ansehen, ihn selbst kompilieren oder Code-Überprüfungen (Code Reviews) durchführen:</p> <p>👉 <strong>GitHub-Repository:</strong> <a href="https://github.com/center2055/OnionHop">center2055/OnionHop: Privacy-first Desktop app that routes your traffic through Tor - Anonymous browsing made simple</a></p> <p>Die Software steht für <strong>Linux, Windows und macOS</strong> zur Verfügung (es gibt auch tragbare Versionen, die nicht installiert werden müssen). <strong>Neben</strong> der <strong>grafischen Oberfläche</strong> gibt es für Automatisierungen auch eine <strong>reine Kommandozeilen-Version (CLI)</strong>.</p> <h1>Systemweite Socks5 Proxy vs. TUN VPN-Technik Modus mit eigener virtuellen Netzwerkkarte (TUN)</h1> <p>Um zu verstehen, warum der TUN oft sicherer ist, hilft ein direkter Vergleich:</p> <table><thead> <tr> <th align="left"><strong>Eigenschaft</strong></th> <th align="left"><strong>Systemweiter Vermittlungsserver (System SOCKS5</strong> <strong>Proxy)</strong></th> <th align="left"><strong>TUN "Netzwerktunnel"(OSI Layer 3</strong>) <strong>"virtuellen Netzwerkadapter" nicht TAP wie bei VPN Layer 2</strong></th> </tr> </thead><tbody> <tr> <td align="left"><strong>Arbeitsweise</strong></td> <td align="left">Setzt darauf, dass Programme die Regeln des Betriebssystems respektieren und die Poststelle nutzen.</td> <td align="left">Zwingt den gesamten Netzwerkverkehr auf tiefer Ebene durch einen Trichter.</td> </tr> <tr> <td align="left"><strong>Zuverlässigkeit</strong></td> <td align="left">Manche Programme (z. B. bestimmte Spiele oder Hintergrunddienste) ignorieren diese Einstellungen und funken direkt ins Internet.</td> <td align="left">Fängt alles ab, völlig unabhängig davon, wie das einzelne Programm programmiert ist.</td> </tr> <tr> <td align="left"><strong>Schutz vor Datenlecks</strong></td> <td align="left">Es kann vorkommen, dass Informationen (wie Adressanfragen) ungeschützt nach außen dringen (Datenlecks).</td> <td align="left">Bietet einen sehr hohen Schutz vor Datenlecks, da kein Datenpaket die Straßensperre umgehen kann. Eigenschaft Systemweiter Vermittlungsserver (SOCK5 Proxy) TUN-ModusArbeitsweise Setzt darauf, dass Programme die Regeln des Betriebssystems respektieren und die Poststelle nutzen. Zwingt den gesamten Netzwerkverkehr auf tiefer Ebene durch einen Trichter. Zuverlässigkeit Manche Programme (z. B. bestimmte Spiele oder Hintergrunddienste) ignorieren diese Einstellungen und funken direkt ins Internet. Fängt alles ab, völlig unabhängig davon, wie das einzelne Programm programmiert ist. Schutz vor Datenlecks Es kann vorkommen, dass Informationen (wie Adressanfragen) ungeschützt nach außen dringen (Datenlecks). Bietet einen sehr hohen Schutz vor Datenlecks, da kein Datenpaket die Straßensperre umgehen kann.</td> </tr> </tbody></table> <p><strong>Zusammenfassung: Warum es beide Modi (System SOCKS5 Proxy und TUN) gibt</strong></p> <p>Genau an diesem Punkt zeigt sich, warum Werkzeuge wie OnionHop unterschiedliche Modi anbieten müssen:</p> <ol> <li><strong>Der System SOCKS5 Proxy-Modus (Anwendung muss Socks5 fähig sein z.B. alle Internet Browser):</strong> Er ist sehr ressourcenschonend und leichtgewichtig. Er eignet sich hervorragend, wenn du gezielt nur die Anwendungen über das Tor-Netzwerk leiten möchtest, die diesen Standard unterstützen (wie deinen Browser).</li> <li><strong>Der TUN-Modus "virtuelle Netzwerkkarte":</strong> Er löst exakt das Problem der fehlenden Unterstützung in Programmen. Wie wir zuvor besprochen haben, baut dieser Modus eine **virtuelle Netzwerkkarte (**sichtbar unter "Netzwerkverbindungen" unter Windows, WIN + R = <code>ncpa.cpl)</code> auf und zwingt das Betriebssystem, <strong>alles</strong> dorthin zu leiten. Hierbei ist es völlig egal, ob ein Programm von Vermittlungsservern weiß oder nicht – die Daten werden auf einer Ebene abgefangen, der sich kein Programm entziehen kann.</li> </ol> <h1>Für die Entwickler unter euch: Wie ändert man den System-Proxy eigentlich programmatisch?</h1> <p>Wer schon länger in der Softwareentwicklung tätig ist, kennt das Problem bei der plattformübergreifenden Programmierung: Ein einheitliches Vorgehen gibt es hier leider nicht. Jedes Betriebssystem kocht sein eigenes Süppchen, was bei Werkzeugen wie OnionHop unter der Haube einigen Aufwand bedeutet. Hier ist ein kleiner technischer Einblick, wie der Code das im Hintergrund löst:</p> <p><strong>1. Windows: Die Registrierungsdatenbank und WinINet</strong> Einfach nur Werte in eine Konfigurationsdatei zu schreiben, reicht hier nicht. Zuerst müssen die Werte in der Registrierungsdatenbank (im Zweig <code>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings</code>) manipuliert werden (z. B. <code>ProxyEnable</code> auf <code>1</code> und <code>ProxyServer</code> auf <code>127.0.0.1:9050</code>). Der entscheidende Schritt ist danach aber, das System über diese Änderung zu benachrichtigen, da laufende Anwendungen (wie der Browser) die neuen Werte sonst ignorieren. Dafür muss ein Aufruf der Windows-Systembibliothek <code>wininet.dll</code> erfolgen. Über die Programmierschnittstelle (API) <code>InternetSetOption</code> feuert man die Markierungen (Flags) <code>INTERNET_OPTION_SETTINGS_CHANGED</code> und <code>INTERNET_OPTION_REFRESH</code> ab, um das System zum sofortigen Neuladen zu zwingen.</p> <p><strong>2. Linux: Die große Fragmentierung</strong> Gerade wenn man in hybriden Umgebungen (wie dem Windows-Subsystem für Linux oder mit Container-Lösungen) entwickelt, merkt man schnell: Linux hat keine zentrale Instanz für diese Einstellungen.</p> <ul> <li><strong>Kommandozeile und Hintergrunddienste:</strong> Diese reagieren fast ausschließlich auf Umgebungsvariablen wie <code>http_proxy</code> oder <code>ALL_PROXY</code>. Diese müssen durch das Programm systemweit oder in den jeweiligen Startskripten (z. B. <code>~/.bashrc</code>) gesetzt werden.</li> <li><strong>GNOME-Desktop:</strong> Hier wird die Konfigurationsdatenbank (dconf) genutzt. Programmatisch löst man das über die C-Programmierschnittstelle von GLib oder einfacher durch das Ausführen von Systembefehlen im Hintergrund (z. B. <code>gsettings set org.gnome.system.proxy mode 'manual'</code>).</li> <li><strong>KDE Plasma:</strong> Speichert die Konfiguration in Textdateien (<code>~/.config/kioslaverc</code>), die von der Software analysiert und editiert werden müssen, gefolgt von einem Befehl zum Neustart der zuständigen KDE-Dienste.</li> </ul> <p><strong>3. macOS: SystemConfiguration Framework</strong> Apple regelt das Netzwerkmanagement streng über die einzelnen Hardware-Schnittstellen (WLAN, Kabelnetzwerk etc.).</p> <ul> <li><strong>Der skriptbasierte Weg:</strong> Ein Programm ruft im Hintergrund das vorinstallierte Kommandozeilen-Werkzeug <code>networksetup</code> auf, um den Vermittlungsserver für jede aktive Netzwerkschnittstelle einzeln zu setzen (z. B. <code>networksetup -setsocksfirewallproxy "Wi-Fi"</code> <a href="http://127.0.0.1/"><code>127.0.0.1</code></a> <code>9050</code>).</li> <li><strong>Der native Weg:</strong> Die Software greift direkt über C oder Swift auf das Systemgerüst <code>SystemConfiguration</code> zu. Über die Programmierschnittstelle <code>SCDynamicStore</code> klinkt man sich in den Konfigurationsspeicher ein, schreibt ein Datenverzeichnis mit den neuen Werten in den Pfad <code>State:/Network/Global/Proxies</code> und teilt so dem Kernel die Netzwerkänderung ohne Umwege direkt mit.</li> </ul> <h1>Wie Onionhop unter Windows den Datenverkehr über virtuelle Netzwerkschnittstellen (TUN) lenkt</h1> <p>Die Magie passiert über <strong>virtuelle Netzwerkschnittstellen (TUN-Modus)</strong> und gezielte Manipulation der <strong>Wegfindung (Routing)</strong>.</p> <h1>1. Der virtuelle Netzwerktreiber</h1> <p>Windows nutzt für Netzwerkkarten die sogenannte <em>Network Driver Interface Specification</em> (NDIS). Tools wie Onionhop installieren einen virtuellen Treiber (oft auf Basis von Wintun).</p> <p>Auf der Ebene des <strong>Betriebssystemkerns (Kernel-Ebene)</strong> ist dieser Treiber eine vollwertige Netzwerkkarte. Das System sieht absolut keinen Unterschied zu eurem echten WLAN-Modul oder Netzwerkkabel. Dieser Adapter arbeitet auf der <strong>Vermittlungsschicht (Layer 3)</strong>. Er verarbeitet also reine IP-Datenpakete (Internetprotokoll) und simuliert keine Hardware-Adressen (MAC-Adressen) der tieferen Schichten.</p> <h1>2. Die Übernahme der Wegfindung (Routing)</h1> <p>Damit Windows die Daten nicht ans WLAN, sondern an Onionhop schickt, wird die <strong>Wegfindungstabelle (Routingtabelle)</strong> dynamisch angepasst, sobald die Verbindung steht:</p> <ul> <li>Onionhop fügt eine neue Standardroute (<code>0.0.0.0/0</code> – also den Weg für "alle unbekannten Ziele im Internet") hinzu, die auf die virtuelle TUN-Schnittstelle zeigt.</li> <li>Der entscheidende Trick: Diese neue Route bekommt einen niedrigeren <strong>Prioritätswert (Metrik)</strong> als der echte WLAN-Adapter. Da Windows bei konkurrierenden Routen immer den Weg mit dem niedrigsten Wert wählt, fließt der gesamte ausgehende Datenverkehr des Systems ab sofort in den virtuellen Tunnel.</li> </ul> <h1>3. Datenkapselung im Anwendungsbereich (User-Space)</h1> <p>Jetzt landen die Daten (Nutzdaten) bei der Onionhop-Anwendung, die als Hintergrunddienst läuft:</p> <ol> <li>Die Anwendung lauscht an der virtuellen Schnittstelle und fängt die IP-Pakete ab.</li> <li>Sie verschlüsselt diese Nutzdaten.</li> <li>Die verschlüsselten Pakete werden nun mit einer neuen Ziel-IP versehen (dem ersten Knotenpunkt im Onion-Netzwerk). Das nennt man <strong>Datenkapselung (Encapsulation)</strong>.</li> <li>Erst jetzt übergibt Onionhop diese neu verpackten Pakete wieder an den Windows-Netzwerkstapel.</li> </ol> <p>Die Wegfindungstabelle von Windows sieht nun diese spezifische Ziel-IP des Einsteiger-Knotens und weiß: <em>"Ah, diese IP muss über das echte Standard-Gateway des physischen WLAN-Adapters raus."</em></p> <p>Der echte WLAN-Adapter dient also nur noch als reines Transportmedium für den bereits gekapselten und verschlüsselten Datenverkehr. Die eigentlichen Programme (wie der Browser) denken währenddessen, sie sprechen mit einer ganz normalen Netzwerkkarte.</p> <p><strong>Zum Selbstprüfen für die Kommandozeile:</strong></p> <p>Wer sich das beim Testen von Onionhop live ansehen will, kann die PowerShell nutzen:</p> <ul> <li><strong>Versteckte Schnittstellen anzeigen:</strong></li> <li><code>PowerShellGet-NetAdapter -IncludeHidden</code></li> <li><strong>Wegfindung und Prioritäten prüfen:</strong></li> <li><code>PowerShellGet-NetRoute -DestinationPrefix "0.0.0.0/0"</code></li> </ul> <h1>Was ist die Abgrenzung zu einem "echten" VPN wie z.B. ProtonVPN?</h1> <table><thead> <tr> <th align="left"><strong>Eigenschaft</strong></th> <th align="left"><strong>OnionHop (Tor-Netzwerk)</strong></th> <th align="left"><strong>Klassisches VPN (z.B. ProtonVPN)</strong></th> </tr> </thead><tbody> <tr> <td align="left"><strong>Architektur</strong></td> <td align="left"><strong>Dezentral.</strong> Deine Daten fließen über drei zufällige, weltweit verteilte Knotenpunkte.</td> <td align="left"><strong>Zentralisiert.</strong> Deine Daten fließen direkt durch einen festen Server des VPN-Anbieters.</td> </tr> <tr> <td align="left"><strong>Vertrauensmodell</strong></td> <td align="left"><strong>Trustless.</strong> Du musst niemandem vertrauen. Der erste Knoten kennt dich (aber nicht das Ziel), der letzte Knoten kennt das Ziel (aber nicht dich).</td> <td align="left"><strong>Vertrauensbasiert.</strong> Du musst deinem VPN Anbieter zu 100 % vertrauen, da sie deinen gesamten unverschlüsselten Datenverkehr sehen können.</td> </tr> <tr> <td align="left"><strong>Protokolle</strong></td> <td align="left">Tor transportiert prinzipbedingt <strong>nur TCP-Verbindungen</strong>. UDP (wichtig für Online-Spiele oder VoIP) wird blockiert.</td> <td align="left">Überträgt TCP, UDP und oft auch ICMP (Ping) vollständig. Eigenschaft OnionHop (Tor-Netzwerk) Klassisches VPN (z.B. ProtonVPN) Architektur Dezentral. Deine Daten fließen über drei zufällige, weltweit verteilte Knotenpunkte. Zentralisiert. Deine Daten fließen direkt durch einen festen Server des VPN-Anbieters. Vertrauensmodell Trustless. Du musst niemandem vertrauen. Der erste Knoten kennt dich (aber nicht das Ziel), der letzte Knoten kennt das Ziel (aber nicht dich). Vertrauensbasiert. Du musst deinem VPN Anbieter zu 100 % vertrauen, da sie deinen gesamten unverschlüsselten Datenverkehr sehen können.Protokolle Tor transportiert prinzipbedingt nur TCP-Verbindungen. UDP (wichtig für Online-Spiele oder VoIP) wird blockiert. Überträgt TCP, UDP und oft auch ICMP (Ping) vollständig.</td> </tr> </tbody></table> <h1>Das Virtuelle Private Netzwerk (VPN): Tiefer Eingriff auf Schicht 2 und 3</h1> <p>Ein VPN verhält sich für das Betriebssystem wie eine echte, physische Netzwerkkarte – nur eben als virtuelle Variante (Netzwerkschnittstelle). Es greift tief in das System ein und fängt den gesamten Datenverkehr ab, bevor dieser das Gerät verlässt.</p> <ul> <li><strong>Auf der Vermittlungsschicht (Schicht 3 / Network Layer):</strong> Hier arbeiten die meisten modernen VPN-Verbindungen (wie WireGuard oder IPsec). Sie verpacken (kapseln) komplette IP-Datenpakete. Das bedeutet, dass die gesamte Netzkopplung (Routing) übernommen wird. Jeder Datenverkehr – egal ob gesicherte Verbindungsaufbauten (TCP), verbindungslose Übertragungen (UDP) oder Diagnoseabfragen (ICMP, wie bei einem Ping) – wird in den verschlüsselten Tunnel gezwungen.</li> <li><strong>Auf der Sicherungsschicht (Schicht 2 / Data Link Layer):</strong> Einige VPN-Lösungen beherrschen auch die sogenannte Netzwerküberbrückung (Bridging, z. B. OpenVPN im TAP-Modus). Hier werden die rohen Datenrahmen (Ethernet Frames) übertragen. Das System verhält sich so, als wären alle Rechner über hunderte Kilometer hinweg an denselben physischen Netzwerkverteiler (Switch) angeschlossen. In diesem Modus werden sogar lokale Netzwerk-Rundrufe (Broadcasts) durch den Tunnel übertragen.</li> </ul> <h1>Das Zwiebelnetzwerk (Tor): Aufsatz auf Schicht 4 und 7</h1> <p>Tor arbeitet architektonisch völlig anders und hat mit den unteren Netzwerkschichten (Schicht 2 und 3) primär nichts zu tun. Es erstellt keine virtuelle Netzwerkkarte im Betriebssystem.</p> <ul> <li><strong>Anwendungsschicht (Schicht 7) &amp; Transportschicht (Schicht 4):</strong> Das Tor-Programm läuft lokal als Stellvertreter-Dienst (SOCKS-Proxy). Eure Software (z. B. der Browser) muss explizit so konfiguriert werden, dass sie diesen Stellvertreter anspricht. Tor nimmt diese Anfragen entgegen und wickelt den Datenstrom ausschließlich über die Transportschicht ab – und hier auch <strong>nur für das TCP-Protokoll</strong>.</li> <li><strong>Keine rohen Pakete:</strong> Tor transportiert keine IP-Datenpakete (Schicht 3) und keine Ethernet-Datenrahmen (Schicht 2). Verbindungslose UDP-Pakete oder simple Ping-Abfragen (ICMP) werden vom Tor-Netzwerk schlichtweg nicht weitergeleitet.</li> </ul> <h1>Die Konsequenz für die IT-Sicherheit (Datenlecks)</h1> <p>Aus Sicht der Informationssicherheit ergibt sich daraus ein massiver Unterschied im Gefahrenpotenzial:</p> <p>Da ein klassisches VPN auf der <strong>Vermittlungsschicht (Schicht 3)</strong> arbeitet, fängt es als Standard-Netzweg (Default Gateway) den <em>gesamten</em> Verkehr des Betriebssystems ein.</p> <p>Das Zwiebelnetzwerk hingegen ist stark anfällig für Datenlecks (Leakage), da es auf <strong>Schicht 4 und 7</strong> operiert. Wenn eine Anwendung auf dem Rechner nicht strikt an den Tor-Stellvertreter (Proxy) gebunden ist, oder wenn sie versucht, über das verbindungslose UDP-Protokoll eine Namensauflösung (DNS-Anfrage) durchzuführen, wandern diese Datenpakete unverschlüsselt am Zwiebelnetzwerk vorbei ins normale Internet. Eure echte IP-Adresse wäre in diesem Fall sofort enttarnt. Um Tor so abzusichern, dass es wie ein VPN den gesamten Rechnerverkehr schützt (auf Schicht 3 erzwingt), bedarf es spezialisierter Betriebssysteme wie <a href="https://tails.net/">Tails</a> oder dedizierter Hardware-Zwischenstationen.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Horus_Sirius"> /u/Horus_Sirius </a> <br> <span><a href="https://www.onionhop.de/">[link]</a></span>   <span><a href="https://www.reddit.com/r/Computersicherheit/comments/1v3vcph/digitale_selbstbestimmung_onionhop_leitet_euren/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tails 7.6.1]]></title>
<description><![CDATA[This release is an emergency release to fix important security
vulnerabilities in Tor Browser.

Changes and updates



Update Tor Browser to
15.0.9, which
fixes several vulnerabilities in Firefox
140.9.0.



We are not aware of these vulnerabilities being exploited in practice.



Update the Tor ...]]></description>
<link>https://tsecurity.de/de/3687675/it-security-tools/tails-761/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687675/it-security-tools/tails-761/</guid>
<pubDate>Wed, 22 Jul 2026 23:53:43 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This release is an emergency release to fix important security
vulnerabilities in <em>Tor Browser</em>.</p>

<h1>Changes and updates</h1>


<ul>
<li><p>Update <em>Tor Browser</em> to
<a href="https://blog.torproject.org/new-release-tor-browser-1509">15.0.9</a>, which
fixes <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2026-27/">several vulnerabilities in <em>Firefox</em>
140.9.0</a>.</p>

<div class="attack">

<p>We are not aware of these vulnerabilities being exploited in practice.</p>

</div>
</li>
<li><p>Update the <em>Tor</em> client to 0.4.9.6.</p></li>
<li><p>Update <em>Thunderbird</em> to <a href="https://www.thunderbird.net/en-US/thunderbird/140.9.0esr/releasenotes/">140.9.0</a>.</p></li>
<li><p>Update some firmware packages. This improves support for newer hardware:
graphics, Wi-Fi, and so on.</p></li>
</ul>


<p>For more details, read our <a href="https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog">changelog</a>.</p>

<h1>Get Tails 7.6.1</h1>


<h2>To upgrade your Tails USB stick and keep your Persistent Storage</h2>

<ul>
<li><p>Automatic upgrades are available from Tails 7.0 or later to 7.6.1.</p></li>
<li><p>If you cannot do an automatic upgrade or if Tails fails to start after an
automatic upgrade, please try to do a <a href="https://tails.net/doc/upgrade/index.en.html#manual">manual upgrade</a>.</p></li>
</ul>


<h2>To install Tails 7.6.1 on a new USB stick</h2>

<p>Follow our installation instructions:</p>

<ul>
<li><p><a href="https://tails.net/install/windows/index.en.html">Install from Windows</a></p></li>
<li><p><a href="https://tails.net/install/mac/index.en.html">Install from macOS</a></p></li>
<li><p><a href="https://tails.net/install/linux/index.en.html">Install from Linux</a></p></li>
<li><p><a href="https://tails.net/install/expert/index.en.html">Install from Debian or Ubuntu using the command line and GnuPG</a></p></li>
</ul>


<div class="caution"><p>The Persistent Storage on the USB stick will be lost if
you install instead of upgrading.</p></div>


<h2>To download only</h2>

<p>If you don't need installation or upgrade instructions, you can download
Tails 7.6.1 directly:</p>

<ul>
<li><p><a href="https://tails.net/install/download/index.en.html">For USB sticks (USB image)</a></p></li>
<li><p><a href="https://tails.net/install/download-iso/index.en.html">For DVDs and virtual machines (ISO image)</a></p></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tails 7.6.2]]></title>
<description><![CDATA[This release is an emergency release to fix an important security
vulnerability in the confinement of Tor Browser.

Changes and updates



Update Flatpak to 1.16.6, which fixes
CVE-2026-34078, a major
sandbox escape vulnerability. Using this vulnerability, an attacker could
break the security con...]]></description>
<link>https://tsecurity.de/de/3687674/it-security-tools/tails-762/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687674/it-security-tools/tails-762/</guid>
<pubDate>Wed, 22 Jul 2026 23:53:42 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This release is an emergency release to fix an important security
vulnerability in the confinement of <em>Tor Browser</em>.</p>

<h1>Changes and updates</h1>


<ul>
<li><p>Update <em>Flatpak</em> to 1.16.6, which fixes
<a href="https://www.cve.org/CVERecord?id=CVE-2026-34078">CVE-2026-34078</a>, a major
sandbox escape vulnerability. Using this vulnerability, an attacker could
break the <a href="https://tails.net/doc/anonymous_internet/Tor_Browser/index.en.html#confinement">security confinement of <em>Tor
Browser</em></a> and access all
files that don't require an administration password, including in the
Persistent Storage.</p>

<div class="attack">

<p>This vulnerability can only be exploited by a powerful attacker who has
already exploited another vulnerability to take control of <i>Tor
Browser</i>.</p>

</div>
</li>
</ul>


<p>For more details, read our <a href="https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog">changelog</a>.</p>

<h1>Get Tails 7.6.2</h1>


<h2>To upgrade your Tails USB stick and keep your Persistent Storage</h2>

<ul>
<li><p>Automatic upgrades are available from Tails 7.0 or later to 7.6.2.</p></li>
<li><p>If you cannot do an automatic upgrade or if Tails fails to start after an
automatic upgrade, please try to do a <a href="https://tails.net/doc/upgrade/index.en.html#manual">manual upgrade</a>.</p></li>
</ul>


<h2>To install Tails 7.6.2 on a new USB stick</h2>

<p>Follow our <a href="https://tails.net/install/index.en.html">installation instructions</a>.</p>

<div class="caution"><p>The Persistent Storage on the USB stick will be lost if
you install instead of upgrading.</p></div>


<h2>To download only</h2>

<p>If you don't need installation or upgrade instructions, you can download
Tails 7.6.2 directly:</p>

<ul>
<li><p><a href="https://tails.net/install/download/index.en.html">For USB sticks (USB image)</a></p></li>
<li><p><a href="https://tails.net/install/download-iso/index.en.html">For DVDs and virtual machines (ISO image)</a></p></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tails 7.7]]></title>
<description><![CDATA[New feature


Detection of outdated Secure Boot certificates

Since 2023, Microsoft has started
replacing
the Secure Boot certificates originally issued in 2011. These older certificates
begin expiring in June 2026.

Tails now notifies you if the computer that you are using has outdated Secure
Bo...]]></description>
<link>https://tsecurity.de/de/3687673/it-security-tools/tails-77/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687673/it-security-tools/tails-77/</guid>
<pubDate>Wed, 22 Jul 2026 23:53:41 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>New feature</h1>


<h2>Detection of outdated Secure Boot certificates</h2>

<p>Since 2023, <a href="https://support.microsoft.com/en-us/topic/windows-secure-boot-certificate-expiration-and-ca-updates-7ff40d33-95dc-4c3c-8725-a9b95457578e">Microsoft has started
replacing</a>
the Secure Boot certificates originally issued in 2011. These older certificates
begin expiring in June 2026.</p>

<p>Tails now notifies you if the computer that you are using <a href="https://tails.net/support/known_issues/secure_boot_certificates/index.en.html">has outdated Secure
Boot certificates and needs an
update</a>.</p>

<p><a href="https://tails.net/support/known_issues/secure_boot_certificates/secure_boot_update_needed.png"><img alt="Notification: Secure Boot Update Needed" class="screenshot" height="247" src="https://tails.net/support/known_issues/secure_boot_certificates/secure_boot_update_needed.png" width="585"></a></p>

<h1>Changes and updates</h1>


<ul>
<li><p>Update <em>Tor Browser</em> to <a href="https://blog.torproject.org/new-release-tor-browser-15010/">15.0.10</a>.</p></li>
<li><p>Update <em>Thunderbird</em> to <a href="https://www.thunderbird.net/en-US/thunderbird/140.9.1esr/releasenotes/">140.9.1</a>.</p></li>
</ul>


<h1>Fixed problems</h1>


<ul>
<li>Make the <em>/root</em> folder only readable by the <code>root</code> user. (<a href="https://gitlab.tails.boum.org/tails/tails/-/work_items/21514">#21514</a>)</li>
</ul>


<p>For more details, read our <a href="https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog">changelog</a>.</p>

<h1>Get Tails 7.7</h1>


<h2>To upgrade your Tails USB stick and keep your Persistent Storage</h2>

<ul>
<li><p>Automatic upgrades are available from Tails 7.0 or later to 7.7.</p></li>
<li><p>If you cannot do an automatic upgrade or if Tails fails to start after an
automatic upgrade, please try to do a <a href="https://tails.net/doc/upgrade/index.en.html#manual">manual upgrade</a>.</p></li>
</ul>


<h2>To install Tails 7.7 on a new USB stick</h2>

<p>Follow our <a href="https://tails.net/install/index.en.html">installation instructions</a>.</p>

<div class="caution"><p>The Persistent Storage on the USB stick will be lost if
you install instead of upgrading.</p></div>


<h2>To download only</h2>

<p>If you don't need installation or upgrade instructions, you can download
Tails 7.7 directly:</p>

<ul>
<li><p><a href="https://tails.net/install/download/index.en.html">For USB sticks (USB image)</a></p></li>
<li><p><a href="https://tails.net/install/download-iso/index.en.html">For DVDs and virtual machines (ISO image)</a></p></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tails 7.7.1]]></title>
<description><![CDATA[This release is an emergency release to fix important security
vulnerabilities in Tor Browser.

Changes and updates



Update Tor Browser to
15.0.11, which
fixes several vulnerabilities in Firefox
140.10.1.



We are not aware of these vulnerabilities being exploited in practice until now.



Upd...]]></description>
<link>https://tsecurity.de/de/3687672/it-security-tools/tails-771/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687672/it-security-tools/tails-771/</guid>
<pubDate>Wed, 22 Jul 2026 23:53:39 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This release is an emergency release to fix important security
vulnerabilities in <em>Tor Browser</em>.</p>

<h1>Changes and updates</h1>


<ul>
<li><p>Update <em>Tor Browser</em> to
<a href="https://blog.torproject.org/new-release-tor-browser-15011/">15.0.11</a>, which
fixes <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2026-36/">several vulnerabilities in <em>Firefox</em>
140.10.1</a>.</p>

<div class="attack">

<p>We are not aware of these vulnerabilities being exploited in practice until now.</p>

</div>
</li>
<li><p>Update <em>Thunderbird</em> to <a href="https://www.thunderbird.net/en-US/thunderbird/140.10.0esr/releasenotes/">140.10.0</a>.</p></li>
<li><p>Stop making it possible to start our ISO images from a USB stick.</p>

<p>Since <a href="https://tails.net/news/version_3.12/">2019</a>, we recommend <em>USB images</em> to start Tails
from a USB stick, which is by far the most common way of running Tails.</p>

<p>We still distribute <a href="https://tails.net/install/download-iso/index.en.html"><em>ISO images</em></a> to start Tails from
a DVD or in a virtual machine. Until now, these ISO images worked on USB
sticks as well, but provided a degraded experience without automatic upgrades
or Persistent Storage.</p>

<p>Our ISO images no longer work on USB sticks to save a few megabytes and
prevent confusion for people who use USB sticks.</p></li>
</ul>


<p>For more details, read our <a href="https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog">changelog</a>.</p>

<h1>Get Tails 7.7.1</h1>


<h2>To upgrade your Tails USB stick and keep your Persistent Storage</h2>

<ul>
<li><p>Automatic upgrades are available from Tails 7.0 or later to 7.7.1.</p></li>
<li><p>If you cannot do an automatic upgrade or if Tails fails to start after an
automatic upgrade, please try to do a <a href="https://tails.net/doc/upgrade/index.en.html#manual">manual upgrade</a>.</p></li>
</ul>


<h2>To install Tails 7.7.1 on a new USB stick</h2>

<p>Follow our <a href="https://tails.net/install/index.en.html">installation instructions</a>.</p>

<div class="caution"><p>The Persistent Storage on the USB stick will be lost if
you install instead of upgrading.</p></div>


<h2>To download only</h2>

<p>If you don't need installation or upgrade instructions, you can download
Tails 7.7.1 directly:</p>

<ul>
<li><p><a href="https://tails.net/install/download/index.en.html">For USB sticks (USB image)</a></p></li>
<li><p><a href="https://tails.net/install/download-iso/index.en.html">For DVDs and virtual machines (ISO image)</a></p></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tails 7.7.2]]></title>
<description><![CDATA[This release is an emergency release to fix a critical security
vulnerability in the Linux kernel.

Changes and updates



Update the Linux kernel to 6.12.85, which fixes Copy
Fail, a vulnerability that could allow an application in
Tails to gain administration privileges.

For example, if an att...]]></description>
<link>https://tsecurity.de/de/3687671/it-security-tools/tails-772/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687671/it-security-tools/tails-772/</guid>
<pubDate>Wed, 22 Jul 2026 23:53:38 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This release is an emergency release to fix a critical security
vulnerability in the Linux kernel.</p>

<h1>Changes and updates</h1>


<ul>
<li><p>Update the <em>Linux</em> kernel to 6.12.85, which fixes <a href="https://copy.fail/">Copy
Fail</a>, a vulnerability that could allow an application in
Tails to gain administration privileges.</p>

<p>For example, if an attacker was able to exploit other unknown security
vulnerabilities in an application included in Tails, they might then use Copy
Fail to take full control of your Tails and deanonymize you.</p>

<div class="attack">

<p>We are not aware of this vulnerability being used in practice until now.</p>

</div>
</li>
</ul>


<h1>Fixed problems</h1>


<p>For more details, read our <a href="https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog">changelog</a>.</p>

<h1>Get Tails 7.7.2</h1>


<h2>To upgrade your Tails USB stick and keep your Persistent Storage</h2>

<ul>
<li><p>Automatic upgrades are available from Tails 7.0 or later to 7.7.2.</p></li>
<li><p>If you cannot do an automatic upgrade or if Tails fails to start after an
automatic upgrade, please try to do a <a href="https://tails.net/doc/upgrade/index.en.html#manual">manual upgrade</a>.</p></li>
</ul>


<h2>To install Tails 7.7.2 on a new USB stick</h2>

<p>Follow our <a href="https://tails.net/install/index.en.html">installation instructions</a>.</p>

<div class="caution"><p>The Persistent Storage on the USB stick will be lost if
you install instead of upgrading.</p></div>


<h2>To download only</h2>

<p>If you don't need installation or upgrade instructions, you can download
Tails 7.7.2 directly:</p>

<ul>
<li><p><a href="https://tails.net/install/download/index.en.html">For USB sticks (USB image)</a></p></li>
<li><p><a href="https://tails.net/install/download-iso/index.en.html">For DVDs and virtual machines (ISO image)</a></p></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tails 7.7.3]]></title>
<description><![CDATA[This release is an emergency release to fix a critical security vulnerability in
the Linux kernel, as well as security vulnerabilities in Tor Browser and in
the Tor client.

Changes and updates



Update the Linux kernel to 6.12.86, which fixes Dirty
Frag, a vulnerability that could allow an appl...]]></description>
<link>https://tsecurity.de/de/3687670/it-security-tools/tails-773/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687670/it-security-tools/tails-773/</guid>
<pubDate>Wed, 22 Jul 2026 23:53:37 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This release is an emergency release to fix a critical security vulnerability in
the Linux kernel, as well as security vulnerabilities in <em>Tor Browser</em> and in
the <em>Tor</em> client.</p>

<h1>Changes and updates</h1>


<ul>
<li><p>Update the <em>Linux</em> kernel to 6.12.86, which fixes <a href="https://github.com/V4bel/dirtyfrag">Dirty
Frag</a>, a vulnerability that could allow an application in
Tails to gain administration privileges.</p>

<p>For example, if an attacker was able to exploit other unknown security
vulnerabilities in an application included in Tails, they might then use Dirty
Frag to take full control of your Tails and deanonymize you.</p>

<div class="attack">

<p>We are not aware of this vulnerability being used in practice until now.</p>

</div>
</li>
<li><p>Update <em>Tor Browser</em> to <a href="https://blog.torproject.org/new-release-tor-browser-15012/">15.0.12</a>.</p></li>
<li><p>Update the <em>Tor</em> client to 0.4.9.8.</p></li>
<li><p>Update <em>Thunderbird</em> to <a href="https://www.thunderbird.net/en-US/thunderbird/140.10.1esr/releasenotes/">140.10.1</a>.</p></li>
</ul>


<h1>Fixed problems</h1>


<p>For more details, read our <a href="https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog">changelog</a>.</p>

<h1>Get Tails 7.7.3</h1>


<h2>To upgrade your Tails USB stick and keep your Persistent Storage</h2>

<ul>
<li><p>Automatic upgrades are available from Tails 7.0 or later to 7.7.3.</p></li>
<li><p>If you cannot do an automatic upgrade or if Tails fails to start after an
automatic upgrade, please try to do a <a href="https://tails.net/doc/upgrade/index.en.html#manual">manual upgrade</a>.</p></li>
</ul>


<h2>To install Tails 7.7.3 on a new USB stick</h2>

<p>Follow our <a href="https://tails.net/install/index.en.html">installation instructions</a>.</p>

<div class="caution"><p>The Persistent Storage on the USB stick will be lost if
you install instead of upgrading.</p></div>


<h2>To download only</h2>

<p>If you don't need installation or upgrade instructions, you can download
Tails 7.7.3 directly:</p>

<ul>
<li><p><a href="https://tails.net/install/download/index.en.html">For USB sticks (USB image)</a></p></li>
<li><p><a href="https://tails.net/install/download-iso/index.en.html">For DVDs and virtual machines (ISO image)</a></p></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tails 7.8]]></title>
<description><![CDATA[Changes and updates



Update Tor Browser to 15.0.14.
Remove Thunderbird.

You can still install Thunderbird as additional
software.

If you have both the Thunderbird Email Client and Additional Software
features of the Persistent Storage turned on, Tails automatically adds
Thunderbird to your li...]]></description>
<link>https://tsecurity.de/de/3687669/it-security-tools/tails-78/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687669/it-security-tools/tails-78/</guid>
<pubDate>Wed, 22 Jul 2026 23:53:36 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Changes and updates</h1>


<ul>
<li><p>Update <em>Tor Browser</em> to <a href="https://blog.torproject.org/new-release-tor-browser-15014/">15.0.14</a>.</p></li>
<li><p>Remove <em>Thunderbird</em>.</p>

<p>You can still <a href="https://tails.net/doc/anonymous_internet/thunderbird/index.en.html">install <em>Thunderbird</em> as additional
software</a>.</p>

<p>If you have both the <strong>Thunderbird Email Client</strong> and <strong>Additional Software</strong>
features of the Persistent Storage turned on, Tails automatically adds
<em>Thunderbird</em> to your list of <a href="https://tails.net/doc/persistent_storage/additional_software/index.en.html">additional
software</a>.</p>

<p>A new version of <em>Thunderbird</em> is released in Debian shortly after each Tails
release, because both <em>Tails</em> and <em>Thunderbird</em> follow the <a href="https://whattrainisitnow.com/calendar/">release calendar
of <em>Firefox</em></a>. As a consequence,
until Tails 7.5 (February 2026), the version of <em>Thunderbird</em> in Tails was
almost always outdated, with known security vulnerabilities.</p>

<p>By installing <em>Thunderbird</em> as additional software, the latest version
of <em>Thunderbird</em> is installed automatically from your Persistent Storage each
time you start Tails.</p></li>
</ul>


<h1>Fixed problems</h1>


<ul>
<li><p>Fix multiple security vulnerabilities in the Linux kernel and haveged, that
could allow an application in Tails to gain administration privileges.</p>

<p>For example, if an attacker was able to exploit other unknown security
vulnerabilities in an application included in Tails, they might then use one
of these vulnerabilities to take full control of your Tails and
deanonymize you.</p></li>
</ul>


<p>For more details, read our <a href="https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog">changelog</a>.</p>

<h1>Get Tails 7.8</h1>


<h2>To upgrade your Tails USB stick and keep your Persistent Storage</h2>

<ul>
<li><p>Automatic upgrades are available from Tails 7.0 or later to 7.8.</p></li>
<li><p>If you cannot do an automatic upgrade or if Tails fails to start after an
automatic upgrade, please try to do a <a href="https://tails.net/doc/upgrade/index.en.html#manual">manual upgrade</a>.</p></li>
</ul>


<h2>To install Tails 7.8 on a new USB stick</h2>

<p>Follow our installation instructions:</p>

<ul>
<li><p><a href="https://tails.net/install/windows/index.en.html">Install from Windows</a></p></li>
<li><p><a href="https://tails.net/install/mac/index.en.html">Install from macOS</a></p></li>
<li><p><a href="https://tails.net/install/linux/index.en.html">Install from Linux</a></p></li>
<li><p><a href="https://tails.net/install/expert/index.en.html">Install from Debian or Ubuntu using the command line and GnuPG</a></p></li>
</ul>


<div class="caution"><p>The Persistent Storage on the USB stick will be lost if
you install instead of upgrading.</p></div>


<h2>To download only</h2>

<p>If you don't need installation or upgrade instructions, you can download
Tails 7.8 directly:</p>

<ul>
<li><p><a href="https://tails.net/install/download/index.en.html">For USB sticks (USB image)</a></p></li>
<li><p><a href="https://tails.net/install/download-iso/index.en.html">For DVDs and virtual machines (ISO image)</a></p></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tails 7.8.1]]></title>
<description><![CDATA[This release is an emergency release to fix a serious security vulnerability in
the Linux kernel, as well as security vulnerabilities in the Tor client.

Changes and updates



Update the Tor client to 0.4.9.9, which fixes several security
vulnerabilities.
Update the Linux kernel to 6.12.90-2, wh...]]></description>
<link>https://tsecurity.de/de/3687668/it-security-tools/tails-781/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687668/it-security-tools/tails-781/</guid>
<pubDate>Wed, 22 Jul 2026 23:53:34 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This release is an emergency release to fix a serious security vulnerability in
the Linux kernel, as well as security vulnerabilities in the <em>Tor</em> client.</p>

<h1>Changes and updates</h1>


<ul>
<li><p>Update the <em>Tor</em> client to 0.4.9.9, which fixes <a href="https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ReleaseNotes">several security
vulnerabilities</a>.</p></li>
<li><p>Update the <em>Linux</em> kernel to 6.12.90-2, which fixes
<a href="https://security-tracker.debian.org/tracker/CVE-2026-43503">CVE-2026-43503</a>,
a vulnerability that could allow an application in Tails to gain
administration privileges.</p>

<p>For example, if an attacker was able to exploit other unknown security
vulnerabilities in an application included in Tails, they might then use this
vulnerability to take full control of your Tails and deanonymize you.</p>

<div class="attack">

<p>This attack is very unlikely, but could be performed by a strong attacker,
such as a government or a hacking firm. We are not aware of this vulnerability
being used in practice until now.</p>

</div>
</li>
</ul>


<h1>Fixed problems</h1>


<ul>
<li>Fix a fingerprinting issue in the <em>Unsafe Browser</em>. (<a href="https://gitlab.tails.boum.org/tails/tails/-/work_items/21617">#21617</a>)</li>
</ul>


<h1>Get Tails 7.8.1</h1>


<h2>To upgrade your Tails USB stick and keep your Persistent Storage</h2>

<ul>
<li><p>Automatic upgrades are available from Tails 7.0 or later to 7.8.1.</p></li>
<li><p>If you cannot do an automatic upgrade or if Tails fails to start after an
automatic upgrade, please try to do a <a href="https://tails.net/doc/upgrade/index.en.html#manual">manual upgrade</a>.</p></li>
</ul>


<h2>To install Tails 7.8.1 on a new USB stick</h2>

<p>Follow our <a href="https://tails.net/install/index.en.html">installation instructions</a>.</p>

<div class="caution"><p>The Persistent Storage on the USB stick will be lost if
you install instead of upgrading.</p></div>


<h2>To download only</h2>

<p>If you don't need installation or upgrade instructions, you can download
Tails 7.8.1 directly:</p>

<ul>
<li><p><a href="https://tails.net/install/download/index.en.html">For USB sticks (USB image)</a></p></li>
<li><p><a href="https://tails.net/install/download-iso/index.en.html">For DVDs and virtual machines (ISO image)</a></p></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tails 7.9]]></title>
<description><![CDATA[Changes and updates



Update Tor Browser to 15.0.16.
Update some firmware packages. This improves support for newer hardware:
graphics, Wi-Fi, and so on.



Fixed problems



Stop notifying about outdated Secure Boot
certificates in rare cases
where the certificates are already up to date. (#216...]]></description>
<link>https://tsecurity.de/de/3687667/it-security-tools/tails-79/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687667/it-security-tools/tails-79/</guid>
<pubDate>Wed, 22 Jul 2026 23:53:33 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Changes and updates</h1>


<ul>
<li><p>Update <em>Tor Browser</em> to <a href="https://blog.torproject.org/new-release-tor-browser-15016/">15.0.16</a>.</p></li>
<li><p>Update some firmware packages. This improves support for newer hardware:
graphics, Wi-Fi, and so on.</p></li>
</ul>


<h1>Fixed problems</h1>


<ul>
<li>Stop notifying about <a href="https://tails.net/support/known_issues/secure_boot_certificates/index.en.html">outdated Secure Boot
certificates</a> in rare cases
where the certificates are already up to date. (<a href="https://gitlab.tails.boum.org/tails/tails/-/work_items/21643">#21643</a>)</li>
</ul>


<p>For more details, read our <a href="https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog">changelog</a>.</p>

<h1>Get Tails 7.9</h1>


<h2>To upgrade your Tails USB stick and keep your Persistent Storage</h2>

<ul>
<li><p>Automatic upgrades are available from Tails 7.0 or later to 7.9.</p></li>
<li><p>If you cannot do an automatic upgrade or if Tails fails to start after an
automatic upgrade, please try to do a <a href="https://tails.net/doc/upgrade/index.en.html#manual">manual upgrade</a>.</p></li>
</ul>


<h2>To install Tails 7.9 on a new USB stick</h2>

<p>Follow our <a href="https://tails.net/install/index.en.html">installation instructions</a>.</p>

<div class="caution"><p>The Persistent Storage on the USB stick will be lost if
you install instead of upgrading.</p></div>


<h2>To download only</h2>

<p>If you don't need installation or upgrade instructions, you can download
Tails 7.9 directly:</p>

<ul>
<li><p><a href="https://tails.net/install/download/index.en.html">For USB sticks (USB image)</a></p></li>
<li><p><a href="https://tails.net/install/download-iso/index.en.html">For DVDs and virtual machines (ISO image)</a></p></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tails 7.9.1]]></title>
<description><![CDATA[Changes and updates



Update Tor Browser to 15.0.17.
Update the Tor client to 0.4.9.11.
Update the Linux kernel to 6.12.94, which fixes CVE-2026-43503 (DirtyClone) and CVE-2026-46331 (PACKET_EDIT_MEME),
vulnerabilities that could allow an application in
Tails to gain administration privileges.

...]]></description>
<link>https://tsecurity.de/de/3687666/it-security-tools/tails-791/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687666/it-security-tools/tails-791/</guid>
<pubDate>Wed, 22 Jul 2026 23:53:30 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Changes and updates</h1>


<ul>
<li><p>Update <em>Tor Browser</em> to <a href="https://blog.torproject.org/new-release-tor-browser-15017/">15.0.17</a>.</p></li>
<li><p>Update the <em>Tor</em> client to 0.4.9.11.</p></li>
<li><p>Update the <em>Linux</em> kernel to 6.12.94, which fixes <a href="https://www.cve.org/CVERecord?id=CVE-2026-43503">CVE-2026-43503</a> (<em>DirtyClone</em>) and <a href="https://www.cve.org/CVERecord?id=CVE-2026-46331">CVE-2026-46331</a> (<em>PACKET_EDIT_MEME</em>),
vulnerabilities that could allow an application in
Tails to gain administration privileges.</p>

<p>For example, if an attacker was able to exploit other unknown security
vulnerabilities in an application included in Tails, they might then use CVE-2026-46331
to take full control of your Tails and deanonymize you.</p>

<div class="attack">

<p>This attack is unlikely, but could be performed by a strong attacker,
such as a government or a hacking firm. We are not aware of this vulnerability being
used in practice until now.</p>

</div>
</li>
</ul>


<h1>Fixed problems</h1>


<p>For more details, read our <a href="https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog">changelog</a>.</p>

<h1>Get Tails 7.9.1</h1>


<h2>To upgrade your Tails USB stick and keep your Persistent Storage</h2>

<ul>
<li><p>Automatic upgrades are available from Tails 7.0 or later to 7.9.1.</p></li>
<li><p>If you cannot do an automatic upgrade or if Tails fails to start after an
automatic upgrade, please try to do a <a href="https://tails.net/doc/upgrade/index.en.html#manual">manual upgrade</a>.</p></li>
</ul>


<h2>To install Tails 7.9.1 on a new USB stick</h2>

<p>Follow our <a href="https://tails.net/install/index.en.html">installation instructions</a>.</p>

<div class="caution"><p>The Persistent Storage on the USB stick will be lost if
you install instead of upgrading.</p></div>


<h2>To download only</h2>

<p>If you don't need installation or upgrade instructions, you can download
Tails 7.9.1 directly:</p>

<ul>
<li><p><a href="https://tails.net/install/download/index.en.html">For USB sticks (USB image)</a></p></li>
<li><p><a href="https://tails.net/install/download-iso/index.en.html">For DVDs and virtual machines (ISO image)</a></p></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Release: Tor Browser 15.0.16]]></title>
<description><![CDATA[Tor Browser 15.0.16 is now available from the Tor Browser download page and also from our distribution directory.
This version includes important security updates to Firefox.
Send us your feedback
If you find a bug or have a suggestion for how we could improve this release, please let us know.
Fu...]]></description>
<link>https://tsecurity.de/de/3687544/it-security-tools/new-release-tor-browser-15016/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687544/it-security-tools/new-release-tor-browser-15016/</guid>
<pubDate>Wed, 22 Jul 2026 22:34:52 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article class="blog-post">
    <picture>
      <source media="(min-width:415px)" srcset="https://blog.torproject.org/new-release-tor-browser-15016/lead.webp" type="image/webp">
<source srcset="https://blog.torproject.org/new-release-tor-browser-15016/lead_small.webp" type="image/webp">

      <img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/new-release-tor-browser-15016/lead.png">
    </picture>
    <div class="body"><p>Tor Browser 15.0.16 is now available from the <a href="https://www.torproject.org/download/">Tor Browser download page</a> and also from our <a href="https://www.torproject.org/dist/torbrowser/15.0.16/">distribution directory</a>.</p>
<p>This version includes important <a href="https://www.mozilla.org/en-US/security/advisories/">security updates</a> to Firefox.</p>
<h2>Send us your feedback</h2>
<p>If you find a bug or have a suggestion for how we could improve this release, <a href="https://support.torproject.org/misc/bug-or-feedback/">please let us know</a>.</p>
<h2>Full changelog</h2>
<p>The <a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/raw/maint-15.0/projects/browser/Bundle-Data/Docs-TBB/ChangeLog.txt">full changelog</a> since Tor Browser 15.0.16 is:</p>
<ul>
<li>All Platforms<ul>
<li>Updated NoScript to 13.6.24.1984</li>
<li>Updated OpenSSL to 3.5.7</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45044">Bug tor-browser#45044</a>: NS 13.6.19.902 DocStartInjection regressed</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45046">Bug tor-browser#45046</a>: Rebase Tor Browser stable onto 140.12.0esr</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45054">Bug tor-browser#45054</a>: Backport Security Fixes from Firefox 152</li>
</ul>
</li>
<li>Windows + macOS + Linux<ul>
<li>Updated Firefox to 140.12.0esr</li>
</ul>
</li>
<li>Android<ul>
<li>Updated GeckoView to 140.12.0esr</li>
</ul>
</li>
<li>Build System<ul>
<li>All Platforms<ul>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41802">Bug tor-browser-build#41802</a>: Remove the tor daemon requirement for signing</li>
</ul>
</li>
<li>Windows + Linux + Android<ul>
<li>Updated Go to 1.25.11</li>
</ul>
</li>
</ul>
</li>
</ul>

    </div>
  <div class="categories">
    <ul><li>
        <a href="https://blog.torproject.org/category/applications">
          applications
        </a>
      </li><li>
        <a href="https://blog.torproject.org/category/releases">
          releases
        </a>
      </li></ul>
  </div>
  </article>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Release: Tails 7.9]]></title>
<description><![CDATA[Changes and updates

Update Tor Browser to 15.0.16.

Update some firmware packages. This improves support for newer hardware: graphics, Wi-Fi, and so on.


Fixed problems

Stop notifying about outdated Secure Boot certificates in rare cases where the certificates are already up to date. (#21643)
...]]></description>
<link>https://tsecurity.de/de/3687543/it-security-tools/new-release-tails-79/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687543/it-security-tools/new-release-tails-79/</guid>
<pubDate>Wed, 22 Jul 2026 22:34:51 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article class="blog-post">
    <picture>
      <source media="(min-width:415px)" srcset="https://blog.torproject.org/new-release-tails-7_9/lead.webp" type="image/webp">
<source srcset="https://blog.torproject.org/new-release-tails-7_9/lead_small.webp" type="image/webp">

      <img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/new-release-tails-7_9/lead.jpg">
    </picture>
    <div class="body"><h2>Changes and updates</h2>
<ul>
<li><p>Update <em>Tor Browser</em> to <a href="https://blog.torproject.org/new-release-tor-browser-15016/">15.0.16</a>.</p>
</li>
<li><p>Update some firmware packages. This improves support for newer hardware: graphics, Wi-Fi, and so on.</p>
</li>
</ul>
<h2>Fixed problems</h2>
<ul>
<li>Stop notifying about <a href="https://tails.net/support/known_issues/secure_boot_certificates/">outdated Secure Boot certificates</a> in rare cases where the certificates are already up to date. (<a href="https://gitlab.tails.boum.org/tails/tails/-/issues/21643">#21643</a>)</li>
</ul>
<p>For more details, read our
<a href="https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog">changelog</a>.</p>
<h2>Get Tails 7.9</h2>
<h3>To upgrade your Tails USB stick and keep your Persistent Storage</h3>
<ul>
<li><p>Automatic upgrades are available from Tails 7.0 or later to 7.9.</p>
</li>
<li><p>If you cannot do an automatic upgrade or if Tails fails to start after an automatic upgrade, please try to do a <a href="https://tails.net/doc/upgrade/#manual">manual upgrade</a>.</p>
</li>
</ul>
<h3>To install Tails 7.9 on a new USB stick</h3>
<p>Follow our <a href="https://tails.net/install/">installation instructions</a>.</p>
<p>The Persistent Storage on the USB stick will be lost if you install instead of
upgrading.</p>
<h3>To download only</h3>
<p>If you don't need installation or upgrade instructions, you can download Tails
7.9 directly:</p>
<ul>
<li><p><a href="https://tails.net/install/download/">For USB sticks (USB image)</a></p>
</li>
<li><p><a href="https://tails.net/install/download-iso/">For DVDs and virtual machines (ISO image)</a></p>
</li>
</ul>
<h2>Support and feedback</h2>
<p>For support and feedback, visit the <a href="https://tails.net/support/">Support
section</a> on the Tails website.</p>

    </div>
  <div class="categories">
    <ul><li>
        <a href="https://blog.torproject.org/category/tails">
          tails
        </a>
      </li><li>
        <a href="https://blog.torproject.org/category/releases">
          releases
        </a>
      </li></ul>
  </div>
  </article>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sunsetting Tor 0.4.8 – Please update to 0.4.9 by September]]></title>
<description><![CDATA[Hello Tor Community!
As you know, different teams inside the Tor Project are working on the Arti
Relay project where we hope to be able to begin the upgrade of the network
towards our Rust implementation of Tor in the near future. To support this
work, we would like to announce that we intend to ...]]></description>
<link>https://tsecurity.de/de/3687542/it-security-tools/sunsetting-tor-048-please-update-to-049-by-september/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687542/it-security-tools/sunsetting-tor-048-please-update-to-049-by-september/</guid>
<pubDate>Wed, 22 Jul 2026 22:34:49 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article class="blog-post">
    <picture>
      <source media="(min-width:415px)" srcset="https://blog.torproject.org/static/images/lead.webp" type="image/webp">
<source srcset="https://blog.torproject.org/static/images/lead_small.webp" type="image/webp">

      <img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/static/images/lead.png">
    </picture>
    <div class="body"><p>Hello Tor Community!</p>
<p>As you know, different teams inside the Tor Project are working on the Arti
Relay project where we hope to be able to begin the upgrade of the network
towards our Rust implementation of Tor in the near future. To support this
work, we would like to announce that we intend to actively stop compatibility
for 0.4.8 and earlier C Tor versions soon. This means that these versions will
<em>no longer work on the network at all</em> after our target date, which is
currently September 1st, 2026.</p>
<p>If you’re a Tor Browser user running an up-to-date version of Tor Browser, this
won't impact you. If you're running an older, perhaps not-so-well-maintained,
Onion Service somewhere, or you’re building an app that integrates C Tor, you
may want to read along here.</p>
<p><a href="https://gitlab.torproject.org/tpo/core/team/-/wikis/NetworkTeam/CoreTorReleases#list-of-releases">Tor 0.4.8 reached End of Life on the 1st of
June</a>,
and there will not be any more updates to this release series. We highly
encourage people to upgrade to the Tor 0.4.9 series (or later).</p>
<p>Usually, we try not to break existing releases, even if they are unsupported,
unless we have a pretty good reason. In this case, we have several reasons.
With the work towards Arti on both the client and relay, the Network Team has
identified a couple of features we would like to remove from the Tor ecosystem.
Removing support for 0.4.8 will help us facilitate a smooth transition, and reduce effort associated with
difficult to maintain features that provide very little value. Unfortunately,
because Tor’s Directory Protocol layer works the way it does, we cannot remove
these features without affecting older clients.</p>
<p>The most important reason is this: in 0.4.9, we have made some former fields in
our directory data obsolete -- specifically, <a href="https://spec.torproject.org/proposals/350-remove-tap.html">TAP onion
keys</a> and <a href="https://spec.torproject.org/proposals/321-happy-families.html">family
lines</a>. Removing
these fields will let us save a great deal of client directory bandwidth for
everyone.  This, in turn, will make all Tor clients bootstrap a little faster,
especially those on slow connections. But when we remove these fields, clients
and relays running earlier versions of Tor will no longer work, since they
expect the TAP onion keys to be present. Therefore, in order to deliver
improved performance faster, we need to accelerate the date on which 0.4.8 will
stop working.</p>
<p>The secondary reason for sunsetting 0.4.8: Our Arti directory authority
implementation needs network integration soon, and it will be easier to write
if it doesn’t support deprecated fields.</p>
<p>With this blog post out, we will begin reaching out to the downstreams of Tor
we identified as shipping older versions and try to get them to upgrade. We
appreciate community help here, too. If you identify that your favorite project
that bundles Tor uses an outdated version of Tor, please reach out to them and
(politely!) encourage them to upgrade. We are tracking some of this outreach in
<a href="https://gitlab.torproject.org/tpo/network-health/team/-/work_items/460">network-health/team#460</a>.
If you have a very good reason for needing a longer time with 0.4.8 support
than 1 September 2026, please let us know by leaving a comment on that ticket.</p>
<p>Thank you!</p>

    </div>
  <div class="categories">
    <ul><li>
        <a href="https://blog.torproject.org/category/tor">
          tor
        </a>
      </li></ul>
  </div>
  </article>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Release: Tor Browser 15.0.17]]></title>
<description><![CDATA[Tor Browser 15.0.17 is now available from the Tor Browser download page and also from our distribution directory.
This version includes important security updates to Tor.
Send us your feedback
If you find a bug or have a suggestion for how we could improve this release, please let us know.
Full c...]]></description>
<link>https://tsecurity.de/de/3687541/it-security-tools/new-release-tor-browser-15017/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687541/it-security-tools/new-release-tor-browser-15017/</guid>
<pubDate>Wed, 22 Jul 2026 22:34:41 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article class="blog-post">
    <picture>
      <source media="(min-width:415px)" srcset="https://blog.torproject.org/new-release-tor-browser-15017/lead.webp" type="image/webp">
<source srcset="https://blog.torproject.org/new-release-tor-browser-15017/lead_small.webp" type="image/webp">

      <img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/new-release-tor-browser-15017/lead.png">
    </picture>
    <div class="body"><p>Tor Browser 15.0.17 is now available from the <a href="https://www.torproject.org/download/">Tor Browser download page</a> and also from our <a href="https://www.torproject.org/dist/torbrowser/15.0.17/">distribution directory</a>.</p>
<p>This version includes important <a href="https://forum.torproject.org/t/security-release-0-4-9-11/21786">security updates</a> to Tor.</p>
<h2>Send us your feedback</h2>
<p>If you find a bug or have a suggestion for how we could improve this release, <a href="https://support.torproject.org/misc/bug-or-feedback/">please let us know</a>.</p>
<h2>Full changelog</h2>
<p>The <a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/raw/maint-15.0/projects/browser/Bundle-Data/Docs-TBB/ChangeLog.txt">full changelog</a> since Tor Browser 15.0.16 is:</p>
<ul>
<li>All Platforms<ul>
<li>Updated Tor to 0.4.9.11</li>
<li>Updated NoScript to 13.6.25.1984</li>
</ul>
</li>
<li>Build System<ul>
<li>All Platforms<ul>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41821">Bug tor-browser-build#41821</a>: Update gpg subkeys for boklm</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41827">Bug tor-browser-build#41827</a>: Update morgan's keychain with renewed key</li>
</ul>
</li>
</ul>
</li>
</ul>

    </div>
  <div class="categories">
    <ul><li>
        <a href="https://blog.torproject.org/category/applications">
          applications
        </a>
      </li><li>
        <a href="https://blog.torproject.org/category/releases">
          releases
        </a>
      </li></ul>
  </div>
  </article>]]></content:encoded>
</item>
<item>
<title><![CDATA[Arti 2.5.0 released: Stable Counter Galois Onion]]></title>
<description><![CDATA[Arti is our ongoing project to create a next-generation Tor implementation in
Rust.  We're happy to announce the latest release, Arti 2.5.0.
This release marks Counter Galois Onion as a stable feature and includes it in
full feature builds.  Likewise, Congestion Control is now enabled in default
...]]></description>
<link>https://tsecurity.de/de/3687540/it-security-tools/arti-250-released-stable-counter-galois-onion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687540/it-security-tools/arti-250-released-stable-counter-galois-onion/</guid>
<pubDate>Wed, 22 Jul 2026 22:34:39 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article class="blog-post">
    <picture>
      <source media="(min-width:415px)" srcset="https://blog.torproject.org/arti_2_5_0_released/lead.webp" type="image/webp">
<source srcset="https://blog.torproject.org/arti_2_5_0_released/lead_small.webp" type="image/webp">

      <img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/arti_2_5_0_released/lead.png">
    </picture>
    <div class="body"><p>Arti is our ongoing project to create a next-generation Tor implementation in
Rust.  We're happy to announce the latest release, Arti 2.5.0.</p>
<p>This release marks <a href="https://blog.torproject.org/introducing-cgo/">Counter Galois Onion</a> as a stable feature and includes it in
full feature builds.  Likewise, <a href="https://blog.torproject.org/congestion-contrl-047/">Congestion Control</a> is now enabled in default
builds of Arti, increasing the overall speed without any further configuration.</p>
<p>Unfortunately, this release also comes with the disclosure of two medium-severity
DoS security issues, <a href="https://gitlab.torproject.org/tpo/core/arti/-/work_items/2566">TROVE-2026-024</a> as well as <a href="https://gitlab.torproject.org/tpo/core/arti/-/work_items/2601">TROVE-2026-027</a>, whose fixes
are of course included within the release.</p>
<p>Additionally, this release continues our ongoing development towards using
Arti as a relay and as a directory authority.</p>
<p>Another noteworthy change is that we've increased our minimum supported Rust
version to Rust 1.91, released in October 2025.</p>
<p>Of course, this release also contains a number of bugfixes, cleanups, and
improvements throughout various parts of the code base.</p>
<p>For full details on what we've done, including API changes,
and for information about many more minor and less-visible changes,
please see the <a href="https://gitlab.torproject.org/tpo/core/arti/-/blob/main/CHANGELOG.md?ref_type=heads#arti-250--30-june-2026">CHANGELOG</a>.</p>
<p>For more information on using Arti, see our top-level <a href="https://gitlab.torproject.org/tpo/core/arti/-/blob/main/README.md">README</a>,
and the documentation for the <a href="https://gitlab.torproject.org/tpo/core/arti/-/blob/main/crates/arti/README.md"><code>arti</code> binary</a>.</p>
<p>Thanks to everybody who's contributed to this release, including
5225225, Neel Chauhan, hjrgrn, moumenalaoui, pryty26.</p>
<p>Also, our deep thanks to our <a href="https://www.torproject.org/about/sponsors/">sponsors</a> for funding the development of Arti!</p>

    </div>
  <div class="categories">
    <ul><li>
        <a href="https://blog.torproject.org/category/announcements">
          announcements
        </a>
      </li><li>
        <a href="https://blog.torproject.org/category/releases">
          releases
        </a>
      </li></ul>
  </div>
  </article>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Release: Tails 7.9.1]]></title>
<description><![CDATA[Changes and updates

Update Tor Browser to 15.0.17.

Update the Tor client to 0.4.9.11.

Update the Linux kernel to 6.12.94, which fixes
CVE-2026-43503 (DirtyClone) and
CVE-2026-46331 (PACKET_EDIT_MEME), vulnerabilities that could allow an application in Tails to gain administration privileges.

...]]></description>
<link>https://tsecurity.de/de/3687539/it-security-tools/new-release-tails-791/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687539/it-security-tools/new-release-tails-791/</guid>
<pubDate>Wed, 22 Jul 2026 22:34:16 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article class="blog-post">
    <picture>
      <source media="(min-width:415px)" srcset="https://blog.torproject.org/new-release-tails-7_9_1/lead.webp" type="image/webp">
<source srcset="https://blog.torproject.org/new-release-tails-7_9_1/lead_small.webp" type="image/webp">

      <img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/new-release-tails-7_9_1/lead.jpg">
    </picture>
    <div class="body"><h2>Changes and updates</h2>
<ul>
<li><p>Update <em>Tor Browser</em> to <a href="https://blog.torproject.org/new-release-tor-browser-15017/">15.0.17</a>.</p>
</li>
<li><p>Update the <em>Tor</em> client to 0.4.9.11.</p>
</li>
<li><p>Update the <em>Linux</em> kernel to 6.12.94, which fixes
<a href="https://www.cve.org/CVERecord?id=CVE-2026-43503">CVE-2026-43503</a> (<em>DirtyClone</em>) and
<a href="https://www.cve.org/CVERecord?id=CVE-2026-46331">CVE-2026-46331</a> (<em>PACKET_EDIT_MEME</em>), vulnerabilities that could allow an application in Tails to gain administration privileges.</p>
</li>
</ul>
<p>For example, if an attacker was able to exploit other unknown security
vulnerabilities in an application included in Tails, they might then use
CVE-2026-46331 to take full control of your Tails and deanonymize you.</p>
<p>This attack is unlikely, but could be performed by a strong attacker, such as
a government or a hacking firm. We are not aware of this vulnerability being
used in practice until now.</p>
<h2>Fixed problems</h2>
<p>For more details, read our
<a href="https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog">changelog</a>.</p>
<h2>Get Tails 7.9.1</h2>
<h3>To upgrade your Tails USB stick and keep your Persistent Storage</h3>
<ul>
<li><p>Automatic upgrades are available from Tails 7.0 or later to 7.9.1.</p>
</li>
<li><p>If you cannot do an automatic upgrade or if Tails fails to start after an automatic upgrade, please try to do a <a href="https://tails.net/doc/upgrade/#manual">manual upgrade</a>.</p>
</li>
</ul>
<h3>To install Tails 7.9.1 on a new USB stick</h3>
<p>Follow our <a href="https://tails.net/install/">installation instructions</a>.</p>
<p>The Persistent Storage on the USB stick will be lost if you install instead of
upgrading.</p>
<h3>To download only</h3>
<p>If you don't need installation or upgrade instructions, you can download Tails
7.9.1 directly:</p>
<ul>
<li><p><a href="https://tails.net/install/download/">For USB sticks (USB image)</a></p>
</li>
<li><p><a href="https://tails.net/install/download-iso/">For DVDs and virtual machines (ISO image)</a></p>
</li>
</ul>
<h2>Support and feedback</h2>
<p>For support and feedback, visit the <a href="https://tails.net/support/">Support
section</a> on the Tails website.</p>

    </div>
  <div class="categories">
    <ul><li>
        <a href="https://blog.torproject.org/category/tails">
          tails
        </a>
      </li><li>
        <a href="https://blog.torproject.org/category/releases">
          releases
        </a>
      </li></ul>
  </div>
  </article>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Alpha Release: Tor Browser 16.0a8]]></title>
<description><![CDATA[Tor Browser 16.0a8 is now available from the Tor Browser download page and also from our distribution directory.
This version includes important security updates to Firefox.
⚠️ Reminder: The Tor Browser Alpha release-channel is for testing only. As such, Tor Browser Alpha is not intended for gene...]]></description>
<link>https://tsecurity.de/de/3687537/it-security-tools/new-alpha-release-tor-browser-160a8/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687537/it-security-tools/new-alpha-release-tor-browser-160a8/</guid>
<pubDate>Wed, 22 Jul 2026 22:34:02 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article class="blog-post">
    <picture>
      <source media="(min-width:415px)" srcset="https://blog.torproject.org/new-alpha-release-tor-browser-160a8/lead.webp" type="image/webp">
<source srcset="https://blog.torproject.org/new-alpha-release-tor-browser-160a8/lead_small.webp" type="image/webp">

      <img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/new-alpha-release-tor-browser-160a8/lead.png">
    </picture>
    <div class="body"><p>Tor Browser 16.0a8 is now available from the <a href="https://www.torproject.org/download/alpha/">Tor Browser download page</a> and also from our <a href="https://www.torproject.org/dist/torbrowser/16.0a8/">distribution directory</a>.</p>
<p>This version includes important <a href="https://www.mozilla.org/en-US/security/advisories/">security updates</a> to Firefox.</p>
<p>⚠️ <strong>Reminder</strong>: The Tor Browser Alpha release-channel is for <a href="https://community.torproject.org/user-research/become-tester/">testing only</a>. As such, Tor Browser Alpha is not intended for general use because it is more likely to include bugs affecting usability, security, and privacy.</p>
<p>Moreover, Tor Browser Alphas are now based on Firefox's betas. Please read more about this important change in the <a href="https://blog.torproject.org/future-of-tor-browser-alpha/">Future of Tor Browser Alpha</a> blog post.</p>
<p>If you are an at-risk user, require strong anonymity, or just want a reliably-working browser, please stick with the <a href="https://www.torproject.org/download/">stable release channel</a>.</p>
<h2>Send us your feedback</h2>
<p>If you find a bug or have a suggestion for how we could improve this release, <a href="https://support.torproject.org/misc/bug-or-feedback/">please let us know</a>.</p>
<h2>Full changelog</h2>
<p>The <a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/raw/main/projects/browser/Bundle-Data/Docs-TBB/ChangeLog.txt">full changelog</a> since Tor Browser 16.0a7 is:</p>
<ul>
<li>All Platforms<ul>
<li>Updated NoScript to 13.6.25.90301984</li>
<li>Updated Tor to 0.4.9.11</li>
<li>Updated OpenSSL to 3.5.7</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44857">Bug tor-browser#44857</a>: Drop <code>browser.display.use_system_colors</code> from our preference list</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44896">Bug tor-browser#44896</a>: Review Mozilla 2030929: Remove unused pref privacy.partition.network_state</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45018">Bug tor-browser#45018</a>: resistfingerprinting not available in appearance.mjs in 152</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45019">Bug tor-browser#45019</a>: ReportBrokenSite startup error in 152</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45047">Bug tor-browser#45047</a>: Cross-site oracle via worklet rejection error in Safer Mode</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45072">Bug tor-browser#45072</a>: Disable XSLT already for 16.0</li>
</ul>
</li>
<li>Windows + macOS + Linux<ul>
<li>Updated Firefox to 152.0a1</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44528">Bug tor-browser#44528</a>: Make sure desktop IP Protection is disabled on desktop</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44795">Bug tor-browser#44795</a>: Revert BB 27604 patch as not needed anymore</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44844">Bug tor-browser#44844</a>: Use new urlbar CSS variables</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44888">Bug tor-browser#44888</a>: Use <code>--button-opacity-disabled</code> for disabled styling.</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44955">Bug tor-browser#44955</a>: Use <code>context-fill</code> for <code>about-wordmark.svg</code></li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44956">Bug tor-browser#44956</a>: Switch colours in letterboxing setting icons to match the tab-alignment icons</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45016">Bug tor-browser#45016</a>: Several errors about EngineProcess.sys.mjs in 152</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45017">Bug tor-browser#45017</a>: Wrong letterboxing background in 152</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45037">Bug tor-browser#45037</a>: Potential runtime errors in the search service when changing JS status</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45043">Bug tor-browser#45043</a>: Re-add missing changes to settings after 151/152 rebase</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45083">Bug tor-browser#45083</a>: Error in about:preferences due to ipprotection missing</li>
</ul>
</li>
<li>macOS<ul>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44728">Bug tor-browser#44728</a>: Bundled fonts are broken on macOS when the GPU process is enabled</li>
</ul>
</li>
<li>Linux<ul>
<li><a href="https://gitlab.torproject.org/tpo/applications/@%20libfontconfig.so.1/-/issues/45048">Bug @ libfontconfig.so.1#45048</a>: Backport Bugzilla 2041887: Crash in after users upgraded to fontconfig 2.18.0 [tor-browser]</li>
</ul>
</li>
<li>Android<ul>
<li>Updated GeckoView to 152.0a1</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/43856">Bug tor-browser#43856</a>: Fix onBackPressed() deprecation</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44091">Bug tor-browser#44091</a>: Add frequent regions to tor connection assist for android</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44175">Bug tor-browser#44175</a>: Remove all default browser functionality (Android)</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44769">Bug tor-browser#44769</a>: TBA crash screen has firefox asset as well as a "Send crash report" button</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45052">Bug tor-browser#45052</a>: Initialise Tor modules on android in the same order as desktop</li>
</ul>
</li>
<li>Build System<ul>
<li>All Platforms<ul>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41802">Bug tor-browser-build#41802</a>: Remove the tor daemon requirement for signing</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41809">Bug tor-browser-build#41809</a>: Update toolchains for Firefox 152</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41813">Bug tor-browser-build#41813</a>: Disable build artifacts in <code>make generate_gradle_dependencies_list-geckoview</code></li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41821">Bug tor-browser-build#41821</a>: Update gpg subkeys for boklm</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41823">Bug tor-browser-build#41823</a>: Add versions information to the toolchain list update</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41827">Bug tor-browser-build#41827</a>: Update morgan's keychain with renewed key</li>
</ul>
</li>
<li>Windows + Linux + Android<ul>
<li>Updated Go to 1.26.4</li>
</ul>
</li>
<li>Windows<ul>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41810">Bug tor-browser-build#41810</a>: Define GetAddrInfoExCancel on mingw</li>
</ul>
</li>
<li>Android<ul>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45086">Bug tor-browser#45086</a>: Compress omni.ja with xz on Android</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41830">Bug tor-browser-build#41830</a>: Update the browser project to change omni.ja.xz</li>
</ul>
</li>
</ul>
</li>
</ul>

    </div>
  <div class="categories">
    <ul><li>
        <a href="https://blog.torproject.org/category/applications">
          applications
        </a>
      </li><li>
        <a href="https://blog.torproject.org/category/releases">
          releases
        </a>
      </li></ul>
  </div>
  </article>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Release: Tor Browser 15.0.18]]></title>
<description><![CDATA[Tor Browser 15.0.18 is now available from the Tor Browser download page and also from our distribution directory.
This version includes important security updates to Firefox.
Send us your feedback
If you find a bug or have a suggestion for how we could improve this release, please let us know.
Fu...]]></description>
<link>https://tsecurity.de/de/3687536/it-security-tools/new-release-tor-browser-15018/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687536/it-security-tools/new-release-tor-browser-15018/</guid>
<pubDate>Wed, 22 Jul 2026 22:33:08 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article class="blog-post">
    <picture>
      <source media="(min-width:415px)" srcset="https://blog.torproject.org/new-release-tor-browser-15018/lead.webp" type="image/webp">
<source srcset="https://blog.torproject.org/new-release-tor-browser-15018/lead_small.webp" type="image/webp">

      <img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/new-release-tor-browser-15018/lead.png">
    </picture>
    <div class="body"><p>Tor Browser 15.0.18 is now available from the <a href="https://www.torproject.org/download/">Tor Browser download page</a> and also from our <a href="https://www.torproject.org/dist/torbrowser/15.0.18/">distribution directory</a>.</p>
<p>This version includes important <a href="https://www.mozilla.org/en-US/security/advisories/">security updates</a> to Firefox.</p>
<h2>Send us your feedback</h2>
<p>If you find a bug or have a suggestion for how we could improve this release, <a href="https://support.torproject.org/misc/bug-or-feedback/">please let us know</a>.</p>
<h2>Full changelog</h2>
<p>The <a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/raw/maint-15.0/projects/browser/Bundle-Data/Docs-TBB/ChangeLog.txt">full changelog</a> since Tor Browser 15.0.17 is:</p>
<ul>
<li>All Platforms<ul>
<li>Updated NoScript to 13.6.30.1984</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45111">Bug tor-browser#45111</a>: Cherry-pick latest firefox/esr140 commits on 140.12.0esr</li>
</ul>
</li>
<li>Build System<ul>
<li>All Platforms<ul>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41821">Bug tor-browser-build#41821</a>: Update gpg subkeys for boklm</li>
</ul>
</li>
<li>Windows + Linux + Android<ul>
<li>Updated Go to 1.25.12</li>
</ul>
</li>
</ul>
</li>
</ul>

    </div>
  <div class="categories">
    <ul><li>
        <a href="https://blog.torproject.org/category/applications">
          applications
        </a>
      </li><li>
        <a href="https://blog.torproject.org/category/releases">
          releases
        </a>
      </li></ul>
  </div>
  </article>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Release: Tor Browser 15.0.19]]></title>
<description><![CDATA[Tor Browser 15.0.19 is now available from the Tor Browser download page and also from our distribution directory.
This version includes important security updates to Firefox.
Send us your feedback
If you find a bug or have a suggestion for how we could improve this release, please let us know.
Fu...]]></description>
<link>https://tsecurity.de/de/3687535/it-security-tools/new-release-tor-browser-15019/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687535/it-security-tools/new-release-tor-browser-15019/</guid>
<pubDate>Wed, 22 Jul 2026 22:32:48 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article class="blog-post">
    <picture>
      <source media="(min-width:415px)" srcset="https://blog.torproject.org/new-release-tor-browser-15019/lead.webp" type="image/webp">
<source srcset="https://blog.torproject.org/new-release-tor-browser-15019/lead_small.webp" type="image/webp">

      <img class="lead" referrerpolicy="no-referrer" loading="lazy" src="https://blog.torproject.org/new-release-tor-browser-15019/lead.png">
    </picture>
    <div class="body"><p>Tor Browser 15.0.19 is now available from the <a href="https://www.torproject.org/download/">Tor Browser download page</a> and also from our <a href="https://www.torproject.org/dist/torbrowser/15.0.19/">distribution directory</a>.</p>
<p>This version includes important <a href="https://www.mozilla.org/en-US/security/advisories/">security updates</a> to Firefox.</p>
<h2>Send us your feedback</h2>
<p>If you find a bug or have a suggestion for how we could improve this release, <a href="https://support.torproject.org/misc/bug-or-feedback/">please let us know</a>.</p>
<h2>Full changelog</h2>
<p>The <a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/raw/maint-15.0/projects/browser/Bundle-Data/Docs-TBB/ChangeLog.txt">full changelog</a> since Tor Browser 15.0.18 is:</p>
<ul>
<li>All Platforms<ul>
<li>Updated NoScript to 13.6.31.1984</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/44748">Bug tor-browser#44748</a>: Revert Funding the Commons Implementations</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45117">Bug tor-browser#45117</a>: Rebase Tor Browser stable onto 140.13.0esr</li>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/45124">Bug tor-browser#45124</a>: Backport Security Fixes from Firefox 153</li>
</ul>
</li>
<li>Windows + macOS + Linux<ul>
<li>Updated Firefox to 140.13.0esr</li>
</ul>
</li>
<li>Android<ul>
<li>Updated GeckoView to 140.13.0esr</li>
</ul>
</li>
<li>Build System<ul>
<li>All Platforms<ul>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41838">Bug tor-browser-build#41838</a>: Update personal_access_tokens URL in tools/fetch_changelogs.py</li>
</ul>
</li>
<li>Windows<ul>
<li><a href="https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41819">Bug tor-browser-build#41819</a>: Fix windows-rs URL in projects/firefox/config</li>
</ul>
</li>
</ul>
</li>
</ul>

    </div>
  <div class="categories">
    <ul><li>
        <a href="https://blog.torproject.org/category/applications">
          applications
        </a>
      </li><li>
        <a href="https://blog.torproject.org/category/releases">
          releases
        </a>
      </li></ul>
  </div>
  </article>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco’s new AI model tells code reviewers where to look for vulnerabilities]]></title>
<description><![CDATA[Cisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially vulnerable parts of a software repository before deeper investigation begins.



Rather than detecting a specific CVE or generating a patch, these models search a codebas...]]></description>
<link>https://tsecurity.de/de/3687085/ai-nachrichten/ciscos-new-ai-model-tells-code-reviewers-where-to-look-for-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687085/ai-nachrichten/ciscos-new-ai-model-tells-code-reviewers-where-to-look-for-vulnerabilities/</guid>
<pubDate>Wed, 22 Jul 2026 19:05:41 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Cisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially vulnerable parts of a software repository before deeper investigation begins.</p>



<p class="wp-block-paragraph">Rather than detecting a specific CVE or generating a patch, these models search a codebase using only a Common Weakness Enumeration (CWE) description and return the files most likely to contain that class of vulnerability.</p>



<p class="wp-block-paragraph">“Its purpose is to reduce a large codebase to a focused set of files that a security professional or a downstream security workflow should investigate,” Cisco’s AI researcher <a href="https://www.linkedin.com/in/supriti-vijay/" target="_blank" rel="noreferrer noopener">Supriti Vijay</a> said via email. “The goal is not to replace a security engineer’s judgement or send them on a wild-goose chase, but to reduce fatigue and workload by helping them triage an issue earlier and focus their investigation on the most relevant parts of the codebase.”</p>



<p class="wp-block-paragraph">The Antares family consists of models with 350 million, 1 billion, and 3 billion parameters trained specifically for repository-scale vulnerability localization.</p>



<p class="wp-block-paragraph">The company said its largest model approaches the performance of GPT-5.5 on its internal vulnerability localization (Vloc) benchmark while remaining small enough for low-cost local deployment.</p>



<h2 class="wp-block-heading">A search assistant, not a vulnerability detector</h2>



<p class="wp-block-paragraph">Cisco is careful to define what Antares is, and what it is not.</p>



<p class="wp-block-paragraph">“Antares outputs a ranked list of source files likely to contain a relevant vulnerability, along with the terminal exploration trace that led to that result,” Cisco Foundation AI Chief Scientist <a href="https://www.linkedin.com/in/amin-karbasi-5025335/" target="_blank" rel="noreferrer noopener">Amin Karbasi</a> wrote in a blog post, adding that the models are not meant to replace the broader application security toolchain: Human analysts or downstream security tools will still be needed to confirm exploitability, <a href="https://www.infoworld.com/article/4200083/gitlab-previews-auto-remediation-of-vulnerable-dependencies.html">identify vulnerable lines of code</a>, assess severity and generate fixes.</p>



<p class="wp-block-paragraph">Antares differs from conventional static analysis platforms such as Semgrep or CodeQL, which primarily rely on predefined rules or queries. Cisco instead describes Antares as an evidence-driven exploration agent that adapts its search as it traverses the repository.</p>



<p class="wp-block-paragraph">Cisco’s argument is that large repositories often contain thousands of files, making manual reviews exhaustive and unrealistic. By reducing the search space to a manageable shortlist, the company hopes to reduce investigation fatigue without replacing human judgement.</p>



<h2 class="wp-block-heading">Claims of specialization over scale</h2>



<p class="wp-block-paragraph">Cisco is also making a statement about how cybersecurity models should evolve.</p>



<p class="wp-block-paragraph">Instead of pursuing larger foundational models, Cisco argued that specialized, task-trained models can outperform much larger open-weight alternatives for vulnerability localization. In its evaluation Antares-3B, the largest model intended for single-GPU deployments, produced results comparable to GPT-5.5 while outperforming several substantially larger open models by Google, OpenAI and Meta.</p>



<p class="wp-block-paragraph">The family also includes Antares-350M for resource-constrained environments and Antares-1B for laptops and workstations, which Cisco has made available as open-weight models on Hugging Face.</p>



<p class="wp-block-paragraph">The command line interface (CLI) on the models supports targeted CWE investigations, repository-wide scans, SARIF output and local inference, which Cisco said enables organizations to keep proprietary code inside their own trust boundary.</p>



<p class="wp-block-paragraph">However, because Antares identifies candidate files rather than confirmed vulnerabilities, organizations will still need to understand how often such repository-wide searches should be run, how much they improve existing triage workflows, and whether the reduction in investigation effort ultimately translates into measurable security or cost benefits.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco’s new AI model tells code reviewers where to look for vulnerabilities]]></title>
<description><![CDATA[Cisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially vulnerable parts of a software repository before deeper investigation begins.



Rather than detecting a specific CVE or generating a patch, these models search a codebas...]]></description>
<link>https://tsecurity.de/de/3687065/it-security-nachrichten/ciscos-new-ai-model-tells-code-reviewers-where-to-look-for-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687065/it-security-nachrichten/ciscos-new-ai-model-tells-code-reviewers-where-to-look-for-vulnerabilities/</guid>
<pubDate>Wed, 22 Jul 2026 18:54:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Cisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially vulnerable parts of a software repository before deeper investigation begins.</p>



<p class="wp-block-paragraph">Rather than detecting a specific CVE or generating a patch, these models search a codebase using only a Common Weakness Enumeration (CWE) description and return the files most likely to contain that class of vulnerability.</p>



<p class="wp-block-paragraph">“Its purpose is to reduce a large codebase to a focused set of files that a security professional or a downstream security workflow should investigate,” Cisco’s AI researcher <a href="https://www.linkedin.com/in/supriti-vijay/" target="_blank" rel="noreferrer noopener">Supriti Vijay</a> said via email. “The goal is not to replace a security engineer’s judgement or send them on a wild-goose chase, but to reduce fatigue and workload by helping them triage an issue earlier and focus their investigation on the most relevant parts of the codebase.”</p>



<p class="wp-block-paragraph">The Antares family consists of models with 350 million, 1 billion, and 3 billion parameters trained specifically for repository-scale vulnerability localization.</p>



<p class="wp-block-paragraph">The company said its largest model approaches the performance of GPT-5.5 on its internal vulnerability localization (Vloc) benchmark while remaining small enough for low-cost local deployment.</p>



<h2 class="wp-block-heading">A search assistant, not a vulnerability detector</h2>



<p class="wp-block-paragraph">Cisco is careful to define what Antares is, and what it is not.</p>



<p class="wp-block-paragraph">“Antares outputs a ranked list of source files likely to contain a relevant vulnerability, along with the terminal exploration trace that led to that result,” Cisco Foundation AI Chief Scientist <a href="https://www.linkedin.com/in/amin-karbasi-5025335/" target="_blank" rel="noreferrer noopener">Amin Karbasi</a> wrote in a blog post, adding that the models are not meant to replace the broader application security toolchain: Human analysts or downstream security tools will still be needed to confirm exploitability, <a href="https://www.infoworld.com/article/4200083/gitlab-previews-auto-remediation-of-vulnerable-dependencies.html">identify vulnerable lines of code</a>, assess severity and generate fixes.</p>



<p class="wp-block-paragraph">Antares differs from conventional static analysis platforms such as Semgrep or CodeQL, which primarily rely on predefined rules or queries. Cisco instead describes Antares as an evidence-driven exploration agent that adapts its search as it traverses the repository.</p>



<p class="wp-block-paragraph">Cisco’s argument is that large repositories often contain thousands of files, making manual reviews exhaustive and unrealistic. By reducing the search space to a manageable shortlist, the company hopes to reduce investigation fatigue without replacing human judgement.</p>



<h2 class="wp-block-heading">Claims of specialization over scale</h2>



<p class="wp-block-paragraph">Cisco is also making a statement about how cybersecurity models should evolve.</p>



<p class="wp-block-paragraph">Instead of pursuing larger foundational models, Cisco argued that specialized, task-trained models can outperform much larger open-weight alternatives for vulnerability localization. In its evaluation Antares-3B, the largest model intended for single-GPU deployments, produced results comparable to GPT-5.5 while outperforming several substantially larger open models by Google, OpenAI and Meta.</p>



<p class="wp-block-paragraph">The family also includes Antares-350M for resource-constrained environments and Antares-1B for laptops and workstations, which Cisco has made available as open-weight models on Hugging Face.</p>



<p class="wp-block-paragraph">The command line interface (CLI) on the models supports targeted CWE investigations, repository-wide scans, SARIF output and local inference, which Cisco said enables organizations to keep proprietary code inside their own trust boundary.</p>



<p class="wp-block-paragraph">However, because Antares identifies candidate files rather than confirmed vulnerabilities, organizations will still need to understand how often such repository-wide searches should be run, how much they improve existing triage workflows, and whether the reduction in investigation effort ultimately translates into measurable security or cost benefits.</p>



<p class="wp-block-paragraph"><em>This article first appeared on <a href="https://www.infoworld.com/article/4200143/ciscos-new-ai-model-tells-code-reviewers-where-to-look-for-vulnerabilities.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab previews auto-remediation of vulnerable dependencies]]></title>
<description><![CDATA[GitLab has released GitLab 19.2, an update to the company’s devsecops platform that allows teams to fix vulnerable dependencies automatically, use Security Review Flow to catch logic flaws that scanners miss, and run AI agents straight from the terminal, the company said. 



Highlights in GitLab...]]></description>
<link>https://tsecurity.de/de/3686997/ai-nachrichten/gitlab-previews-auto-remediation-of-vulnerable-dependencies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686997/ai-nachrichten/gitlab-previews-auto-remediation-of-vulnerable-dependencies/</guid>
<pubDate>Wed, 22 Jul 2026 18:23:04 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">GitLab has released <a href="https://about.gitlab.com/whats-new/" data-type="link" data-id="https://about.gitlab.com/whats-new/">GitLab 19.2</a>, an update to the company’s <a href="https://www.infoworld.com/article/2337499/what-is-devsecops-securing-devops-pipelines.html" data-type="link" data-id="https://www.infoworld.com/article/2337499/what-is-devsecops-securing-devops-pipelines.html">devsecops</a> platform that allows teams to fix vulnerable dependencies automatically, use Security Review Flow to catch logic flaws that scanners miss, and run AI agents straight from the terminal, the company said. </p>



<p class="wp-block-paragraph">Highlights in GitLab 19.2 include the following:</p>



<ul class="wp-block-list">
<li>Dependency Scanning Auto-Remediation, in public beta, uses AI to fix build-breaking changes and iterates until your pipeline passes, with every change governed by your existing gates and audit trail. </li>



<li>Security Review Flow, also in public beta, analyzes code changes as a security engineer would and catches authorization gaps, business-logic errors, and race conditions that static scanners structurally cannot see.</li>



<li>GitLab Duo CLI, now generally available, gives developers access to agents and multi-step agentic flows for all software life cycle tasks without leaving the terminal. </li>



<li>Custom Flows, now generally available, let teams replace manual multi-step workflows with agentic automations for software development, triggered by GitLab events.</li>
</ul>



<p class="wp-block-paragraph">“Coding agents made it possible to generate far more code and moved the bottleneck downstream to reviews and security,” said Manav Khurana, chief product and marketing officer at GitLab, in a statement. “GitLab 19.2 puts agents to work on that bottleneck: fixing vulnerable dependencies, catching the flaws scanners miss, and automating the steps in between with a person still approving what ships.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3902 | GitLab up to 15.4.5/15.5.4/15.6.0 Project Maintainer log file (Issue 381895 / EUVD-2022-43238)]]></title>
<description><![CDATA[A vulnerability was found in GitLab up to 15.4.5/15.5.4/15.6.0 and classified as problematic. This affects an unknown function of the component Project Maintainer Handler. Executing a manipulation can lead to sensitive information in log files.

This vulnerability is registered as CVE-2022-3902. ...]]></description>
<link>https://tsecurity.de/de/3686057/sicherheitsluecken/cve-2022-3902-gitlab-up-to-154515541560-project-maintainer-log-file-issue-381895-euvd-2022-43238/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686057/sicherheitsluecken/cve-2022-3902-gitlab-up-to-154515541560-project-maintainer-log-file-issue-381895-euvd-2022-43238/</guid>
<pubDate>Wed, 22 Jul 2026 13:03:59 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gitlab">GitLab up to 15.4.5/15.5.4/15.6.0</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown function of the component <em>Project Maintainer Handler</em>. Executing a manipulation can lead to sensitive information in log files.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2022-3902">CVE-2022-3902</a>. It is possible to launch the attack remotely. No exploit is available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3870 | GitLab Community Edition/Enterprise Edition up to 15.5.6/15.6.3/15.7.1 User Avatar information disclosure (Issue 381647 / EUVD-2022-43207)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in GitLab Community Edition and Enterprise Edition up to 15.5.6/15.6.3/15.7.1. This impacts an unknown function of the component User Avatar Handler. The manipulation leads to information disclosure.

This vulnerability is docum...]]></description>
<link>https://tsecurity.de/de/3682321/sicherheitsluecken/cve-2022-3870-gitlab-community-editionenterprise-edition-up-to-155615631571-user-avatar-information-disclosure-issue-381647-euvd-2022-43207/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682321/sicherheitsluecken/cve-2022-3870-gitlab-community-editionenterprise-edition-up-to-155615631571-user-avatar-information-disclosure-issue-381647-euvd-2022-43207/</guid>
<pubDate>Tue, 21 Jul 2026 00:39:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 15.5.6/15.6.3/15.7.1</a>. This impacts an unknown function of the component <em>User Avatar Handler</em>. The manipulation leads to information disclosure.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2022-3870">CVE-2022-3870</a>. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3819 | GitLab Community Edition/Enterprise Edition up to 15.3.4/15.4.3/15.5.1 Emoji improper authorization (Issue 365847 / EUVD-2022-43160)]]></title>
<description><![CDATA[A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1. It has been declared as critical. Affected is an unknown function of the component Emoji Handler. The manipulation results in improper authorization.

This vulnerability is identified as CVE-2...]]></description>
<link>https://tsecurity.de/de/3682232/sicherheitsluecken/cve-2022-3819-gitlab-community-editionenterprise-edition-up-to-153415431551-emoji-improper-authorization-issue-365847-euvd-2022-43160/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682232/sicherheitsluecken/cve-2022-3819-gitlab-community-editionenterprise-edition-up-to-153415431551-emoji-improper-authorization-issue-365847-euvd-2022-43160/</guid>
<pubDate>Mon, 20 Jul 2026 23:44:50 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. Affected is an unknown function of the component <em>Emoji Handler</em>. The manipulation results in improper authorization.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2022-3819">CVE-2022-3819</a>. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3818 | GitLab Community Edition/Enterprise Edition up to 15.3.4/15.4.3/15.5.1 URL Parser resource consumption (Issue 358170 / EUVD-2022-43159)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1. Affected by this vulnerability is an unknown functionality of the component URL Parser. Such manipulation leads to resource consumption.

This vulnerability is docu...]]></description>
<link>https://tsecurity.de/de/3682231/sicherheitsluecken/cve-2022-3818-gitlab-community-editionenterprise-edition-up-to-153415431551-url-parser-resource-consumption-issue-358170-euvd-2022-43159/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682231/sicherheitsluecken/cve-2022-3818-gitlab-community-editionenterprise-edition-up-to-153415431551-url-parser-resource-consumption-issue-358170-euvd-2022-43159/</guid>
<pubDate>Mon, 20 Jul 2026 23:44:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1</a>. Affected by this vulnerability is an unknown functionality of the component <em>URL Parser</em>. Such manipulation leads to resource consumption.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2022-3818">CVE-2022-3818</a>. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3820 | GitLab up to 15.4.3/15.5.1 IP Address Restriction improper authentication (Issue 378638 / EUVD-2022-43161)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in GitLab up to 15.4.3/15.5.1. This affects an unknown part of the component IP Address Restriction. The manipulation leads to improper authentication.

This vulnerability is listed as CVE-2022-3820. The attack may be initiated rem...]]></description>
<link>https://tsecurity.de/de/3682229/sicherheitsluecken/cve-2022-3820-gitlab-up-to-15431551-ip-address-restriction-improper-authentication-issue-378638-euvd-2022-43161/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682229/sicherheitsluecken/cve-2022-3820-gitlab-up-to-15431551-ip-address-restriction-improper-authentication-issue-378638-euvd-2022-43161/</guid>
<pubDate>Mon, 20 Jul 2026 23:44:46 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/gitlab">GitLab up to 15.4.3/15.5.1</a>. This affects an unknown part of the component <em>IP Address Restriction</em>. The manipulation leads to improper authentication.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2022-3820">CVE-2022-3820</a>. The attack may be initiated remotely. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker Wipes Romania's Entire Land Registry Database]]></title>
<description><![CDATA[A hacker reportedly wiped Romania's entire land registry database after a failed extortion attempt, halting property transactions across the country and preventing notaries from issuing land extracts, authenticating sales, or registering mortgages. "On the dark web, the hacker also boasted to hav...]]></description>
<link>https://tsecurity.de/de/3681830/it-security-nachrichten/hacker-wipes-romanias-entire-land-registry-database/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681830/it-security-nachrichten/hacker-wipes-romanias-entire-land-registry-database/</guid>
<pubDate>Mon, 20 Jul 2026 19:23:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A hacker reportedly wiped Romania's entire land registry database after a failed extortion attempt, halting property transactions across the country and preventing notaries from issuing land extracts, authenticating sales, or registering mortgages. "On the dark web, the hacker also boasted to have begun backup copies of stolen data in an attempt to prevent it from being restored," reports Cybernews. "However, Romanian officials have managed to at least restore the ANCPI's website and post a message saying they were rebuilding the agency's entire network from scratch. It appears that the agency has an offline copy of the wiped data." From the report: First, the hacker breached Romania's cadastre agency, the National Agency for Cadastre and Real Estate Advertising (ANCPI), posting on a hacking forum: "[RO] Thy arss shall be spanked, Romania! [ANCPI]." "In addition to the data of Romanian citizens, from various databases collected through ANCPI networks, there is also a copy of the GitLab servers containing the source code of all their systems, such as Eterra, RENNS, as well as a version of my little ransomware program," the announcement continued.
 
"The official government website announced a shutdown of IT systems due to 'technical problems,' but this is a bit of an understatement. An offer of assistance was made, but without insistence or pressure." Indeed, the ANCPI initially claimed technical issues but had to admit it was facing a cyberattack. Today, no one can really access the institution's systems. And since the extortion didn't work, the hacker -- who seems to have entered the database using valid credentials -- deleted all data they had stolen, including internal documents, employee credentials, and, of course, land registry data.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Hacker+Wipes+Romania's+Entire+Land+Registry+Database%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F07%2F20%2F172249%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F07%2F20%2F172249%2Fhacker-wipes-romanias-entire-land-registry-database%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/26/07/20/172249/hacker-wipes-romanias-entire-land-registry-database?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Catanzaro: Some changes to GNOME security tracking]]></title>
<description><![CDATA[Michael Catanzaro, who has been managing GNOME security issue tracking since
November 2020, has written a blog post that details some changes in how he will
be managing GNOME vulnerability reports from now on due to an increase in
AI-generated security reports. He will be switching from a 90-day ...]]></description>
<link>https://tsecurity.de/de/3681780/linux-tipps/catanzaro-some-changes-to-gnome-security-tracking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681780/linux-tipps/catanzaro-some-changes-to-gnome-security-tracking/</guid>
<pubDate>Mon, 20 Jul 2026 19:05:07 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Michael Catanzaro, who has been managing GNOME security issue tracking since
November 2020, has written a <a href="https://blogs.gnome.org/mcatanzaro/2026/07/20/some-changes-to-gnome-security-tracking/">blog post</a> that details some changes in how he will
be managing GNOME vulnerability reports from now on due to an increase in
AI-generated security reports. He will be switching from a 90-day deadline for
disclosures to 30 days for issues reported on August 1, or later. "<q>The
shorter deadline would probably work better for GNOME even if not for the
increase in AI-generated issue reports.</q>"</p>

<p>He also has indicated that he will be stepping away from the task of managing
security issue tracking entirely by December 1, 2026, which means that there
will be a gap to fill:</p>

<blockquote class="bq">
<p>Currently nobody else is tracking GNOME security issues. If you are an
experienced GNOME community member and you are interested in taking over this
work, let me know and I will help you get started. (Security tracking is not a
good task for newcomers.)</p>

<p>This may also be an opportunity to improve our tracking infrastructure. I use
a <a href="https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home">wiki
page</a>, but this is fairly primitive and requires considerable manual
upkeep. It's easy to forget to update the page when an issue report is closed,
for example. Ideally, we would replace the wiki with a proper web app that
dynamically updates based on the actual state of the issue.</p>
</blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3793 | GitLab Community Edition/Enterprise Edition up to 15.3.4/15.4.3/15.5.1 Configuration File improper authorization (Issue 372120 / EUVD-2022-43139)]]></title>
<description><![CDATA[A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1. It has been classified as critical. This impacts an unknown function of the component Configuration File Handler. The manipulation leads to improper authorization.

This vulnerability is refer...]]></description>
<link>https://tsecurity.de/de/3680323/sicherheitsluecken/cve-2022-3793-gitlab-community-editionenterprise-edition-up-to-153415431551-configuration-file-improper-authorization-issue-372120-euvd-2022-43139/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680323/sicherheitsluecken/cve-2022-3793-gitlab-community-editionenterprise-edition-up-to-153415431551-configuration-file-improper-authorization-issue-372120-euvd-2022-43139/</guid>
<pubDate>Mon, 20 Jul 2026 07:55:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. This impacts an unknown function of the component <em>Configuration File Handler</em>. The manipulation leads to improper authorization.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2022-3793">CVE-2022-3793</a>. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3759 | GitLab Community Edition/Enterprise Edition CI Job denial of service (Issue 379633 / EUVD-2022-43113)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in GitLab Community Edition and Enterprise Edition. This issue affects some unknown processing of the component CI Job Handler. Performing a manipulation results in denial of service.

This vulnerability is identified as CVE-202...]]></description>
<link>https://tsecurity.de/de/3679921/sicherheitsluecken/cve-2022-3759-gitlab-community-editionenterprise-edition-ci-job-denial-of-service-issue-379633-euvd-2022-43113/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679921/sicherheitsluecken/cve-2022-3759-gitlab-community-editionenterprise-edition-ci-job-denial-of-service-issue-379633-euvd-2022-43113/</guid>
<pubDate>Sun, 19 Jul 2026 22:08:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition</a>. This issue affects some unknown processing of the component <em>CI Job Handler</em>. Performing a manipulation results in denial of service.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2022-3759">CVE-2022-3759</a>. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3767 | GitLab DAST Analyzer up to 3.0.31 Request Header information disclosure (Issue 377473 / EUVD-2022-43119)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in GitLab DAST Analyzer up to 3.0.31. This impacts an unknown function of the component Request Header Handler. Performing a manipulation results in information disclosure.

This vulnerability was named CVE-2022-3767. The attack may be i...]]></description>
<link>https://tsecurity.de/de/3679918/sicherheitsluecken/cve-2022-3767-gitlab-dast-analyzer-up-to-3031-request-header-information-disclosure-issue-377473-euvd-2022-43119/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679918/sicherheitsluecken/cve-2022-3767-gitlab-dast-analyzer-up-to-3031-request-header-information-disclosure-issue-377473-euvd-2022-43119/</guid>
<pubDate>Sun, 19 Jul 2026 22:07:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/gitlab:dast_analyzer">GitLab DAST Analyzer up to 3.0.31</a>. This impacts an unknown function of the component <em>Request Header Handler</em>. Performing a manipulation results in information disclosure.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2022-3767">CVE-2022-3767</a>. The attack may be initiated remotely. There is no available exploit.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3740 | GitLab Community Edition/Enterprise Edition up to 15.3.4/15.4.3/15.5.1 improper authorization (Issue 368416 / EUVD-2022-43096)]]></title>
<description><![CDATA[A vulnerability has been found in GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1 and classified as critical. The impacted element is an unknown function. Performing a manipulation results in improper authorization.

This vulnerability is cataloged as CVE-2022-3740. It ...]]></description>
<link>https://tsecurity.de/de/3679764/sicherheitsluecken/cve-2022-3740-gitlab-community-editionenterprise-edition-up-to-153415431551-improper-authorization-issue-368416-euvd-2022-43096/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679764/sicherheitsluecken/cve-2022-3740-gitlab-community-editionenterprise-edition-up-to-153415431551-improper-authorization-issue-368416-euvd-2022-43096/</guid>
<pubDate>Sun, 19 Jul 2026 18:29:46 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. The impacted element is an unknown function. Performing a manipulation results in improper authorization.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2022-3740">CVE-2022-3740</a>. It is possible to initiate the attack remotely. There is no exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3758 | GitLab up to 15.7.7/15.8.3/15.9.1 Private Snippet permission (Issue 379598 / EUVD-2022-43112)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in GitLab up to 15.7.7/15.8.3/15.9.1. This affects an unknown part of the component Private Snippet Handler. Such manipulation leads to permission issues.

This vulnerability is documented as CVE-2022-3758. The attack can be executed re...]]></description>
<link>https://tsecurity.de/de/3679760/sicherheitsluecken/cve-2022-3758-gitlab-up-to-157715831591-private-snippet-permission-issue-379598-euvd-2022-43112/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679760/sicherheitsluecken/cve-2022-3758-gitlab-up-to-157715831591-private-snippet-permission-issue-379598-euvd-2022-43112/</guid>
<pubDate>Sun, 19 Jul 2026 18:29:40 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/gitlab">GitLab up to 15.7.7/15.8.3/15.9.1</a>. This affects an unknown part of the component <em>Private Snippet Handler</em>. Such manipulation leads to permission issues.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2022-3758">CVE-2022-3758</a>. The attack can be executed remotely. There is not any exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3726 | GitLab Community Edition/Enterprise Edition up to 15.3.4/15.4.3/15.5.1 Swagger OpenAPI Document cross-site request forgery (Issue 362509 / EUVD-2022-43082)]]></title>
<description><![CDATA[A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1 and classified as problematic. This affects an unknown function of the component Swagger OpenAPI Document Handler. Executing a manipulation can lead to cross-site request forgery.

The identifi...]]></description>
<link>https://tsecurity.de/de/3679430/sicherheitsluecken/cve-2022-3726-gitlab-community-editionenterprise-edition-up-to-153415431551-swagger-openapi-document-cross-site-request-forgery-issue-362509-euvd-2022-43082/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679430/sicherheitsluecken/cve-2022-3726-gitlab-community-editionenterprise-edition-up-to-153415431551-swagger-openapi-document-cross-site-request-forgery-issue-362509-euvd-2022-43082/</guid>
<pubDate>Sun, 19 Jul 2026 14:09:07 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown function of the component <em>Swagger OpenAPI Document Handler</em>. Executing a manipulation can lead to cross-site request forgery.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2022-3726">CVE-2022-3726</a>. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3706 | GitLab Community Edition/Enterprise Edition up to 15.3.4/15.4.3/15.5.1 Job improper authorization (Issue 365532 / EUVD-2022-43063)]]></title>
<description><![CDATA[A vulnerability has been found in GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1 and classified as critical. The impacted element is an unknown function of the component Job Handler. Performing a manipulation results in improper authorization.

This vulnerability was n...]]></description>
<link>https://tsecurity.de/de/3679367/sicherheitsluecken/cve-2022-3706-gitlab-community-editionenterprise-edition-up-to-153415431551-job-improper-authorization-issue-365532-euvd-2022-43063/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679367/sicherheitsluecken/cve-2022-3706-gitlab-community-editionenterprise-edition-up-to-153415431551-job-improper-authorization-issue-365532-euvd-2022-43063/</guid>
<pubDate>Sun, 19 Jul 2026 13:09:08 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. The impacted element is an unknown function of the component <em>Job Handler</em>. Performing a manipulation results in improper authorization.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2022-3706">CVE-2022-3706</a>. The attack may be initiated remotely. There is no available exploit.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab 19.2: Duo CLI bringt KI für Security und Workflow ins Terminal - it boltwise]]></title>
<description><![CDATA[GitLab 19.2 macht die Duo CLI für alle verfügbar: KI unterstützt Security-Remediation per Dependency Scanning, erzeugt Merge Requests und prüft ...]]></description>
<link>https://tsecurity.de/de/3678346/it-security-nachrichten/gitlab-192-duo-cli-bringt-ki-fuer-security-und-workflow-ins-terminal-it-boltwise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678346/it-security-nachrichten/gitlab-192-duo-cli-bringt-ki-fuer-security-und-workflow-ins-terminal-it-boltwise/</guid>
<pubDate>Sat, 18 Jul 2026 19:53:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[GitLab 19.2 macht die Duo CLI für alle verfügbar: KI unterstützt <b>Security</b>-Remediation per Dependency Scanning, erzeugt Merge Requests und prüft ...]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3639 | GitLab Community Edition/Enterprise Edition resource consumption (ID 36687 / EUVD-2022-42999)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in GitLab Community Edition and Enterprise Edition. Affected is an unknown function. This manipulation causes resource consumption.

The identification of this vulnerability is CVE-2022-3639. It is possible to initiate the attack remotel...]]></description>
<link>https://tsecurity.de/de/3677288/sicherheitsluecken/cve-2022-3639-gitlab-community-editionenterprise-edition-resource-consumption-id-36687-euvd-2022-42999/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677288/sicherheitsluecken/cve-2022-3639-gitlab-community-editionenterprise-edition-resource-consumption-id-36687-euvd-2022-42999/</guid>
<pubDate>Sat, 18 Jul 2026 03:09:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition</a>. Affected is an unknown function. This manipulation causes resource consumption.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2022-3639">CVE-2022-3639</a>. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3613 | GitLab Community Edition/Enterprise Edition up to 15.5.6/15.6.3/15.7.1 Prometheus Server resource consumption (Issue 378456 / EUVD-2022-42974)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in GitLab Community Edition and Enterprise Edition up to 15.5.6/15.6.3/15.7.1. This issue affects some unknown processing of the component Prometheus Server Handler. The manipulation results in resource consumption.

This vulnerability is iden...]]></description>
<link>https://tsecurity.de/de/3676808/sicherheitsluecken/cve-2022-3613-gitlab-community-editionenterprise-edition-up-to-155615631571-prometheus-server-resource-consumption-issue-378456-euvd-2022-42974/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676808/sicherheitsluecken/cve-2022-3613-gitlab-community-editionenterprise-edition-up-to-155615631571-prometheus-server-resource-consumption-issue-378456-euvd-2022-42974/</guid>
<pubDate>Fri, 17 Jul 2026 20:23:23 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 15.5.6/15.6.3/15.7.1</a>. This issue affects some unknown processing of the component <em>Prometheus Server Handler</em>. The manipulation results in resource consumption.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2022-3613">CVE-2022-3613</a>. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[Building an Arch Linux aarch64 port for Holo Core (Collabora blog)]]></title>
<description><![CDATA[Collabora has published a blog
post about its work with Valve on Holo Core, which is a port of Arch Linux to
aarch64 to be used as the the operating system on Valve's
64-bit Arm Steam Frame gaming system. Collabora has released the
sources,
binary
packages, and a container image for aarch64 devic...]]></description>
<link>https://tsecurity.de/de/3676690/linux-tipps/building-an-arch-linux-aarch64-port-for-holo-core-collabora-blog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676690/linux-tipps/building-an-arch-linux-aarch64-port-for-holo-core-collabora-blog/</guid>
<pubDate>Fri, 17 Jul 2026 19:27:11 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Collabora has published a <a href="https://www.collabora.com/news-and-blog/news-and-events/building-an-arch-linux-aarch64-port-for-holo-core.html">blog
post</a> about its work with Valve on Holo Core, which is a port of Arch Linux to
aarch64 to be used as the the operating system on Valve's
64-bit Arm Steam Frame gaming system. Collabora has released the
<a href="https://gitlab.steamos.cloud/holo/holo-core-aarch64-preview">sources</a>,
<a href="https://steamdeck-packages.steamos.cloud/holo-core-aarch64-preview/mash-20251118.3/">binary
packages</a>, and a container image for aarch64 devices. The post
describes some of the challenges in porting Arch Linux to a new
architecture, and what remains to be done:</p>

<blockquote class="bq">
<p>Whilst the infrastructure developed to this point is capable of
building from first principles up until a point-in-time snapshot, the
next step is to build this into a system which can track Arch Linux as
it is developed. This work will serve as the basis of a
continuously-operating CI system capable of shadowing Arch Linux
itself. We will work with the upstream Arch Linux project to help Arch
with their efforts to port the distribution to <tt>aarch64</tt> architecture
and work towards automated repeatable builds.</p>
</blockquote>

<p>The post also includes instructions on how to create and test an
aarch64 build container on an x86_64 host, for users who would like to
follow along at home but lack a 64-bit Arm device.</p>

<p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-07-17 - Plasma, KDE Framework, COSMIC, Pipewire, Firefox]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected Mid or End of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may f...]]></description>
<link>https://tsecurity.de/de/3676482/unix-server/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676482/unix-server/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/</guid>
<pubDate>Fri, 17 Jul 2026 17:31:56 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected Mid or End of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may found thus far.</p>
<h3><a name="p-866692-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-866692-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-866692-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-866692-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/189028/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/189028/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/189028/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 7.0.14, the 7.0 series is now EOL (End Of Life). Please install 7.1, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/189028/1">(click for more details)</a>
<h2><a name="p-866692-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-866692-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>PipeWire</strong> <a href="https://gitlab.freedesktop.org/pipewire/pipewire/-/releases/1.6.8">1.6.8</a></li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/en-US/firefox/152.0.6/releasenotes/">152.0.6</a></li>
<li><strong>KDE Frameworks</strong> <a href="https://kde.org/announcements/frameworks/6/6.28.0/">6.28.0</a></li>
<li><strong>KDE Plasma</strong> <a href="https://kde.org/announcements/plasma/6/6.7.3/">6.7.3</a></li>
<li><strong>COSMIC</strong> Epoch <a href="https://github.com/pop-os/cosmic-epoch/releases/tag/epoch-1.3.0">1.3.0</a></li>
<li><strong>GStreamer</strong> <a href="https://gstreamer.freedesktop.org/releases/1.28/#1.28.5">1.28.5</a></li>
<li><strong>Wine</strong> <a href="https://www.winehq.org/news/2026071001">11.13</a></li>
</ul>
<h2><a name="p-866692-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-866692-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/189028/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/189028/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.177</li>
<li>linux66 6.6.144</li>
<li>linux612 6.12.95</li>
<li>linux618 6.18.38</li>
<li>linux71 7.1.3</li>
<li>linux72 7.2.0-rc3</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (7/17/26 15:26 CEST)</p>
<ul>
<li>testing core x86_64:  62 new and 62 removed package(s)</li>
<li>testing extra x86_64:  1486 new and 1584 removed package(s)</li>
<li>testing multilib x86_64:  13 new and 13 removed package(s)</li>
</ul>
<p>A list of all package changes can be found <a href="https://gist.githubusercontent.com/hphilm/20841c3d8f4f60c7bfbc2f2ca8f53b62/raw/c5bc9c08f504f55939e66ead30e0673fba85c544">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/189028/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-07-17-plasma-kde-framework-cosmic-pipewire-firefox/189028">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3572 | GitLab Community Edition/Enterprise Edition cross site scripting (Issue 378214 / EUVD-2022-42936)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in GitLab Community Edition and Enterprise Edition. Impacted is an unknown function. The manipulation leads to cross site scripting.

This vulnerability is documented as CVE-2022-3572. The attack can be initiated remotely. There...]]></description>
<link>https://tsecurity.de/de/3675819/sicherheitsluecken/cve-2022-3572-gitlab-community-editionenterprise-edition-cross-site-scripting-issue-378214-euvd-2022-42936/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675819/sicherheitsluecken/cve-2022-3572-gitlab-community-editionenterprise-edition-cross-site-scripting-issue-378214-euvd-2022-42936/</guid>
<pubDate>Fri, 17 Jul 2026 12:53:35 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition</a>. Impacted is an unknown function. The manipulation leads to cross site scripting.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2022-3572">CVE-2022-3572</a>. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3573 | GitLab Community Edition/Enterprise Edition up to 15.5.6/15.6.3/15.7.1 Query Parameter cross site scripting (Issue 378216 / EUVD-2022-42937)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in GitLab Community Edition and Enterprise Edition up to 15.5.6/15.6.3/15.7.1. This affects an unknown function of the component Query Parameter Handler. Executing a manipulation can lead to cross site scripting.

This vulnerability is registere...]]></description>
<link>https://tsecurity.de/de/3675817/sicherheitsluecken/cve-2022-3573-gitlab-community-editionenterprise-edition-up-to-155615631571-query-parameter-cross-site-scripting-issue-378216-euvd-2022-42937/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675817/sicherheitsluecken/cve-2022-3573-gitlab-community-editionenterprise-edition-up-to-155615631571-query-parameter-cross-site-scripting-issue-378216-euvd-2022-42937/</guid>
<pubDate>Fri, 17 Jul 2026 12:53:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 15.5.6/15.6.3/15.7.1</a>. This affects an unknown function of the component <em>Query Parameter Handler</em>. Executing a manipulation can lead to cross site scripting.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2022-3573">CVE-2022-3573</a>. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[Intruder brings AI-powered, on-demand penetration testing to web applications]]></title>
<description><![CDATA[Intruder has announced the launch of AI Pentesting for web applications, providing on-demand penetration testing. Following its initial release of issue-level investigations last quarter, the platform now allows organizations to securely connect their codebases via GitHub or GitLab to automatical...]]></description>
<link>https://tsecurity.de/de/3673419/it-security-nachrichten/intruder-brings-ai-powered-on-demand-penetration-testing-to-web-applications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673419/it-security-nachrichten/intruder-brings-ai-powered-on-demand-penetration-testing-to-web-applications/</guid>
<pubDate>Thu, 16 Jul 2026 14:24:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Intruder has announced the launch of AI Pentesting for web applications, providing on-demand penetration testing. Following its initial release of issue-level investigations last quarter, the platform now allows organizations to securely connect their codebases via GitHub or GitLab to automatically…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/intruder-brings-ai-powered-on-demand-penetration-testing-to-web-applications/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/intruder-brings-ai-powered-on-demand-penetration-testing-to-web-applications/">Intruder brings AI-powered, on-demand penetration testing to web applications</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Intruder brings AI-powered, on-demand penetration testing to web applications]]></title>
<description><![CDATA[Intruder has announced the launch of AI Pentesting for web applications, providing on-demand penetration testing. Following its initial release of issue-level investigations last quarter, the platform now allows organizations to securely connect their codebases via GitHub or GitLab to automatical...]]></description>
<link>https://tsecurity.de/de/3673270/it-security-nachrichten/intruder-brings-ai-powered-on-demand-penetration-testing-to-web-applications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673270/it-security-nachrichten/intruder-brings-ai-powered-on-demand-penetration-testing-to-web-applications/</guid>
<pubDate>Thu, 16 Jul 2026 13:39:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Intruder has announced the launch of AI Pentesting for web applications, providing on-demand penetration testing. Following its initial release of issue-level investigations last quarter, the platform now allows organizations to securely connect their codebases via GitHub or GitLab to automatically scope and launch penetration tests in minutes, with results and audit-ready reporting in hours. Mythos and Daybreak have proven that AI is extremely adept at finding security vulnerabilities. At the same time, AI is accelerating … <a href="https://www.helpnetsecurity.com/2026/07/16/intruder-brings-ai-powered-on-demand-penetration-testing-to-web-applications/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/16/intruder-brings-ai-powered-on-demand-penetration-testing-to-web-applications/">Intruder brings AI-powered, on-demand penetration testing to web applications</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3514 | GitLab Community Edition/Enterprise Edition up to 15.5.6/15.6.3/15.7.1 URL Parser denial of service (Issue 377978 / EUVD-2022-42883)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in GitLab Community Edition and Enterprise Edition up to 15.5.6/15.6.3/15.7.1. The impacted element is an unknown function of the component URL Parser. Performing a manipulation results in denial of service.

This vulnerability is cataloged...]]></description>
<link>https://tsecurity.de/de/3672814/sicherheitsluecken/cve-2022-3514-gitlab-community-editionenterprise-edition-up-to-155615631571-url-parser-denial-of-service-issue-377978-euvd-2022-42883/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672814/sicherheitsluecken/cve-2022-3514-gitlab-community-editionenterprise-edition-up-to-155615631571-url-parser-denial-of-service-issue-377978-euvd-2022-42883/</guid>
<pubDate>Thu, 16 Jul 2026 10:40:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 15.5.6/15.6.3/15.7.1</a>. The impacted element is an unknown function of the component <em>URL Parser</em>. Performing a manipulation results in denial of service.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2022-3514">CVE-2022-3514</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3486 | GitLab Community Edition/Enterprise Edition up to 15.3.4/15.4.3/15.5.1 URL redirect (Issue 377810 / EUVD-2022-42858)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1. The affected element is an unknown function of the component URL Handler. Such manipulation leads to open redirect.

This vulnerability is uniquely identifie...]]></description>
<link>https://tsecurity.de/de/3672163/sicherheitsluecken/cve-2022-3486-gitlab-community-editionenterprise-edition-up-to-153415431551-url-redirect-issue-377810-euvd-2022-42858/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672163/sicherheitsluecken/cve-2022-3486-gitlab-community-editionenterprise-edition-up-to-153415431551-url-redirect-issue-377810-euvd-2022-42858/</guid>
<pubDate>Thu, 16 Jul 2026 03:35:22 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1</a>. The affected element is an unknown function of the component <em>URL Handler</em>. Such manipulation leads to open redirect.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2022-3486">CVE-2022-3486</a>. The attack can be launched remotely. No exploit exists.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3482 | GitLab Community Edition/Enterprise Edition Release Name access control (Issue 377802 / EUVD-2022-42854)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in GitLab Community Edition and Enterprise Edition. This impacts an unknown function of the component Release Name Handler. Performing a manipulation results in improper access controls.

This vulnerability was named CVE-2022-3482. The attack ...]]></description>
<link>https://tsecurity.de/de/3670967/sicherheitsluecken/cve-2022-3482-gitlab-community-editionenterprise-edition-release-name-access-control-issue-377802-euvd-2022-42854/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670967/sicherheitsluecken/cve-2022-3482-gitlab-community-editionenterprise-edition-release-name-access-control-issue-377802-euvd-2022-42854/</guid>
<pubDate>Wed, 15 Jul 2026 16:26:08 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition</a>. This impacts an unknown function of the component <em>Release Name Handler</em>. Performing a manipulation results in improper access controls.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2022-3482">CVE-2022-3482</a>. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3483 | GitLab Community Edition/Enterprise Edition up to 15.3.4/15.4.3/15.5.1 Datadog Access Token information disclosure (Issue 377799 / EUVD-2022-42855)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1. Affected is an unknown function of the component Datadog Access Token Handler. This manipulation causes information disclosure.

This vulnerability is registe...]]></description>
<link>https://tsecurity.de/de/3670966/sicherheitsluecken/cve-2022-3483-gitlab-community-editionenterprise-edition-up-to-153415431551-datadog-access-token-information-disclosure-issue-377799-euvd-2022-42855/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670966/sicherheitsluecken/cve-2022-3483-gitlab-community-editionenterprise-edition-up-to-153415431551-datadog-access-token-information-disclosure-issue-377799-euvd-2022-42855/</guid>
<pubDate>Wed, 15 Jul 2026 16:26:07 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1</a>. Affected is an unknown function of the component <em>Datadog Access Token Handler</em>. This manipulation causes information disclosure.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2022-3483">CVE-2022-3483</a>. Remote exploitation of the attack is possible. No exploit is available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3478 | GitLab up to 15.4.5/15.5.4/15.6.0 Nuget Package denial of service (Issue 377788 / EUVD-2022-42850)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in GitLab up to 15.4.5/15.5.4/15.6.0. The affected element is an unknown function of the component Nuget Package Handler. Such manipulation leads to denial of service.

This vulnerability is listed as CVE-2022-3478. The attack may be...]]></description>
<link>https://tsecurity.de/de/3670463/sicherheitsluecken/cve-2022-3478-gitlab-up-to-154515541560-nuget-package-denial-of-service-issue-377788-euvd-2022-42850/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670463/sicherheitsluecken/cve-2022-3478-gitlab-up-to-154515541560-nuget-package-denial-of-service-issue-377788-euvd-2022-42850/</guid>
<pubDate>Wed, 15 Jul 2026 13:24:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/gitlab">GitLab up to 15.4.5/15.5.4/15.6.0</a>. The affected element is an unknown function of the component <em>Nuget Package Handler</em>. Such manipulation leads to denial of service.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2022-3478">CVE-2022-3478</a>. The attack may be performed from remote. There is no available exploit.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3411 | GitLab Community Edition/Enterprise Edition Issue Description resource consumption (Duplicate CVE-2023-0886 / Issue 376247)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in GitLab Community Edition and Enterprise Edition. The affected element is an unknown function of the component Issue Description Handler. Executing a manipulation can lead to resource consumption.

The identification of this vulnerability is C...]]></description>
<link>https://tsecurity.de/de/3667602/sicherheitsluecken/cve-2022-3411-gitlab-community-editionenterprise-edition-issue-description-resource-consumption-duplicate-cve-2023-0886-issue-376247/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667602/sicherheitsluecken/cve-2022-3411-gitlab-community-editionenterprise-edition-issue-description-resource-consumption-duplicate-cve-2023-0886-issue-376247/</guid>
<pubDate>Tue, 14 Jul 2026 12:27:50 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition</a>. The affected element is an unknown function of the component <em>Issue Description Handler</em>. Executing a manipulation can lead to resource consumption.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2022-3411">CVE-2022-3411</a>. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is advised.

This entry has a duplicate CVE-2023-0886 assigned.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3413 | GitLab Enterprise Edition up to 15.3.4/15.4.3/15.5.1 Audit Event improper authorization (Issue 374926 / EUVD-2022-42790)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in GitLab Enterprise Edition up to 15.3.4/15.4.3/15.5.1. Impacted is an unknown function of the component Audit Event Handler. This manipulation causes improper authorization.

This vulnerability is handled as CVE-2022-3413. The at...]]></description>
<link>https://tsecurity.de/de/3667600/sicherheitsluecken/cve-2022-3413-gitlab-enterprise-edition-up-to-153415431551-audit-event-improper-authorization-issue-374926-euvd-2022-42790/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667600/sicherheitsluecken/cve-2022-3413-gitlab-enterprise-edition-up-to-153415431551-audit-event-improper-authorization-issue-374926-euvd-2022-42790/</guid>
<pubDate>Tue, 14 Jul 2026 12:27:47 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/gitlab:enterprise_edition">GitLab Enterprise Edition up to 15.3.4/15.4.3/15.5.1</a>. Impacted is an unknown function of the component <em>Audit Event Handler</em>. This manipulation causes improper authorization.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2022-3413">CVE-2022-3413</a>. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3375 | GitLab up to 15.8.4/15.9.3/15.10.0 Branch Name information disclosure (Issue 376041 / EUVD-2022-42754)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in GitLab up to 15.8.4/15.9.3/15.10.0. Affected by this issue is some unknown functionality of the component Branch Name Handler. This manipulation causes information disclosure.

This vulnerability is handled as CVE-2022-3375. The attack ca...]]></description>
<link>https://tsecurity.de/de/3666638/sicherheitsluecken/cve-2022-3375-gitlab-up-to-1584159315100-branch-name-information-disclosure-issue-376041-euvd-2022-42754/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666638/sicherheitsluecken/cve-2022-3375-gitlab-up-to-1584159315100-branch-name-information-disclosure-issue-376041-euvd-2022-42754/</guid>
<pubDate>Tue, 14 Jul 2026 02:37:46 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/gitlab">GitLab up to 15.8.4/15.9.3/15.10.0</a>. Affected by this issue is some unknown functionality of the component <em>Branch Name Handler</em>. This manipulation causes information disclosure.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2022-3375">CVE-2022-3375</a>. The attack can be initiated remotely. There is not any exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3381 | GitLab up to 15.7.7/15.8.3/15.9.1 URL redirect (Issue 376046 / EUVD-2022-42759)]]></title>
<description><![CDATA[A vulnerability was found in GitLab up to 15.7.7/15.8.3/15.9.1. It has been declared as problematic. This vulnerability affects unknown code of the component URL Handler. Executing a manipulation can lead to open redirect.

This vulnerability is handled as CVE-2022-3381. The attack can be execute...]]></description>
<link>https://tsecurity.de/de/3666636/sicherheitsluecken/cve-2022-3381-gitlab-up-to-157715831591-url-redirect-issue-376046-euvd-2022-42759/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666636/sicherheitsluecken/cve-2022-3381-gitlab-up-to-157715831591-url-redirect-issue-376046-euvd-2022-42759/</guid>
<pubDate>Tue, 14 Jul 2026 02:37:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gitlab">GitLab up to 15.7.7/15.8.3/15.9.1</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. This vulnerability affects unknown code of the component <em>URL Handler</em>. Executing a manipulation can lead to open redirect.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2022-3381">CVE-2022-3381</a>. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3325 | GitLab Community Edition/Enterprise Edition API access control (Issue 36081 / EUVD-2022-42715)]]></title>
<description><![CDATA[A vulnerability has been found in GitLab Community Edition and Enterprise Edition and classified as critical. Affected by this issue is some unknown functionality of the component API. Performing a manipulation results in improper access controls.

This vulnerability is cataloged as CVE-2022-3325...]]></description>
<link>https://tsecurity.de/de/3662773/sicherheitsluecken/cve-2022-3325-gitlab-community-editionenterprise-edition-api-access-control-issue-36081-euvd-2022-42715/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662773/sicherheitsluecken/cve-2022-3325-gitlab-community-editionenterprise-edition-api-access-control-issue-36081-euvd-2022-42715/</guid>
<pubDate>Sun, 12 Jul 2026 07:22:54 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this issue is some unknown functionality of the component <em>API</em>. Performing a manipulation results in improper access controls.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2022-3325">CVE-2022-3325</a>. It is possible to initiate the attack remotely. There is no exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3291 | GitLab Enterprise Edition Cache information disclosure (Issue 35429 / EUVD-2022-42686)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in GitLab Enterprise Edition. Affected is an unknown function of the component Cache Handler. This manipulation causes information disclosure.

This vulnerability is tracked as CVE-2022-3291. The attack is possible to be carried...]]></description>
<link>https://tsecurity.de/de/3661376/sicherheitsluecken/cve-2022-3291-gitlab-enterprise-edition-cache-information-disclosure-issue-35429-euvd-2022-42686/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661376/sicherheitsluecken/cve-2022-3291-gitlab-enterprise-edition-cache-information-disclosure-issue-35429-euvd-2022-42686/</guid>
<pubDate>Sat, 11 Jul 2026 08:38:34 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/gitlab:enterprise_edition">GitLab Enterprise Edition</a>. Affected is an unknown function of the component <em>Cache Handler</em>. This manipulation causes information disclosure.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2022-3291">CVE-2022-3291</a>. The attack is possible to be carried out remotely. No exploit exists.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3293 | GitLab Enterprise Edition WebHook Log information disclosure (Issue 36900 / EUVD-2022-42687)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in GitLab Enterprise Edition. Affected by this vulnerability is an unknown functionality of the component WebHook Log Handler. Such manipulation leads to information disclosure.

This vulnerability is listed as CVE-2022-3293. The att...]]></description>
<link>https://tsecurity.de/de/3661375/sicherheitsluecken/cve-2022-3293-gitlab-enterprise-edition-webhook-log-information-disclosure-issue-36900-euvd-2022-42687/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661375/sicherheitsluecken/cve-2022-3293-gitlab-enterprise-edition-webhook-log-information-disclosure-issue-36900-euvd-2022-42687/</guid>
<pubDate>Sat, 11 Jul 2026 08:38:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/gitlab:enterprise_edition">GitLab Enterprise Edition</a>. Affected by this vulnerability is an unknown functionality of the component <em>WebHook Log Handler</em>. Such manipulation leads to information disclosure.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2022-3293">CVE-2022-3293</a>. The attack may be performed from remote. There is no available exploit.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3280 | GitLab Community Edition/Enterprise Edition up to 15.3.4/15.4.3/15.5.1 URL redirect (Issue 352611 / EUVD-2022-42676)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1. This vulnerability affects unknown code of the component URL Handler. The manipulation leads to open redirect.

This vulnerability is traded as CVE-2022-3280. It...]]></description>
<link>https://tsecurity.de/de/3661245/sicherheitsluecken/cve-2022-3280-gitlab-community-editionenterprise-edition-up-to-153415431551-url-redirect-issue-352611-euvd-2022-42676/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661245/sicherheitsluecken/cve-2022-3280-gitlab-community-editionenterprise-edition-up-to-153415431551-url-redirect-issue-352611-euvd-2022-42676/</guid>
<pubDate>Sat, 11 Jul 2026 06:38:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 15.3.4/15.4.3/15.5.1</a>. This vulnerability affects unknown code of the component <em>URL Handler</em>. The manipulation leads to open redirect.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2022-3280">CVE-2022-3280</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3286 | GitLab Enterprise Edition IP Restriction access control (Issue 36382 / EUVD-2022-42682)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in GitLab Enterprise Edition. This affects an unknown function of the component IP Restriction Handler. The manipulation leads to improper access controls.

This vulnerability is referenced as CVE-2022-3286. Remote exploitation of the attack i...]]></description>
<link>https://tsecurity.de/de/3661244/sicherheitsluecken/cve-2022-3286-gitlab-enterprise-edition-ip-restriction-access-control-issue-36382-euvd-2022-42682/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661244/sicherheitsluecken/cve-2022-3286-gitlab-enterprise-edition-ip-restriction-access-control-issue-36382-euvd-2022-42682/</guid>
<pubDate>Sat, 11 Jul 2026 06:38:03 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/gitlab:enterprise_edition">GitLab Enterprise Edition</a>. This affects an unknown function of the component <em>IP Restriction Handler</em>. The manipulation leads to improper access controls.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2022-3286">CVE-2022-3286</a>. Remote exploitation of the attack is possible. No exploit is available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3283 | GitLab Community Edition/Enterprise Edition Issue resource consumption (Issue 36198 / EUVD-2022-42679)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in GitLab Community Edition and Enterprise Edition. Affected by this issue is some unknown functionality of the component Issue Handler. Such manipulation leads to resource consumption.

This vulnerability is referenced as CVE-2022-3283. It is p...]]></description>
<link>https://tsecurity.de/de/3661243/sicherheitsluecken/cve-2022-3283-gitlab-community-editionenterprise-edition-issue-resource-consumption-issue-36198-euvd-2022-42679/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661243/sicherheitsluecken/cve-2022-3283-gitlab-community-editionenterprise-edition-issue-resource-consumption-issue-36198-euvd-2022-42679/</guid>
<pubDate>Sat, 11 Jul 2026 06:38:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition</a>. Affected by this issue is some unknown functionality of the component <em>Issue Handler</em>. Such manipulation leads to resource consumption.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2022-3283">CVE-2022-3283</a>. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3285 | GitLab up to 15.2.4/15.3.3/15.4.0 Healthcheck Endpoint denial of service (Issue 64 / EUVD-2022-42681)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in GitLab up to 15.2.4/15.3.3/15.4.0. This issue affects some unknown processing of the component Healthcheck Endpoint. The manipulation results in denial of service.

This vulnerability is known as CVE-2022-3285. It is possible to launch the at...]]></description>
<link>https://tsecurity.de/de/3661242/sicherheitsluecken/cve-2022-3285-gitlab-up-to-152415331540-healthcheck-endpoint-denial-of-service-issue-64-euvd-2022-42681/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661242/sicherheitsluecken/cve-2022-3285-gitlab-up-to-152415331540-healthcheck-endpoint-denial-of-service-issue-64-euvd-2022-42681/</guid>
<pubDate>Sat, 11 Jul 2026 06:38:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/gitlab">GitLab up to 15.2.4/15.3.3/15.4.0</a>. This issue affects some unknown processing of the component <em>Healthcheck Endpoint</em>. The manipulation results in denial of service.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2022-3285">CVE-2022-3285</a>. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3288 | GitLab Community Edition/Enterprise Edition Branche access control (Issue 35494 / EUVD-2022-42684)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in GitLab Community Edition and Enterprise Edition. This impacts an unknown function of the component Branche Handler. The manipulation results in improper access controls.

This vulnerability is identified as CVE-2022-3288. The attack can be execu...]]></description>
<link>https://tsecurity.de/de/3661241/sicherheitsluecken/cve-2022-3288-gitlab-community-editionenterprise-edition-branche-access-control-issue-35494-euvd-2022-42684/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661241/sicherheitsluecken/cve-2022-3288-gitlab-community-editionenterprise-edition-branche-access-control-issue-35494-euvd-2022-42684/</guid>
<pubDate>Sat, 11 Jul 2026 06:38:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition</a>. This impacts an unknown function of the component <em>Branche Handler</em>. The manipulation results in improper access controls.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2022-3288">CVE-2022-3288</a>. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3279 | GitLab Community Edition/Enterprise Edition Job Log Parser denial of service (Issue 36424 / EUVD-2022-42675)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in GitLab Community Edition and Enterprise Edition. The impacted element is an unknown function of the component Job Log Parser. Executing a manipulation can lead to denial of service.

The identification of this vulnerability is CVE-20...]]></description>
<link>https://tsecurity.de/de/3661001/sicherheitsluecken/cve-2022-3279-gitlab-community-editionenterprise-edition-job-log-parser-denial-of-service-issue-36424-euvd-2022-42675/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661001/sicherheitsluecken/cve-2022-3279-gitlab-community-editionenterprise-edition-job-log-parser-denial-of-service-issue-36424-euvd-2022-42675/</guid>
<pubDate>Sat, 11 Jul 2026 02:07:44 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition</a>. The impacted element is an unknown function of the component <em>Job Log Parser</em>. Executing a manipulation can lead to denial of service.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2022-3279">CVE-2022-3279</a>. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[[Stable Update] 2026-07-11 - Kernels, COSMIC 1.2, Xorg, Firefox, Thunderbird, KDE Gear]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. This also marks the stable release of ‘Bian-May’ - Manjaro 26.1. We will work now on the Release Candidate ISOs to test possible issues before releasing new install medias.
Current Promotions

Get the latest Gaming Laptop ...]]></description>
<link>https://tsecurity.de/de/3660964/unix-server/stable-update-2026-07-11-kernels-cosmic-12-xorg-firefox-thunderbird-kde-gear/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660964/unix-server/stable-update-2026-07-11-kernels-cosmic-12-xorg-firefox-thunderbird-kde-gear/</guid>
<pubDate>Sat, 11 Jul 2026 01:15:49 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. This also marks the stable release of ‘Bian-May’ - Manjaro 26.1. We will work now on the Release Candidate ISOs to test possible issues before releasing new install medias.</p>
<h3><a name="p-865662-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-865662-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-865662-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-865662-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/stable-update-2026-07-11-kernels-cosmic-1-2-xorg-firefox-thunderbird-kde-gear/188902/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/stable-update-2026-07-11-kernels-cosmic-1-2-xorg-firefox-thunderbird-kde-gear/188902/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/stable-update-2026-07-11-kernels-cosmic-1-2-xorg-firefox-thunderbird-kde-gear/188902/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 7.0.14, the 7.0 series is now EOL (End Of Life). Please install 7.1, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/stable-update-2026-07-11-kernels-cosmic-1-2-xorg-firefox-thunderbird-kde-gear/188902/1">(click for more details)</a>
<h2><a name="p-865662-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-865662-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>Kernels</strong> got updated
<ul>
<li><strong>linux70</strong> got removed from our repos</li>
<li><strong>linux-firmware</strong> <a href="https://gitlab.com/kernel-firmware/linux-firmware/-/compare/20260519...20260622?from_project_id=48890189">20260622</a></li>
<li>slight <strong>toolchain</strong> update</li>
<li><strong>NVIDIA</strong> <a href="https://www.nvidia.com/en-us/drivers/details/274183/">610.43.03</a></li>
<li>we dropped <strong>NVIDIA</strong> driver series 570xx and 575xx</li>
</ul>
</li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/en-US/firefox/152.0.4/releasenotes/">152.0.4</a></li>
<li><strong>Thunderbird</strong> <a href="https://www.thunderbird.net/en-US/thunderbird/152.0/releasenotes">152.0</a></li>
<li><strong>Virtualbox</strong> <a href="https://www.virtualbox.org/wiki/Changelog-7.2">7.2.12</a></li>
<li><strong>Godot</strong> <a href="https://godotengine.org/releases/4.7/">4.7</a></li>
<li><strong>Pipewire</strong> <a href="https://gitlab.freedesktop.org/pipewire/pipewire/-/releases/1.6.7">1.6.7</a></li>
<li><strong>Systemd</strong> <a href="https://github.com/systemd/systemd/compare/v260.2...v261.1">261.1</a></li>
<li><strong>COSMIC</strong> Epoch <a href="https://github.com/pop-os/cosmic-epoch/releases/tag/epoch-1.2.0">1.2.0</a></li>
<li><strong>Plasma</strong> <a href="https://kde.org/announcements/plasma/6/6.6.6/">6.6.6</a></li>
<li><strong>KDE Gear</strong> <a href="https://kde.org/announcements/gear/26.04.3/">26.04.3</a></li>
<li><strong>QEmu</strong> <a href="https://www.qemu.org/2026/04/22/qemu-11-0-0/">11.0.2</a></li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/en-US/firefox/152.0.5/releasenotes/">152.0.5</a></li>
<li><strong>Xorg-Server</strong> <a href="https://lists.x.org/archives/xorg-announce/2026-July/003718.html">21.1.24</a></li>
<li><strong>XWayland</strong> <a href="https://lists.x.org/archives/xorg-announce/2026-July/003717.html">24.1.13</a></li>
<li><strong>OpenSearch</strong> <a href="https://opensearch.org/blog/explore-opensearch-3-7/">3.7.0</a></li>
</ul>
<h2><a name="p-865662-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-865662-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/stable-update-2026-07-11-kernels-cosmic-1-2-xorg-firefox-thunderbird-kde-gear/188902/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/stable-update-2026-07-11-kernels-cosmic-1-2-xorg-firefox-thunderbird-kde-gear/188902/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.177</li>
<li>linux66 6.6.144</li>
<li>linux612 6.12.95</li>
<li>linux618 6.18.38</li>
<li>linux71 7.1.3</li>
<li>linux72 7.2.0-rc2</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (7/9/26 07:43 CEST)</p>
<ul>
<li>stable core x86_64:  121 new and 122 removed package(s)</li>
<li>stable extra x86_64:  4021 new and 4169 removed package(s)</li>
<li>stable multilib x86_64:  65 new and 70 removed package(s)</li>
</ul>
<p>A list of all package changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1205/raw">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/stable-update-2026-07-11-kernels-cosmic-1-2-xorg-firefox-thunderbird-kde-gear/188902/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>3 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/stable-update-2026-07-11-kernels-cosmic-1-2-xorg-firefox-thunderbird-kde-gear/188902">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-12506 | GitLab up to 18.11.6/19.0.3/19.1.1 Git Reference Name Resolver input validation (WID-SEC-2026-2265)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in GitLab up to 18.11.6/19.0.3/19.1.1. This affects an unknown part of the component Git Reference Name Resolver. The manipulation results in improper input validation.

This vulnerability is identified as CVE-2025-12506. The attack can be exe...]]></description>
<link>https://tsecurity.de/de/3657262/sicherheitsluecken/cve-2025-12506-gitlab-up-to-1811619031911-git-reference-name-resolver-input-validation-wid-sec-2026-2265/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657262/sicherheitsluecken/cve-2025-12506-gitlab-up-to-1811619031911-git-reference-name-resolver-input-validation-wid-sec-2026-2265/</guid>
<pubDate>Thu, 09 Jul 2026 15:54:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/gitlab">GitLab up to 18.11.6/19.0.3/19.1.1</a>. This affects an unknown part of the component <em>Git Reference Name Resolver</em>. The manipulation results in improper input validation.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2025-12506">CVE-2025-12506</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-8472 | GitLab up to 18.11.6/19.0.3/19.1.1 Work Item Metadata Access authorization (WID-SEC-2026-2265)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in GitLab up to 18.11.6/19.0.3/19.1.1. Affected by this vulnerability is an unknown functionality of the component Work Item Metadata Access. Such manipulation leads to missing authorization.

This vulnerability is uniquely identified a...]]></description>
<link>https://tsecurity.de/de/3657261/sicherheitsluecken/cve-2026-8472-gitlab-up-to-1811619031911-work-item-metadata-access-authorization-wid-sec-2026-2265/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657261/sicherheitsluecken/cve-2026-8472-gitlab-up-to-1811619031911-work-item-metadata-access-authorization-wid-sec-2026-2265/</guid>
<pubDate>Thu, 09 Jul 2026 15:54:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/gitlab">GitLab up to 18.11.6/19.0.3/19.1.1</a>. Affected by this vulnerability is an unknown functionality of the component <em>Work Item Metadata Access</em>. Such manipulation leads to missing authorization.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-8472">CVE-2026-8472</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-13151 | GitLab up to 18.11.6/19.0.3/19.1.1 Setting improper authorization (WID-SEC-2026-2265)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in GitLab up to 18.11.6/19.0.3/19.1.1. This issue affects some unknown processing of the component Setting Handler. Such manipulation leads to improper authorization.

This vulnerability is listed as CVE-2026-13151. The attack may be perfo...]]></description>
<link>https://tsecurity.de/de/3657260/sicherheitsluecken/cve-2026-13151-gitlab-up-to-1811619031911-setting-improper-authorization-wid-sec-2026-2265/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657260/sicherheitsluecken/cve-2026-13151-gitlab-up-to-1811619031911-setting-improper-authorization-wid-sec-2026-2265/</guid>
<pubDate>Thu, 09 Jul 2026 15:54:41 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/gitlab">GitLab up to 18.11.6/19.0.3/19.1.1</a>. This issue affects some unknown processing of the component <em>Setting Handler</em>. Such manipulation leads to improper authorization.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-13151">CVE-2026-13151</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-6352 | GitLab up to 18.11.6/19.0.3/19.1.1 GraphQL Operations improper authorization (WID-SEC-2026-2265)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in GitLab up to 18.11.6/19.0.3/19.1.1. This affects an unknown function of the component GraphQL Operations. The manipulation leads to improper authorization.

This vulnerability is traded as CVE-2026-6352. It is possible to initiate the at...]]></description>
<link>https://tsecurity.de/de/3657259/sicherheitsluecken/cve-2026-6352-gitlab-up-to-1811619031911-graphql-operations-improper-authorization-wid-sec-2026-2265/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657259/sicherheitsluecken/cve-2026-6352-gitlab-up-to-1811619031911-graphql-operations-improper-authorization-wid-sec-2026-2265/</guid>
<pubDate>Thu, 09 Jul 2026 15:54:40 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/gitlab">GitLab up to 18.11.6/19.0.3/19.1.1</a>. This affects an unknown function of the component <em>GraphQL Operations</em>. The manipulation leads to improper authorization.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-6352">CVE-2026-6352</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[LineageOS: Web-based Flashing wird Realität]]></title>
<description><![CDATA[Die Entwickler hinter LineageOS haben ein Update-Paket geschnürt und in einem Blogpost weitreichende Neuerungen für das gesamte Ökosystem angekündigt. Neben einer runderneuerten Statistik-Seite, einem Dark Mode für das Wiki und dem Wechsel beim Issue-Tracker von GitLab zu GitHub sticht ein...Zum ...]]></description>
<link>https://tsecurity.de/de/3657167/it-nachrichten/lineageos-web-based-flashing-wird-realitaet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657167/it-nachrichten/lineageos-web-based-flashing-wird-realitaet/</guid>
<pubDate>Thu, 09 Jul 2026 15:18:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Entwickler hinter LineageOS haben ein Update-Paket geschnürt und in einem Blogpost weitreichende Neuerungen für das gesamte Ökosystem angekündigt. Neben einer runderneuerten Statistik-Seite, einem Dark Mode für das Wiki und dem Wechsel beim Issue-Tracker von GitLab zu GitHub sticht ein...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/lineageos-web-based-flashing-wird-realitaet/">LineageOS: Web-based Flashing wird Realität</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab Patches Eight Security Vulnerabilities Across Community and Enterprise Editions]]></title>
<description><![CDATA[GitLab has released critical security updates addressing eight vulnerabilities across its Community Edition (CE) and Enterprise Edition (EE), urging users to upgrade immediately to mitigate potential risks. The latest patch versions 19.1.2, 19.0.4, and 18.11.7 were published on July 8,…
Read more...]]></description>
<link>https://tsecurity.de/de/3657042/it-security-nachrichten/gitlab-patches-eight-security-vulnerabilities-across-community-and-enterprise-editions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657042/it-security-nachrichten/gitlab-patches-eight-security-vulnerabilities-across-community-and-enterprise-editions/</guid>
<pubDate>Thu, 09 Jul 2026 14:38:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GitLab has released critical security updates addressing eight vulnerabilities across its Community Edition (CE) and Enterprise Edition (EE), urging users to upgrade immediately to mitigate potential risks. The latest patch versions 19.1.2, 19.0.4, and 18.11.7 were published on July 8,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/gitlab-patches-eight-security-vulnerabilities-across-community-and-enterprise-editions/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/gitlab-patches-eight-security-vulnerabilities-across-community-and-enterprise-editions/">GitLab Patches Eight Security Vulnerabilities Across Community and Enterprise Editions</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-13320 | GitLab up to 18.11.6/19.0.3/19.1.1 Input Sanitizer cross site scripting (WID-SEC-2026-2265)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in GitLab up to 18.11.6/19.0.3/19.1.1. Impacted is an unknown function of the component Input Sanitizer. Performing a manipulation results in cross site scripting.

This vulnerability is cataloged as CVE-2026-13320. It is possible to initia...]]></description>
<link>https://tsecurity.de/de/3656909/sicherheitsluecken/cve-2026-13320-gitlab-up-to-1811619031911-input-sanitizer-cross-site-scripting-wid-sec-2026-2265/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656909/sicherheitsluecken/cve-2026-13320-gitlab-up-to-1811619031911-input-sanitizer-cross-site-scripting-wid-sec-2026-2265/</guid>
<pubDate>Thu, 09 Jul 2026 13:53:31 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/gitlab">GitLab up to 18.11.6/19.0.3/19.1.1</a>. Impacted is an unknown function of the component <em>Input Sanitizer</em>. Performing a manipulation results in cross site scripting.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-13320">CVE-2026-13320</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-6896 | GitLab up to 18.11.6/19.0.3/19.1.1 Input Sanitization permission (WID-SEC-2026-2265)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in GitLab up to 18.11.6/19.0.3/19.1.1. This impacts an unknown function of the component Input Sanitization. The manipulation results in permission issues.

This vulnerability is known as CVE-2026-6896. It is possible to launch the attack remo...]]></description>
<link>https://tsecurity.de/de/3656908/sicherheitsluecken/cve-2026-6896-gitlab-up-to-1811619031911-input-sanitization-permission-wid-sec-2026-2265/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656908/sicherheitsluecken/cve-2026-6896-gitlab-up-to-1811619031911-input-sanitization-permission-wid-sec-2026-2265/</guid>
<pubDate>Thu, 09 Jul 2026 13:53:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/gitlab">GitLab up to 18.11.6/19.0.3/19.1.1</a>. This impacts an unknown function of the component <em>Input Sanitization</em>. The manipulation results in permission issues.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-6896">CVE-2026-6896</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-7492 | GitLab up to 18.11.6/19.0.3/19.1.1 Cross-project Reference Pages improper authorization (WID-SEC-2026-2265)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in GitLab up to 18.11.6/19.0.3/19.1.1. Affected is an unknown function of the component Cross-project Reference Pages. This manipulation causes improper authorization.

This vulnerability is handled as CVE-2026-7492. The attack can be initia...]]></description>
<link>https://tsecurity.de/de/3656907/sicherheitsluecken/cve-2026-7492-gitlab-up-to-1811619031911-cross-project-reference-pages-improper-authorization-wid-sec-2026-2265/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656907/sicherheitsluecken/cve-2026-7492-gitlab-up-to-1811619031911-cross-project-reference-pages-improper-authorization-wid-sec-2026-2265/</guid>
<pubDate>Thu, 09 Jul 2026 13:53:28 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/gitlab">GitLab up to 18.11.6/19.0.3/19.1.1</a>. Affected is an unknown function of the component <em>Cross-project Reference Pages</em>. This manipulation causes improper authorization.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-7492">CVE-2026-7492</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-11827 | GitLab up to 18.11.6/19.0.3/19.1.1 Authorization improper authorization (WID-SEC-2026-2265)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in GitLab up to 18.11.6/19.0.3/19.1.1. This vulnerability affects unknown code of the component Authorization. This manipulation causes improper authorization.

This vulnerability is tracked as CVE-2026-11827. The attack is possible to be ca...]]></description>
<link>https://tsecurity.de/de/3656906/sicherheitsluecken/cve-2026-11827-gitlab-up-to-1811619031911-authorization-improper-authorization-wid-sec-2026-2265/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656906/sicherheitsluecken/cve-2026-11827-gitlab-up-to-1811619031911-authorization-improper-authorization-wid-sec-2026-2265/</guid>
<pubDate>Thu, 09 Jul 2026 13:53:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/gitlab">GitLab up to 18.11.6/19.0.3/19.1.1</a>. This vulnerability affects unknown code of the component <em>Authorization</em>. This manipulation causes improper authorization.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-11827">CVE-2026-11827</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab Patches 8 Vulnerabilities Affecting CE and EE Installations]]></title>
<description><![CDATA[GitLab has released critical security updates to address eight vulnerabilities in its Community Edition (CE) and Enterprise Edition (EE). Administrators are urged to upgrade immediately to versions 19.1.2, 19.0.4, or 18.11.7. The patch rollout on July 8, 2026, includes fixes…
Read more →
The post...]]></description>
<link>https://tsecurity.de/de/3656747/it-security-nachrichten/gitlab-patches-8-vulnerabilities-affecting-ce-and-ee-installations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656747/it-security-nachrichten/gitlab-patches-8-vulnerabilities-affecting-ce-and-ee-installations/</guid>
<pubDate>Thu, 09 Jul 2026 12:50:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GitLab has released critical security updates to address eight vulnerabilities in its Community Edition (CE) and Enterprise Edition (EE). Administrators are urged to upgrade immediately to versions 19.1.2, 19.0.4, or 18.11.7. The patch rollout on July 8, 2026, includes fixes…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/gitlab-patches-8-vulnerabilities-affecting-ce-and-ee-installations/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/gitlab-patches-8-vulnerabilities-affecting-ce-and-ee-installations/">GitLab Patches 8 Vulnerabilities Affecting CE and EE Installations</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [hoch] GitLab: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um beliebigen Code auszuführen, Cross-Site-Scripting durchzuführen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.]]></description>
<link>https://tsecurity.de/de/3656737/it-security-nachrichten/neu-hoch-gitlab-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656737/it-security-nachrichten/neu-hoch-gitlab-mehrere-schwachstellen/</guid>
<pubDate>Thu, 09 Jul 2026 12:50:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um beliebigen Code auszuführen, Cross-Site-Scripting durchzuführen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab Patches Eight Security Vulnerabilities Across Community and Enterprise Editions]]></title>
<description><![CDATA[GitLab has released critical security updates addressing eight vulnerabilities across its Community Edition (CE) and Enterprise Edition (EE), urging users to upgrade immediately to mitigate potential risks. The latest patch versions 19.1.2, 19.0.4, and 18.11.7 were published on July 8, 2026, and ...]]></description>
<link>https://tsecurity.de/de/3656701/it-security-nachrichten/gitlab-patches-eight-security-vulnerabilities-across-community-and-enterprise-editions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656701/it-security-nachrichten/gitlab-patches-eight-security-vulnerabilities-across-community-and-enterprise-editions/</guid>
<pubDate>Thu, 09 Jul 2026 12:37:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GitLab has released critical security updates addressing eight vulnerabilities across its Community Edition (CE) and Enterprise Edition (EE), urging users to upgrade immediately to mitigate potential risks. The latest patch versions 19.1.2, 19.0.4, and 18.11.7 were published on July 8, 2026, and include fixes for high-, medium-, and low-severity issues affecting multiple components of the […]</p>
<p>The post <a href="https://cybersecuritynews.com/gitlab-patches-security-vulnerabilities/">GitLab Patches Eight Security Vulnerabilities Across Community and Enterprise Editions</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab Patches 8 Vulnerabilities Affecting CE and EE Installations]]></title>
<description><![CDATA[GitLab has released critical security updates to address eight vulnerabilities in its Community Edition (CE) and Enterprise Edition (EE). Administrators are urged to upgrade immediately to versions 19.1.2, 19.0.4, or 18.11.7. The patch rollout on July 8, 2026, includes fixes for high-, medium-, a...]]></description>
<link>https://tsecurity.de/de/3656557/it-security-nachrichten/gitlab-patches-8-vulnerabilities-affecting-ce-and-ee-installations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656557/it-security-nachrichten/gitlab-patches-8-vulnerabilities-affecting-ce-and-ee-installations/</guid>
<pubDate>Thu, 09 Jul 2026 11:52:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GitLab has released critical security updates to address eight vulnerabilities in its Community Edition (CE) and Enterprise Edition (EE). Administrators are urged to upgrade immediately to versions 19.1.2, 19.0.4, or 18.11.7. The patch rollout on July 8, 2026, includes fixes for high-, medium-, and low-severity flaws affecting core functionalities such as wiki rendering, repository mirroring, […]</p>
<p>The post <a href="https://gbhackers.com/gitlab-patches-8-vulnerabilities-affecting-ce-and-ee-installations/">GitLab Patches 8 Vulnerabilities Affecting CE and EE Installations</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3060 | GitLab Community Edition/Enterprise Edition Error Tracking injection (Issue 36542 / EUVD-2022-42492)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in GitLab Community Edition and Enterprise Edition. Impacted is an unknown function of the component Error Tracking Handler. Performing a manipulation results in injection.

This vulnerability is identified as CVE-2022-3060. The attack can be ...]]></description>
<link>https://tsecurity.de/de/3656160/sicherheitsluecken/cve-2022-3060-gitlab-community-editionenterprise-edition-error-tracking-injection-issue-36542-euvd-2022-42492/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656160/sicherheitsluecken/cve-2022-3060-gitlab-community-editionenterprise-edition-error-tracking-injection-issue-36542-euvd-2022-42492/</guid>
<pubDate>Thu, 09 Jul 2026 08:38:06 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition</a>. Impacted is an unknown function of the component <em>Error Tracking Handler</em>. Performing a manipulation results in injection.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2022-3060">CVE-2022-3060</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3067 | GitLab Community Edition/Enterprise Edition Import information disclosure (Issue 37216 / EUVD-2022-42498)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in GitLab Community Edition and Enterprise Edition. Affected by this vulnerability is an unknown functionality of the component Import Handler. This manipulation causes information disclosure.

The identification of this vulnerability is CV...]]></description>
<link>https://tsecurity.de/de/3656158/sicherheitsluecken/cve-2022-3067-gitlab-community-editionenterprise-edition-import-information-disclosure-issue-37216-euvd-2022-42498/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656158/sicherheitsluecken/cve-2022-3067-gitlab-community-editionenterprise-edition-import-information-disclosure-issue-37216-euvd-2022-42498/</guid>
<pubDate>Thu, 09 Jul 2026 08:38:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition</a>. Affected by this vulnerability is an unknown functionality of the component <em>Import Handler</em>. This manipulation causes information disclosure.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2022-3067">CVE-2022-3067</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3066 | GitLab Issue access control (Issue 37214 / EUVD-2022-42497)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in GitLab. The affected element is an unknown function of the component Issue Handler. Executing a manipulation can lead to improper access controls.

This vulnerability is tracked as CVE-2022-3066. The attack can be launched remotely. No exploit e...]]></description>
<link>https://tsecurity.de/de/3656157/sicherheitsluecken/cve-2022-3066-gitlab-issue-access-control-issue-37214-euvd-2022-42497/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656157/sicherheitsluecken/cve-2022-3066-gitlab-issue-access-control-issue-37214-euvd-2022-42497/</guid>
<pubDate>Thu, 09 Jul 2026 08:38:03 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/gitlab">GitLab</a>. The affected element is an unknown function of the component <em>Issue Handler</em>. Executing a manipulation can lead to improper access controls.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2022-3066">CVE-2022-3066</a>. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab Patch Release Fixes Affecting CE and EE Installations]]></title>
<description><![CDATA[GitLab released versions 19.1.2, 19.0.4, and 18.11.7 on July 8, 2026, patching eight vulnerabilities ranging from high to low severity across Community Edition (CE) and Enterprise Edition (EE). The company strongly urges all self-managed installations to upgrade immediately, while GitLab.com and ...]]></description>
<link>https://tsecurity.de/de/3656155/it-security-nachrichten/gitlab-patch-release-fixes-affecting-ce-and-ee-installations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656155/it-security-nachrichten/gitlab-patch-release-fixes-affecting-ce-and-ee-installations/</guid>
<pubDate>Thu, 09 Jul 2026 08:37:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GitLab released versions 19.1.2, 19.0.4, and 18.11.7 on July 8, 2026, patching eight vulnerabilities ranging from high to low severity across Community Edition (CE) and Enterprise Edition (EE). The company strongly urges all self-managed installations to upgrade immediately, while GitLab.com and GitLab Dedicated customers require no action, as the fixes are already applied. The most […]</p>
<p>The post <a href="https://cyberpress.org/gitlab-patch-release/">GitLab Patch Release Fixes Affecting CE and EE Installations</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3031 | GitLab Community Edition/Enterprise Edition excessive authentication (Issue 34039 / EUVD-2022-42464)]]></title>
<description><![CDATA[A vulnerability was found in GitLab Community Edition and Enterprise Edition and classified as problematic. The impacted element is an unknown function. The manipulation results in improper restriction of excessive authentication attempts.

This vulnerability is reported as CVE-2022-3031. The att...]]></description>
<link>https://tsecurity.de/de/3656004/sicherheitsluecken/cve-2022-3031-gitlab-community-editionenterprise-edition-excessive-authentication-issue-34039-euvd-2022-42464/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656004/sicherheitsluecken/cve-2022-3031-gitlab-community-editionenterprise-edition-excessive-authentication-issue-34039-euvd-2022-42464/</guid>
<pubDate>Thu, 09 Jul 2026 07:08:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. The impacted element is an unknown function. The manipulation results in improper restriction of excessive authentication attempts.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2022-3031">CVE-2022-3031</a>. The attack can be launched remotely. No exploit exists.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3030 | GitLab Community Edition/Enterprise Edition Pipeline Status access control (Issue 37959 / EUVD-2022-42463)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in GitLab Community Edition and Enterprise Edition. This issue affects some unknown processing of the component Pipeline Status Handler. Such manipulation leads to improper access controls.

This vulnerability is referenced as CVE-2022-303...]]></description>
<link>https://tsecurity.de/de/3655061/sicherheitsluecken/cve-2022-3030-gitlab-community-editionenterprise-edition-pipeline-status-access-control-issue-37959-euvd-2022-42463/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655061/sicherheitsluecken/cve-2022-3030-gitlab-community-editionenterprise-edition-pipeline-status-access-control-issue-37959-euvd-2022-42463/</guid>
<pubDate>Wed, 08 Jul 2026 19:38:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition</a>. This issue affects some unknown processing of the component <em>Pipeline Status Handler</em>. Such manipulation leads to improper access controls.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2022-3030">CVE-2022-3030</a>. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[2026-07-08, Version 26.5.0 (Current), @richardlau]]></title>
<description><![CDATA[Notable Changes
New release key
Welcome to our newest releaser, Stewart X Addison. Future Node.js releases may be signed with his release key, 655F3B5C1FB3FA8D1A0CA6BDE4A7D232B936D2FD.
Other notable changes

[55f48446c7] - (SEMVER-MINOR) buffer: implement blob.textStream() (Matthew Aitken) #64036...]]></description>
<link>https://tsecurity.de/de/3654192/downloads/2026-07-08-version-2650-current-richardlau/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654192/downloads/2026-07-08-version-2650-current-richardlau/</guid>
<pubDate>Wed, 08 Jul 2026 14:01:39 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Notable Changes</h3>
<h4>New release key</h4>
<p>Welcome to our newest releaser, <a href="https://github.com/sxa">Stewart X Addison</a>. Future Node.js releases may be signed with his <a href="https://github.com/nodejs/node/blob/main/README.md#release-keys">release key</a>, <code>655F3B5C1FB3FA8D1A0CA6BDE4A7D232B936D2FD</code>.</p>
<h4>Other notable changes</h4>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/55f48446c7"><code>55f48446c7</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>buffer</strong>: implement blob.textStream() (Matthew Aitken) <a href="https://github.com/nodejs/node/pull/64036" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64036/hovercard">#64036</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b373202efc"><code>b373202efc</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>esm</strong>: add <code>--experimental-import-text</code> flag (Efe) <a href="https://github.com/nodejs/node/pull/62300" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62300/hovercard">#62300</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/39e0c14455"><code>39e0c14455</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>perf_hooks</strong>: sample delay per event loop iteration (Pablo Erhard) <a href="https://github.com/nodejs/node/pull/62935" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62935/hovercard">#62935</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/999a83c937"><code>999a83c937</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>stream</strong>: expose ReadableStreamTee (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64195" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64195/hovercard">#64195</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4e0236dc3d"><code>4e0236dc3d</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>tls</strong>: report negotiated TLS groups (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64119" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64119/hovercard">#64119</a></li>
</ul>
<h3>Commits</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/87648c0a6c"><code>87648c0a6c</code></a>] - <strong>benchmark</strong>: trim down the argon2 sets (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64218" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64218/hovercard">#64218</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a483bfd3f0"><code>a483bfd3f0</code></a>] - <strong>buffer</strong>: remove unreachable overflow check in atob (haramjeong) <a href="https://github.com/nodejs/node/pull/60161" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60161/hovercard">#60161</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6d14279688"><code>6d14279688</code></a>] - <strong>buffer</strong>: add fast api for isUtf8 and isAscii (Gürgün Dayıoğlu) <a href="https://github.com/nodejs/node/pull/64169" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64169/hovercard">#64169</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/55f48446c7"><code>55f48446c7</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>buffer</strong>: implement blob.textStream() (Matthew Aitken) <a href="https://github.com/nodejs/node/pull/64036" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64036/hovercard">#64036</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a67d9a7a44"><code>a67d9a7a44</code></a>] - <strong>build</strong>: allow linting node.1 (Aviv Keller) <a href="https://github.com/nodejs/node/pull/64157" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64157/hovercard">#64157</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/06c1fbc25b"><code>06c1fbc25b</code></a>] - <strong>build</strong>: enable Maglev for riscv64 (Jamie Magee) <a href="https://github.com/nodejs/node/pull/62605" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62605/hovercard">#62605</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/518309c363"><code>518309c363</code></a>] - <strong>build</strong>: suppress clang errors building libffi on Windows (René) <a href="https://github.com/nodejs/node/pull/64222" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64222/hovercard">#64222</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6a80ab485c"><code>6a80ab485c</code></a>] - <strong>build</strong>: add manually-dispatched stress-test workflow (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/64118" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64118/hovercard">#64118</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f4e7bf1f1c"><code>f4e7bf1f1c</code></a>] - <strong>build</strong>: pin envinfo versions in github actions (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/64117" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64117/hovercard">#64117</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/66f6ac0d86"><code>66f6ac0d86</code></a>] - <strong>build</strong>: support setting an emulator from configure script (Ivan Trubach) <a href="https://github.com/nodejs/node/pull/53899" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/53899/hovercard">#53899</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7f26c54aa6"><code>7f26c54aa6</code></a>] - <strong>child_process</strong>: fix permission model propagation via NODE_OPTIONS (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63972" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63972/hovercard">#63972</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/32bb554f5b"><code>32bb554f5b</code></a>] - <strong>crypto</strong>: fix large DH generator validation (Tobias Nießen) <a href="https://github.com/nodejs/node/pull/64092" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64092/hovercard">#64092</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0908d76ef6"><code>0908d76ef6</code></a>] - <strong>crypto</strong>: reject small-order EdDSA points during verify (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64026" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64026/hovercard">#64026</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7f7e5863c2"><code>7f7e5863c2</code></a>] - <strong>deps</strong>: update undici to 8.7.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64282" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64282/hovercard">#64282</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/af91029801"><code>af91029801</code></a>] - <strong>deps</strong>: update nghttp3 to 1.17.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64182" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64182/hovercard">#64182</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2e500ba7b0"><code>2e500ba7b0</code></a>] - <strong>deps</strong>: update googletest to 8b53336594cc52213c6c2c7a0b29194fa896d039 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64181" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64181/hovercard">#64181</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/74e3aa24ba"><code>74e3aa24ba</code></a>] - <strong>deps</strong>: update sqlite to 3.53.3 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64180" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64180/hovercard">#64180</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c7e57f55a7"><code>c7e57f55a7</code></a>] - <strong>deps</strong>: c-ares: cherry-pick 8ba37af8e3fb (René) <a href="https://github.com/nodejs/node/pull/64110" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64110/hovercard">#64110</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/879fdc4daf"><code>879fdc4daf</code></a>] - <strong>deps</strong>: V8: backport da20a197a7f9 (Kevin Gibbons) <a href="https://github.com/nodejs/node/pull/64101" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64101/hovercard">#64101</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a640543a7c"><code>a640543a7c</code></a>] - <strong>deps</strong>: V8: cherry-pick 0cc9eb22c0b0 (Kevin Gibbons) <a href="https://github.com/nodejs/node/pull/64101" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64101/hovercard">#64101</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/feefd179e5"><code>feefd179e5</code></a>] - <strong>deps</strong>: V8: cherry-pick 1a391f98cc7a (Kevin Gibbons) <a href="https://github.com/nodejs/node/pull/64101" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64101/hovercard">#64101</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8ef643d4b0"><code>8ef643d4b0</code></a>] - <strong>deps</strong>: update googletest to 0b1e895ba4226c2fda5ee0178c9b5b1195a741aa (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64039" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64039/hovercard">#64039</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9e50bb0655"><code>9e50bb0655</code></a>] - <strong>dgram</strong>: skip dns.lookup() for literal IP addresses (Ruben Bridgewater) <a href="https://github.com/nodejs/node/pull/64133" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64133/hovercard">#64133</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dc052c095c"><code>dc052c095c</code></a>] - <strong>diagnostics_channel</strong>: return original thenable (Stephen Belanger) <a href="https://github.com/nodejs/node/pull/62407" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62407/hovercard">#62407</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a22a840293"><code>a22a840293</code></a>] - <strong>doc</strong>: clarify QUIC stream state wording (EduardF1) <a href="https://github.com/nodejs/node/pull/63660" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63660/hovercard">#63660</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8d4bec2d71"><code>8d4bec2d71</code></a>] - <strong>doc</strong>: update Http2SecureServer.on("timeout") default value (YuSheng Chen) <a href="https://github.com/nodejs/node/pull/64187" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64187/hovercard">#64187</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/da88f70afa"><code>da88f70afa</code></a>] - <strong>doc</strong>: add note on visibility of CI failures to new contributor guide (Stewart X Addison) <a href="https://github.com/nodejs/node/pull/64256" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64256/hovercard">#64256</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/20ce359ccb"><code>20ce359ccb</code></a>] - <strong>doc</strong>: clarify HTTP/1.1 response ordering (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64213" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64213/hovercard">#64213</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/05eae2835c"><code>05eae2835c</code></a>] - <strong>doc</strong>: recommend node-stress-single-test for flaky tests (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64223" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64223/hovercard">#64223</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3966eb67e7"><code>3966eb67e7</code></a>] - <strong>doc</strong>: fix typo in examples (Vas Sudanagunta) <a href="https://github.com/nodejs/node/pull/64184" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64184/hovercard">#64184</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/12a2b9daa3"><code>12a2b9daa3</code></a>] - <strong>doc</strong>: fix typo in node-config-schema.json (Hamid Reza Ghavami) <a href="https://github.com/nodejs/node/pull/64188" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64188/hovercard">#64188</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0854482671"><code>0854482671</code></a>] - <strong>doc</strong>: clarify defense-in-depth issues (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64215" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64215/hovercard">#64215</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ef4915fc3a"><code>ef4915fc3a</code></a>] - <strong>doc</strong>: fix Fast FFI argument count in ffi.md (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63960" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63960/hovercard">#63960</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bb2eed863c"><code>bb2eed863c</code></a>] - <strong>doc</strong>: add sxa GPG key (ed25519) (Stewart X Addison) <a href="https://github.com/nodejs/node/pull/64193" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64193/hovercard">#64193</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b7bf6e3a06"><code>b7bf6e3a06</code></a>] - <strong>doc</strong>: add guide and answers to FAQs for first-time contributors (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63685" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63685/hovercard">#63685</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ff537ba858"><code>ff537ba858</code></a>] - <strong>doc</strong>: update <code>Http2Server.close</code> &amp; <code>Http2SecureServer.close</code> (YuSheng Chen) <a href="https://github.com/nodejs/node/pull/63298" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63298/hovercard">#63298</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f3db304588"><code>f3db304588</code></a>] - <strong>doc</strong>: update list of people in <code>SECURITY.md</code> (Richard Lau) <a href="https://github.com/nodejs/node/pull/64152" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64152/hovercard">#64152</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2a126647b0"><code>2a126647b0</code></a>] - <strong>doc</strong>: clarify vfs is not a sandbox (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64143" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64143/hovercard">#64143</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/85fc79dd9b"><code>85fc79dd9b</code></a>] - <strong>doc</strong>: fix broken links and duplicate stability label (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64130" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64130/hovercard">#64130</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/189e830eb3"><code>189e830eb3</code></a>] - <strong>doc</strong>: add missing option to man page (Richard Lau) <a href="https://github.com/nodejs/node/pull/64156" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64156/hovercard">#64156</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7a16ccccd0"><code>7a16ccccd0</code></a>] - <strong>doc</strong>: announce upcoming end of tier 2 support for macOS x64 (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63931" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63931/hovercard">#63931</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d5f826045f"><code>d5f826045f</code></a>] - <strong>doc</strong>: update toolchain for official AIX releases (Richard Lau) <a href="https://github.com/nodejs/node/pull/64068" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64068/hovercard">#64068</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/60abc4400f"><code>60abc4400f</code></a>] - <strong>doc</strong>: fix callback example import in fs docs (Kamal Rawal) <a href="https://github.com/nodejs/node/pull/63912" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63912/hovercard">#63912</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e470c74a6c"><code>e470c74a6c</code></a>] - <strong>doc</strong>: fix keepAliveTimeout default in http.createServer options (Jahanzaib iqbal) <a href="https://github.com/nodejs/node/pull/63974" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63974/hovercard">#63974</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/851b460583"><code>851b460583</code></a>] - <strong>esm</strong>: improve ERR_REQUIRE_ASYNC_MODULE (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/64260" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64260/hovercard">#64260</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0cd443df39"><code>0cd443df39</code></a>] - <strong>esm</strong>: print required top-level await locations without evaluating (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/64154" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64154/hovercard">#64154</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b373202efc"><code>b373202efc</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>esm</strong>: add <code>--experimental-import-text</code> flag (Efe) <a href="https://github.com/nodejs/node/pull/62300" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62300/hovercard">#62300</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/eacfbd0ca5"><code>eacfbd0ca5</code></a>] - <strong>http</strong>: add CONNECT method handling for default Host header with proxy (Archkon) <a href="https://github.com/nodejs/node/pull/64114" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64114/hovercard">#64114</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/aeb539a383"><code>aeb539a383</code></a>] - <strong>http</strong>: fix drain event with cork/uncork (David Evans) <a href="https://github.com/nodejs/node/pull/64038" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64038/hovercard">#64038</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8e8874b216"><code>8e8874b216</code></a>] - <strong>http</strong>: document and validate options.path when it's in absolute-form (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/64108" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64108/hovercard">#64108</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/eb2e96bc28"><code>eb2e96bc28</code></a>] - <strong>inspector</strong>: fix crash when writing to closed inspector socket (ympark2011) <a href="https://github.com/nodejs/node/pull/64209" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64209/hovercard">#64209</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/243b0e4e57"><code>243b0e4e57</code></a>] - <strong>lib</strong>: reject string "0" in validatePort when allowZero is false (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/64174" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64174/hovercard">#64174</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/34a537c0ed"><code>34a537c0ed</code></a>] - <strong>lib</strong>: use <code>__proto__: null</code> when calling <code>ObjectDefineProperty</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64239" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64239/hovercard">#64239</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1f72393f19"><code>1f72393f19</code></a>] - <strong>lib</strong>: lazily initialize kEvents and kHandlers maps (Guilherme Araújo) <a href="https://github.com/nodejs/node/pull/63702" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63702/hovercard">#63702</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/92a3dc3191"><code>92a3dc3191</code></a>] - <strong>lib,permission</strong>: fix addon permission drop (Martin Wagner) <a href="https://github.com/nodejs/node/pull/64007" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64007/hovercard">#64007</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/87b8f2a296"><code>87b8f2a296</code></a>] - <strong>meta</strong>: fix linter warning in <code>stale.yml</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64281" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64281/hovercard">#64281</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/829c4a5913"><code>829c4a5913</code></a>] - <strong>meta</strong>: bump actions/cache from 5.0.5 to 6.1.0 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64248" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64248/hovercard">#64248</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0808dcd31c"><code>0808dcd31c</code></a>] - <strong>meta</strong>: bump github/codeql-action/autobuild from 4.36.1 to 4.36.2 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64247" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64247/hovercard">#64247</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/64aa17058f"><code>64aa17058f</code></a>] - <strong>meta</strong>: bump github/codeql-action/analyze from 4.36.1 to 4.36.2 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64246" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64246/hovercard">#64246</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/873d1e0412"><code>873d1e0412</code></a>] - <strong>meta</strong>: bump actions/checkout from 6.0.2 to 7.0.0 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64245" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64245/hovercard">#64245</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fe460ccf0b"><code>fe460ccf0b</code></a>] - <strong>meta</strong>: bump codecov/codecov-action from 6.0.1 to 7.0.0 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64244" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64244/hovercard">#64244</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/845c63ed50"><code>845c63ed50</code></a>] - <strong>meta</strong>: bump rtCamp/action-slack-notify from 2.3.3 to 2.4.0 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64243" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64243/hovercard">#64243</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2cad2d6de5"><code>2cad2d6de5</code></a>] - <strong>meta</strong>: bump github/codeql-action/init from 4.36.1 to 4.36.2 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64242" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64242/hovercard">#64242</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0ddde950c7"><code>0ddde950c7</code></a>] - <strong>meta</strong>: bump actions/setup-python from 6.2.0 to 6.3.0 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64241" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64241/hovercard">#64241</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c0a8760d2f"><code>c0a8760d2f</code></a>] - <strong>meta</strong>: bump github/codeql-action/upload-sarif from 4.36.1 to 4.36.2 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64240" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64240/hovercard">#64240</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f49704b9d0"><code>f49704b9d0</code></a>] - <strong>meta</strong>: clarify V8 flags are outside threat model (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64224" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64224/hovercard">#64224</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6b8dc58e6e"><code>6b8dc58e6e</code></a>] - <strong>meta</strong>: move one or more collaborators to emeritus (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64057" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64057/hovercard">#64057</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fe5260cca7"><code>fe5260cca7</code></a>] - <strong>meta</strong>: update status of past strategic initiatives (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63480" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63480/hovercard">#63480</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7b01040008"><code>7b01040008</code></a>] - <strong>meta</strong>: speed up stale bot (Aviv Keller) <a href="https://github.com/nodejs/node/pull/64075" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64075/hovercard">#64075</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/874c46c24f"><code>874c46c24f</code></a>] - <strong>meta</strong>: update sccache version in test-linux-quic (René) <a href="https://github.com/nodejs/node/pull/64043" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64043/hovercard">#64043</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/48c5c86363"><code>48c5c86363</code></a>] - <strong>module</strong>: enable import support for addons by default (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/64221" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64221/hovercard">#64221</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/39e0c14455"><code>39e0c14455</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>perf_hooks</strong>: sample delay per event loop iteration (Pablo Erhard) <a href="https://github.com/nodejs/node/pull/62935" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62935/hovercard">#62935</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f90f1bd032"><code>f90f1bd032</code></a>] - <strong>perf_hooks</strong>: add NODE_PERFORMANCE_GC_MINOR_MARK_SWEEP constant (Attila Szegedi) <a href="https://github.com/nodejs/node/pull/63877" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63877/hovercard">#63877</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bdf32628c7"><code>bdf32628c7</code></a>] - <strong>process</strong>: fix finalization cleanup ref tracking (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64087" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64087/hovercard">#64087</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9a65b7fff4"><code>9a65b7fff4</code></a>] - <strong>quic</strong>: drop version negotiation packets with oversized CIDs (Mohamed Sayed) <a href="https://github.com/nodejs/node/pull/64228" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64228/hovercard">#64228</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2699fe4706"><code>2699fe4706</code></a>] - <strong>quic</strong>: fixes undefined handle in QuicStream kInspect (Marten Richter) <a href="https://github.com/nodejs/node/pull/64170" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64170/hovercard">#64170</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/00dea28bb3"><code>00dea28bb3</code></a>] - <strong>repl</strong>: lazy-load acorn and defer vm context creation (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63879" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63879/hovercard">#63879</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ce659a1cf9"><code>ce659a1cf9</code></a>] - <strong>src</strong>: fix escaping of single quotes in task runner (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64089" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64089/hovercard">#64089</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dbb3126e5c"><code>dbb3126e5c</code></a>] - <strong>src</strong>: abstract tracing agent for both legacy and perfetto (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/64053" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64053/hovercard">#64053</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/12edf1d68d"><code>12edf1d68d</code></a>] - <strong>src</strong>: avoid redundant call to <code>std::get_if&lt;&gt;()</code> (Tobias Nießen) <a href="https://github.com/nodejs/node/pull/64094" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64094/hovercard">#64094</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/eda91b6d01"><code>eda91b6d01</code></a>] - <strong>src</strong>: avoid copying source string in TextEncoder.encode (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/63897" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63897/hovercard">#63897</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/efbbb9a03c"><code>efbbb9a03c</code></a>] - <strong>stream</strong>: preserve half-open duplexes in async iteration (Efe) <a href="https://github.com/nodejs/node/pull/64275" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64275/hovercard">#64275</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/999a83c937"><code>999a83c937</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>stream</strong>: expose ReadableStreamTee (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64195" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64195/hovercard">#64195</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ab5ed72903"><code>ab5ed72903</code></a>] - <strong>stream</strong>: reject iter consumers on abort (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64066" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64066/hovercard">#64066</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d3fa77c5e2"><code>d3fa77c5e2</code></a>] - <strong>stream</strong>: fix merge abort for pending sources (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64013" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64013/hovercard">#64013</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/38b99140ed"><code>38b99140ed</code></a>] - <strong>stream</strong>: refactor unnecessary optional chaining away (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64253" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64253/hovercard">#64253</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c81f894ebe"><code>c81f894ebe</code></a>] - <strong>stream</strong>: cut per-chunk overhead in WHATWG streams (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64252" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64252/hovercard">#64252</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f162234f24"><code>f162234f24</code></a>] - <strong>stream</strong>: normalize Broadcast.from() byte inputs (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64082" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64082/hovercard">#64082</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1182ad8f3b"><code>1182ad8f3b</code></a>] - <strong>stream</strong>: proxy first own method in Readable.wrap() (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/64048" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64048/hovercard">#64048</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d0b830b382"><code>d0b830b382</code></a>] - <strong>stream</strong>: observe abort while awaiting pipeTo source (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64015" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64015/hovercard">#64015</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f7adcd8359"><code>f7adcd8359</code></a>] - <strong>stream</strong>: respect iter consumer abort signals (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63997" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63997/hovercard">#63997</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b09e624c6f"><code>b09e624c6f</code></a>] - <strong>test</strong>: make blob desiredSize assertion robust (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64106" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64106/hovercard">#64106</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d0d8f0c774"><code>d0d8f0c774</code></a>] - <strong>test</strong>: update WPT for urlpattern to 11a459a2b1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64037" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64037/hovercard">#64037</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ff9122c20c"><code>ff9122c20c</code></a>] - <strong>test</strong>: improve lcov reporter snapshot diagnostics (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64049" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64049/hovercard">#64049</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/570952d4f3"><code>570952d4f3</code></a>] - <strong>test</strong>: keep finalization close fixture ref alive (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64085" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64085/hovercard">#64085</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1b4f213380"><code>1b4f213380</code></a>] - <strong>test</strong>: fix typo from overriden to overridden (parkhojeong) <a href="https://github.com/nodejs/node/pull/63403" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63403/hovercard">#63403</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4c91090b8b"><code>4c91090b8b</code></a>] - <strong>test</strong>: fix typo from funciton to function (parkhojeong) <a href="https://github.com/nodejs/node/pull/63403" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63403/hovercard">#63403</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bf080c7917"><code>bf080c7917</code></a>] - <strong>test</strong>: mark hr-time WPT flaky on macos15-x64 (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64054" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64054/hovercard">#64054</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/24e32098c5"><code>24e32098c5</code></a>] - <strong>test</strong>: use one-off agent in http consumed timeout test (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64052" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64052/hovercard">#64052</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3229886de2"><code>3229886de2</code></a>] - <strong>test</strong>: fix flaky test-runner coverage threshold test (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64051" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64051/hovercard">#64051</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/83b91ea6ec"><code>83b91ea6ec</code></a>] - <strong>test_runner</strong>: filter execArgv fallback for child tests (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64056" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64056/hovercard">#64056</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/269b609a3d"><code>269b609a3d</code></a>] - <strong>test_runner</strong>: improve coverage failure diagnostics (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64050" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64050/hovercard">#64050</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0342744c34"><code>0342744c34</code></a>] - <strong>test_runner</strong>: add timestamp to JUnit reporter testsuites (sangwook) <a href="https://github.com/nodejs/node/pull/64029" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64029/hovercard">#64029</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/086741d121"><code>086741d121</code></a>] - <strong>timers</strong>: reuse Timeout objects in setStreamTimeout (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64254" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64254/hovercard">#64254</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4e0236dc3d"><code>4e0236dc3d</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>tls</strong>: report negotiated TLS groups (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64119" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64119/hovercard">#64119</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3bdd7e20be"><code>3bdd7e20be</code></a>] - <strong>tls</strong>: handle large RSA exponents in X.509 cert (Tobias Nießen) <a href="https://github.com/nodejs/node/pull/64093" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64093/hovercard">#64093</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c96c838977"><code>c96c838977</code></a>] - <strong>tools</strong>: update RUSTC_VERSION for remaining GHA workflows (René) <a href="https://github.com/nodejs/node/pull/64325" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64325/hovercard">#64325</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ee873b7aaf"><code>ee873b7aaf</code></a>] - <strong>tools</strong>: bump <code>temporal_rs</code> version (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63281" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63281/hovercard">#63281</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ea3b870155"><code>ea3b870155</code></a>] - <strong>tools</strong>: remove <code>envinfo</code> from our workflows (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64259" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64259/hovercard">#64259</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d940f02e8b"><code>d940f02e8b</code></a>] - <strong>tools</strong>: bump the eslint group in /tools/eslint with 8 updates (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64249" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64249/hovercard">#64249</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fe0ea2bb5d"><code>fe0ea2bb5d</code></a>] - <strong>tools</strong>: bump @node-core/doc-kit (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64010" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64010/hovercard">#64010</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4dceefde1e"><code>4dceefde1e</code></a>] - <strong>tools</strong>: bump undici from 6.24.1 to 6.27.0 in /tools/doc (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64031" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64031/hovercard">#64031</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6e187db7d7"><code>6e187db7d7</code></a>] - <strong>tools</strong>: update c-ares updater script (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64194" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64194/hovercard">#64194</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/657a35f5a2"><code>657a35f5a2</code></a>] - <strong>tools</strong>: validate version number in release proposal commit message lint (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64070" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64070/hovercard">#64070</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/17228a861c"><code>17228a861c</code></a>] - <strong>tools</strong>: add GHA benchmark runner (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/60293" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60293/hovercard">#60293</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6d11a71d91"><code>6d11a71d91</code></a>] - <strong>tools</strong>: update <code>build-shared/action.yml</code> to a reusable workflow (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64059" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64059/hovercard">#64059</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7a17c50b7f"><code>7a17c50b7f</code></a>] - <strong>tools</strong>: update libffi updater script (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64046" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64046/hovercard">#64046</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/28047a3e71"><code>28047a3e71</code></a>] - <strong>tools</strong>: exclude <code>libffi</code> changes from <code>test-shared</code> GHA CI (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64047" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64047/hovercard">#64047</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/58d9685acc"><code>58d9685acc</code></a>] - <strong>typings</strong>: add typing for crypto (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64122" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64122/hovercard">#64122</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7a9dcad44d"><code>7a9dcad44d</code></a>] - <strong>util</strong>: fix OOM in inspect color stack formatting (Ijtihed Kilani) <a href="https://github.com/nodejs/node/pull/64022" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64022/hovercard">#64022</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d5f01bbbde"><code>d5f01bbbde</code></a>] - <strong>vfs</strong>: reject rename into descendant directory (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64285" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64285/hovercard">#64285</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0b6af91081"><code>0b6af91081</code></a>] - <strong>vfs</strong>: handle current-position sentinel in memory files (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64163" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64163/hovercard">#64163</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/322230d641"><code>322230d641</code></a>] - <strong>vfs</strong>: support writeFileSync with virtual fds (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64165" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64165/hovercard">#64165</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9395d209c7"><code>9395d209c7</code></a>] - <strong>vfs</strong>: avoid recursive readdir symlink cycles (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64168" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64168/hovercard">#64168</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bbdd7643b6"><code>bbdd7643b6</code></a>] - <strong>vfs</strong>: read RealFSProvider files from open fd (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/64104" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64104/hovercard">#64104</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/92859b8097"><code>92859b8097</code></a>] - <strong>vm</strong>: fix copying PropertyDescriptor (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/64073" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64073/hovercard">#64073</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9046035475"><code>9046035475</code></a>] - <strong>zlib</strong>: validate flush king for all streams (Ic3b3rg) <a href="https://github.com/nodejs/node/pull/63746" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63746/hovercard">#63746</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/98be4304a3"><code>98be4304a3</code></a>] - <strong>zlib</strong>: validate flush kind for brotli streams (Ic3b3rg) <a href="https://github.com/nodejs/node/pull/63746" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63746/hovercard">#63746</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/90007a59a9"><code>90007a59a9</code></a>] - <strong>zlib</strong>: expose rejectGarbageAfterEnd option (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64023" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64023/hovercard">#64023</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5933516066"><code>5933516066</code></a>] - <strong>zlib</strong>: reject trailing gzip members in web streams (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64023" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64023/hovercard">#64023</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3018 | GitLab Community Edition/Enterprise Edition up to 15.2.4/15.3.3/15.4.0 DataDog information disclosure (Issue 36093 / EUVD-2022-42453)]]></title>
<description><![CDATA[A vulnerability has been found in GitLab Community Edition and Enterprise Edition up to 15.2.4/15.3.3/15.4.0 and classified as problematic. The impacted element is an unknown function of the component DataDog Handler. Performing a manipulation results in information disclosure.

This vulnerabilit...]]></description>
<link>https://tsecurity.de/de/3654149/sicherheitsluecken/cve-2022-3018-gitlab-community-editionenterprise-edition-up-to-152415331540-datadog-information-disclosure-issue-36093-euvd-2022-42453/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654149/sicherheitsluecken/cve-2022-3018-gitlab-community-editionenterprise-edition-up-to-152415331540-datadog-information-disclosure-issue-36093-euvd-2022-42453/</guid>
<pubDate>Wed, 08 Jul 2026 13:38:24 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 15.2.4/15.3.3/15.4.0</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. The impacted element is an unknown function of the component <em>DataDog Handler</em>. Performing a manipulation results in information disclosure.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2022-3018">CVE-2022-3018</a>. It is possible to initiate the attack remotely. There is no exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-07-04 - Kernels, Firefox, Thunderbird, KDE Gear, COSMIC, QEmu]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected Mid or End of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may f...]]></description>
<link>https://tsecurity.de/de/3644989/unix-server/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644989/unix-server/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/</guid>
<pubDate>Sat, 04 Jul 2026 09:46:33 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected Mid or End of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may found thus far.</p>
<h3><a name="p-864416-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-864416-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-864416-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-864416-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/188735/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/188735/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/188735/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 7.0.14, the 7.0 series is now EOL (End Of Life). Please install 7.1, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/188735/1">(click for more details)</a>
<h2><a name="p-864416-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-864416-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>Kernels</strong> got updated
<ul>
<li><strong>linux70</strong> series is now marked EOL</li>
<li><strong>linux-firmware</strong> <a href="https://gitlab.com/kernel-firmware/linux-firmware/-/compare/20260519...20260622?from_project_id=48890189">20260622</a></li>
<li>slight <strong>toolchain</strong> update</li>
<li>we dropped <strong>NVIDIA</strong> driver series 570xx and 575xx</li>
</ul>
</li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/en-US/firefox/152.0.4/releasenotes/">152.0.4</a></li>
<li><strong>Thunderbird</strong> <a href="https://www.thunderbird.net/en-US/thunderbird/152.0/releasenotes">152.0</a></li>
<li><strong>Virtualbox</strong> <a href="https://www.virtualbox.org/wiki/Changelog-7.2">7.2.12</a></li>
<li><strong>Godot</strong> <a href="https://godotengine.org/releases/4.7/">4.7</a></li>
<li><strong>Pipewire</strong> <a href="https://gitlab.freedesktop.org/pipewire/pipewire/-/releases/1.6.7">1.6.7</a></li>
<li><strong>Systemd</strong> <a href="https://github.com/systemd/systemd/compare/v260.2...v261.1">261.1</a></li>
<li><strong>COSMIC</strong> Epoch <a href="https://github.com/pop-os/cosmic-epoch/releases/tag/epoch-1.2.0">1.2.0</a></li>
<li><strong>KDE Gear</strong> <a href="https://kde.org/announcements/gear/26.04.3/">26.04.3</a></li>
<li><strong>QEmu</strong> <a href="https://www.qemu.org/2026/04/22/qemu-11-0-0/">11.0.2</a></li>
</ul>
<h2><a name="p-864416-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-864416-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/188735/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/188735/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.176</li>
<li>linux66 6.6.143</li>
<li>linux612 6.12.94</li>
<li>linux618 6.18.37</li>
<li>linux70 7.0.14</li>
<li>linux71 7.1.2</li>
<li>linux72 7.2.0-rc1</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (7/4/26 08:10 CEST)</p>
<ul>
<li>testing core x86_64:  89 new and 88 removed package(s)</li>
<li>testing multilib x86_64:  50 new and 50 removed package(s)</li>
<li>testing extra x86_64:  3447 new and 3452 removed package(s)</li>
</ul>
<p><strong>Overlay Changes</strong></p>
<ul>
<li>testing core x86_64:  25 new and 26 removed package(s)</li>
<li>testing multilib x86_64:  6 new and 10 removed package(s)</li>
<li>testing extra x86_64:  260 new and 403 removed package(s)</li>
</ul>
<p>A list of all package changes can be found <a href="https://termbin.com/0now">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/188735/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>3 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-07-04-kernels-firefox-thunderbird-kde-gear-cosmic-qemu/188735">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Valve Open-Sources Steam Machine's E-Ink Display]]></title>
<description><![CDATA[Valve has open-sourced the design for a customizable e-ink front panel for the Steam Machine, dubbed the "Inkterface." "All of it is available on their GitLab under the MIT license, which goes over everything you need to make your own and stick it on the front of your fancy new Steam Machine," re...]]></description>
<link>https://tsecurity.de/de/3644352/it-security-nachrichten/valve-open-sources-steam-machines-e-ink-display/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644352/it-security-nachrichten/valve-open-sources-steam-machines-e-ink-display/</guid>
<pubDate>Fri, 03 Jul 2026 22:21:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Valve has open-sourced the design for a customizable e-ink front panel for the Steam Machine, dubbed the "Inkterface." "All of it is available on their GitLab under the MIT license, which goes over everything you need to make your own and stick it on the front of your fancy new Steam Machine," reports GamingOnLinux. From the report: 

They're now calling it the "Inkterface" and there's a good few things you'll need to make it including:
1 x Adafruit ESP32 Feather with 2MB PSRAM.
1 x Adafruit eInk Breakout Friend.
1 x Adafruit 5.83" Monochrome eInk Panel.
13 x M2.5 x 5mm Pan Head Machine Screws.
4 x 1/4" x 1/4" x 3/16" Stepped Magnet SB443-OUT.
 
Valve even provided a video on the GitLab showing it being put together [...].<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Valve+Open-Sources+Steam+Machine's+E-Ink+Display%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F03%2F1633249%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F03%2F1633249%2Fvalve-open-sources-steam-machines-e-ink-display%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/07/03/1633249/valve-open-sources-steam-machines-e-ink-display?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-Code wächst schneller als Governance]]></title>
<description><![CDATA[KI-Tools beschleunigen die Softwareentwicklung deutlich, doch Kontrolle und Nachvollziehbarkeit halten nicht Schritt. Eine globale GitLab-Studie zeigt strukturelle Defizite bei Governance, Tool-Integration und Traceability. Unternehmen verlieren zunehmend den Überblick über Herkunft, Zweck und Ve...]]></description>
<link>https://tsecurity.de/de/3643705/it-security-nachrichten/ki-code-waechst-schneller-als-governance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643705/it-security-nachrichten/ki-code-waechst-schneller-als-governance/</guid>
<pubDate>Fri, 03 Jul 2026 15:36:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[KI-Tools beschleunigen die Softwareentwicklung deutlich, doch Kontrolle und Nachvollziehbarkeit halten nicht Schritt. Eine globale GitLab-Studie zeigt strukturelle Defizite bei Governance, Tool-Integration und Traceability. Unternehmen verlieren zunehmend den Überblick über Herkunft, Zweck und Verantwortung von KI-generiertem Code.]]></content:encoded>
</item>
<item>
<title><![CDATA[Preventing agent-generated infrastructure bloat through spec-driven governance]]></title>
<description><![CDATA[Autonomous AI engineer agents can deliver software at a scale in multiples of what a human engineering team can do, and that productivity is genuinely valuable. But without proper guardrails at the specification level, these agents can industrialise inefficient infrastructure patterns at the same...]]></description>
<link>https://tsecurity.de/de/3637960/ai-nachrichten/preventing-agent-generated-infrastructure-bloat-through-spec-driven-governance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637960/ai-nachrichten/preventing-agent-generated-infrastructure-bloat-through-spec-driven-governance/</guid>
<pubDate>Wed, 01 Jul 2026 11:19:17 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Autonomous AI engineer agents can deliver software at a scale in multiples of what a human engineering team can do, and that productivity is genuinely valuable. But without proper guardrails at the specification level, these agents can industrialise inefficient infrastructure patterns at the same pace, consistently and at a scale that makes post-deploy remediation impractical. When an agent provisions a three-node GKE cluster using n2-standard-16 machines for a workload a single e2-medium node could handle, or generates a Kubernetes pod spec with 4-CPU and 8GB memory requests for a service that peaks at 200 milli-cores and 256MB, or writes a Dockerfile that pulls a full Ubuntu base image where a distro-less container would serve, infrastructure runs that decision continuously, for the lifetime of the service. The agent will reproduce these patterns across every environment it touches, because the specification never instructed it otherwise. When agentic pipelines are generating infrastructure at scale, operational remediation after the fact becomes impractical.</p>



<p>The scale of what is now being generated autonomously is significant. <a href="https://www.infoworld.com/article/3999607/how-to-succeed-or-fail-with-ai-driven-development.html">InfoWorld’s reporting on AI-driven development</a> shows the pace of AI-generated output is accelerating sharply, and <a href="https://www.infoworld.com/article/3993479/what-we-know-now-about-generative-ai-for-software-development.html">projections suggest more than a quarter of new production code and configuration is already AI-generated</a>. What those projections do not yet capture is the shift from AI-assisted to fully agentic pipelines, where agents generate Terraform, Kubernetes manifests, Helm charts and Docker configurations end-to-end, commit them and trigger deployment, with no human in the loop or little oversight that concentrates on functional capabilities. When that pipeline runs without sustainability constraints, it systematically reproduces that infrastructure inefficiency across every environment it touches.</p>



<p>Green software has traditionally been an operational problem: Right-size the containers retrospectively, tune the cluster after the fact, schedule workloads in low-carbon windows. That approach was already struggling before agentic pipelines arrived. <a href="https://www.gartner.com/en/newsroom/press-releases/2024-05-16-gartner-identifies-the-top-five-strategic-technology-trends-in-software-engineering-for-2024">Gartner projects</a> that by 2027, just 30% of large enterprises will have software sustainability embedded in their non-functional requirements. That statistic carries a consequence most engineering leaders have not yet confronted: If 70% of enterprise code has been written without sustainability intent, then the training data autonomous AI engineer agents learned from is dominated by potentially unsustainable patterns. An agent defaults to the majority pattern in its training distribution, which is the inefficient one. This makes the specification constraint not just a governance need, but a corrective instruction that the agent’s training data never provided.</p>



<h2 class="wp-block-heading">Sustainable specification as a reliable intervention point</h2>



<p>In a fully agentic development pipeline, the specification is not a document an engineer reads before writing code. It is the instruction set the agent executes. It determines which machine types get provisioned, which container base images get selected, how pod resource requests are sized, how storage is allocated and how networking is configured. Every infrastructure decision the agent makes downstream is a function of what the specification permitted or left undefined.</p>



<p>If the specification contains no sustainability constraints, the agent will make infrastructure decisions based on defaults, conventions and training data patterns, none of which are optimised for energy efficiency. An agent prompted to scaffold a GKE-based microservice will, by default, select machine types that ensure availability headroom rather than efficiency. It will size pod resource requests conservatively to avoid out-of-memory conditions from potentially inefficient application code, but not to minimise node utilization. It will pull familiar base images rather than minimal ones. These are not failures of the agent. They are the predictable output of an instruction set that never asked for sustainability.</p>



<p>The fix is to make sustainability a first-class constraint in the specification itself. A constraint such as GS-INFRA-001 (select the smallest GKE machine type that satisfies the workload’s measured resource ceiling, defaulting to e2-medium or smaller) or GS-K8S-001 (set pod CPU requests to measured p95 consumption with a 20% ceiling, not to arbitrary safe values) is a structured policy the agent reads before it generates a single line of Terraform or YAML. The agent does not override it. It executes it. That is the mechanism that makes sustainability structural and automated rather than aspirational.</p>



<h2 class="wp-block-heading">The infrastructure patterns that matter most</h2>



<p>Three infrastructure domains represent the highest-impact targets for sustainability constraints, precisely because autonomous AI engineer agents generate them prolifically and the consequences compound continuously at runtime rather than only when code executes.</p>



<p>The first is IaC and cloud resource provisioning. An agent generating a Terraform configuration for a GKE cluster defaults to instance families and node counts calibrated for resilience, not efficiency. A three-node cluster of n2-standard-16 machines (64 vCPUs, 192GB RAM) provisioned for a service that runs comfortably on a single e2-medium (2 vCPUs, 4GB RAM) represents a 32x over-provisioning of compute. That gap does not show up in staging. It runs in production, is billed continuously, emitting continuously. A sustainability constraint in the Terraform specification that enforces machine type selection against a measured workload profile eliminates this class of error before the agent writes its first resource block.</p>



<p>The second is the Kubernetes pod resource configuration. Pod resource requests are the input the Kubernetes scheduler uses to place workloads on nodes. When an autonomous AI engineer agent generates a pod spec with generous CPU and memory requests, the scheduler reserves that capacity whether the pod uses it or not. Nodes that could host eight efficiently-sized pods instead host two or three over-specified ones, leaving the remaining capacity stranded and the underlying VM running at low utilization. A pod spec with a 4-CPU, 8GB memory request for a service that observably consumes 200 millicores and 256MB at peak is not cautious engineering. It is a scheduler instruction to waste three and a half CPUs and 7.75GB of memory per pod, per node, per hour, across every replica in every environment. A sustainability constraint specifying that pod resource requests must be derived from measured p95 consumption data, not from defaults or intuition, changes this systematically.</p>



<p>The third is the container base image selection. When an agent generates a Dockerfile, it gravitates toward familiar, full-featured base images: Ubuntu, Debian, Python, Node.js. These images are large, carry a significant attack surface and consume more storage, memory and transfer bandwidth than their minimal equivalents. A distroless or Alpine-based image for the same workload can be an order of magnitude smaller. At the scale at which an autonomous AI engineer agent operates, pulling, storing and running bloated base images across hundreds of services is a significant and entirely avoidable infrastructure cost. A constraint specifying distroless or minimal base images as the default, with justification required for exceptions, eliminates the pattern without slowing generation.</p>



<h2 class="wp-block-heading">4 pipeline stages where constraints are enforced</h2>



<p>Embedding constraints in the specification is the intervention. Enforcing them through the pipeline is what makes the intervention reliable. Four stages create the enforcement architecture.</p>



<p>The first stage is generation itself. When sustainability constraints are part of the specification the autonomous AI engineer agent operates from, those constraints shape every artifact the agent produces: Terraform resource blocks, Kubernetes manifests, Helm chart defaults, Dockerfile base image selections. The agent does not reason about sustainability independently. It executes the specification. A well-constrained specification produces sustainable infrastructure by construction, not by review.</p>



<p>The second stage is static analysis. Tools including Checkov, tfsec, KICS and Trivy analyze Terraform, Kubernetes YAML and Dockerfiles against configurable policy rules without modifying the agent or the pipeline architecture. A Checkov policy enforcing the GKE machine type constraint, or a tfsec rule flagging over-provisioned node pools, runs against every artifact the agent generates before it reaches a deployment gate. The violation surfaces as structured CI output the gate acts on. The agent’s output is checked the same way a human engineer’s output would be, consistently, at every commit.</p>



<p>The third stage is the quality gate. Sustainability violations fail the build. They do not generate warnings that an agent pipeline has no mechanism to act on. A gate that blocks deployment on policy violations is the enforcement layer that makes constraints binding rather than advisory. Because the gate operates on artifact output rather than on the agent itself, it is fully autonomous AI engineer agent-agnostic: It does not matter whether the Terraform was generated by Copilot, a custom LLM pipeline, an internal scaffolding agent or a human engineer. The gate evaluates the artifact against the policy. That is the only thing that matters.</p>



<p>The fourth stage is runtime telemetry feeding back into constraint refinement. Actual resource utilization, node efficiency metrics and carbon intensity data from production inform constraint updates at the specification level. A constraint calibrated on design-time estimates tightens over time as empirical data replaces assumptions. The governance model improves continuously rather than stagnating at its initial calibration.</p>



<h2 class="wp-block-heading">3 steps to start this week</h2>



<p>Most engineering organizations already have everything they need to begin. The static analysis toolchain is there: Checkov, tfsec, KICS, Trivy and OPA Conftest all support configurable sustainability policies against Terraform, Kubernetes YAML and Dockerfile artifacts without pipeline replacement. The CI/CD pipeline is there: GitHub Actions, GitLab CI, Jenkins, Tekton and Azure DevOps Pipelines all support blocking quality gates against policy tool outputs. The specification layer is there: Terraform modules, Helm chart value schemas, Kubernetes admission controllers and architectural decision records are already version-controlled in most mature engineering organizations. And critically, this approach is a fully autonomous AI engineer agent-agnostic. The governance layer does not inspect which agent or model generated the infrastructure artifact. It enforces the policy against the output. Whether the Terraform came from a custom agentic pipeline, a Copilot suggestion or a human engineer, the gate applies identically. The only things genuinely missing are the sustainability constraint definitions authored into the specification and the policy rules wired into the CI/CD pipeline to enforce them. Three steps close that gap.</p>



<ol class="wp-block-list">
<li><strong>Audit your IaC specifications for sustainability constraints.</strong> Open an active Terraform module or Helm chart and locate the machine type defaults, pod resource request defaults and base image defaults. For most organizations, these are set to safe, familiar values with no sustainability rationale. Define three constraints: A maximum machine type ceiling for each workload tier, a pod resource request ceiling derived from measured utilization, and a base image policy requiring distro-less or Alpine equivalents. Version control these constraints alongside the specifications they govern.</li>



<li><strong>Add one Checkov or tfsec policy to your CI pipeline.</strong> A policy flagging GKE node pools configured above the e2-standard-4 threshold without a documented justification is implementable in under an hour using Checkov’s custom check API. Wire it as a blocking gate, not a warning. This single addition creates immediate, agent-agnostic enforcement across every Terraform commit in your repository.</li>



<li><strong>Embed sustainability constraints before you scale your agentic pipelines.</strong> The highest-leverage moment is now, before autonomous AI engineer agents are generating infrastructure at full organizational scale. Every agentic pipeline that goes into production without sustainability constraints in its specification becomes a systematic source of over-provisioned, carbon-intensive infrastructure that compounds daily. Retrofitting governance after hundreds of agent-generated services are running is an order of magnitude harder than constraining generation at the specification source.</li>
</ol>



<h2 class="wp-block-heading">What lies ahead</h2>



<p>The sustainability challenge discussed here is not the energy consumed by the AI engineer agent itself, but the long-lived infrastructure decisions encoded into the artifacts it generates. Sustainable infrastructure engineering is no longer an operational discipline. It is an architectural necessity, and the specification layer is where that necessity must be addressed. When autonomous AI engineer agents are generating Terraform, Kubernetes manifests and Docker configurations at scale, the organizations that embed sustainability constraints into the specifications those agents execute will build efficient, cost-controlled, regulation-ready infrastructure by construction. Those that do not will build a remediation programme instead, which at scale will become impractical.</p>



<p>The urgency is not speculative. <a href="https://spectrum.ieee.org/green-software/particle-2">IEEE Spectrum reports</a> that Microsoft’s emissions have risen 23% since its 2020 baseline and Google’s have climbed 51% since 2019, with AI infrastructure as the primary driver. <a href="https://spectrum.ieee.org/firms-bet-climate-tech">Global data centres are on track to consume more electricity than Japan by 2030.</a> A significant fraction of that load is over-provisioned infrastructure that an autonomous AI engineer agent generated from a specification that never asked for efficiency. The constraint cost is low. The compounding cost of the alternative is not.</p>



<p>The governance imperative is converging from three directions simultaneously. Cloud cost: Over-provisioned AI-generated infrastructure compounds spend at a rate that makes early specification-layer control orders of magnitude cheaper than post-deployment rightsizing programmes. Technical debt: Every agentic sprint that ships infrastructure without sustainability constraints adds configuration debt that grows faster than any platform team can retrospectively correct. Regulatory pressure: Sustainability reporting requirements, already mandatory in the EU and accelerating in other jurisdictions, will reach infrastructure efficiency metrics. Engineering organizations that have operationalised sustainability governance at the specification layer will meet those requirements as a natural output of their existing pipeline. Those who have not will discover that compliance is a crisis programme when the deadline arrives. These are not abstract architectural concerns. The organizations that govern agentic generation upstream, at the specification, will compound efficiency gains with every agent run, not just sustainability but cost, too. Those who govern only in production will spend a lot of time remediating what they should have prevented before the first line of Terraform was written.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want </a><a href="https://www.infoworld.com/expert-contributor-network/">to</a><a href="https://www.cio.com/expert-contributor-network/"> join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Software Bill of Material umsetzen: Die besten SBOM-Tools]]></title>
<description><![CDATA[Nur wenn Sie wissen, was drinsteckt, können Sie sich sicher sein, dass alles mit rechten Dingen zugeht. Das gilt für Fast Food wie für Software.  Foto: Geka – shutterstock.com




Um Software abzusichern, muss man wissen, was in ihrem Code steckt. Aus diesem Grund ist eine Software Bill of Materi...]]></description>
<link>https://tsecurity.de/de/3637351/it-security-nachrichten/software-bill-of-material-umsetzen-die-besten-sbom-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637351/it-security-nachrichten/software-bill-of-material-umsetzen-die-besten-sbom-tools/</guid>
<pubDate>Wed, 01 Jul 2026 06:08:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img decoding="async" alt="Nur wenn Sie wissen, was drinsteckt, können Sie sich sicher sein, dass alles mit rechten Dingen zugeht. Das gilt für Fast Food wie für Software. " title="Nur wenn Sie wissen, was drinsteckt, können Sie sich sicher sein, dass alles mit rechten Dingen zugeht. Das gilt für Fast Food wie für Software. " src="https://images.computerwoche.de/bdb/3353396/1200x.jpg" width="1200" loading="lazy"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Nur wenn Sie wissen, was drinsteckt, können Sie sich sicher sein, dass alles mit rechten Dingen zugeht. Das gilt für Fast Food wie für Software. </p></figcaption></figure><p class="imageCredit"> Foto: Geka – shutterstock.com</p></div>




<p>Um Software abzusichern, muss man wissen, was in ihrem Code steckt. Aus diesem Grund ist eine Software Bill of Material, SBOM oder Software-Stückliste heute unerlässlich. Der SolarWinds-Angriff sowie die Log4j-Schwachstelle haben verdeutlicht, wie wichtig es ist, die Sicherheit von Softwarelieferketten in den Fokus zu nehmen – insbesondere, wenn es um Open Source Software geht. <a href="https://www.sonarsource.com/open-source-maintainer-survey-2023.pdf" target="_blank" rel="noreferrer noopener">Einer Umfrage</a> (PDF) des Open-Source-Unternehmens Tidelift zufolge enthalten heute 92 Prozent aller Anwendungen Open-Source-Komponenten. Eine durchschnittliche, moderne Applikation besteht demnach sogar zu 70 Prozent aus quelloffener Software.</p>



<p>Die Antwort auf die potenziellen Risiken sind – wenn es nach der <a title="Linux Foundation" href="https://www.linuxfoundation.org/tools/the-state-of-software-bill-of-materials-sbom-and-cybersecurity-readiness/" target="_blank" rel="noopener">Linux Foundation</a>, der <a title="Open Source Security Foundation" href="https://openssf.org/" target="_blank" rel="noopener">Open Source Security Foundation</a> und <a title="OpenChain" href="https://www.openchainproject.org/" target="_blank" rel="noopener">OpenChain</a> geht – SBOMs: Formale und maschinenlesbare Metadaten, die ein Softwarepaket und seinen Inhalt eindeutig identifizieren. Die Software-Stücklisten können auch andere Informationen enthalten, etwa Copyright- oder Lizenzdaten. Dabei ist eine Software Bill of Material so konzipiert, dass sie organisationsübergreifend ausgetauscht werden kann. Besonders hilfreich ist eine SBOM, um die Transparenz über die von den Teilnehmern einer Softwarelieferkette gelieferten Komponenten zu gewährleisten.</p>



<h2 class="wp-block-heading">SBOM – Best Practices</h2>



<p>Eine SBOM sollte beinhalten:</p>



<ul class="wp-block-list">
<li><p>die Open-Source-Bibliotheken der Anwendung;</p></li>



<li><p>Plugins, Erweiterungen und andere Zusatzmodule;</p></li>



<li><p>von In-House-Entwicklern selbst geschriebenen Quellcode;</p></li>



<li><p>Informationen über die Versionen dieser Komponenten, ihren Lizenzierungs- und Patch-Status;</p></li>



<li><p>automatische kryptografische Signatur und Überprüfung von Komponenten;</p></li>



<li><p>automatische Scans, um SBOMs als Teil der CI/CD-Pipeline zu erstellen.</p></li>
</ul>



<p>Dabei sollte eine Software Bill of Material ein einheitliches Format verwenden. Zu den gängigen SBOM-Formaten gehören:</p>



<ul class="wp-block-list">
<li><p>Software Package Data Exchange (SPDX),</p></li>



<li><p>Software Identification (SWID) Tagging und</p></li>



<li><p>OWASP CycloneDX.</p></li>
</ul>



<p>Bislang hat sich keiner der drei Standards von den anderen abgesetzt und einen De-facto-Industriestandard geschaffen. Um SBOMs praktikabel zu machen, sollte die SBOM-Erstellung nicht nur automatisiert, sondern in die CI/CD-Pipeline integriert werden. Oder wie die National Telecommunications and Information Administration (NTIA) es <a title="ausdrückt" href="https://www.ntia.doc.gov/files/ntia/publications/copado_-_2021.06.17.pdf" target="_blank" rel="noopener">ausdrückt</a> (PDF): “Das ultimative Ziel ist es, SBOMs in Maschinengeschwindigkeit zu generieren.”</p>



<h2 class="wp-block-heading">Software Bill of Materials – Use Cases</h2>



<p>Auch bei SBOMs gibt es drei verschiedene Anwendungsfälle. Im Allgemeinen sind das:</p>



<ol class="wp-block-list">
<li><p><strong>Softwarehersteller</strong> verwenden SBOMs, um Erstellung und Wartung der von ihnen gelieferten Software zu unterstützen.</p></li>



<li><p><strong>Softwareeinkäufer</strong> nutzen SBOMs, um sich vor dem Kauf abzusichern, Rabatte auszuhandeln und Implementierungsstrategien aufzusetzen.</p></li>



<li><p><strong>Softwarebetreiber</strong> nutzen SBOMs für das Vulnerability- und Asset-Management, um Lizenzen und Compliance zu managen und Abhängigkeiten und Risiken in Sachen Software und Komponenten schnell zu identifizieren.</p></li>
</ol>



<h2 class="wp-block-heading">Empfehlenswerte SBOM-Tools</h2>



<p>Bei drei verschiedenen SBOM-Formaten und einer Vielzahl von Metadaten, die innerhalb einer Software Bill of Material verfolgt werden können, ist es nicht verwunderlich, dass es kein SBOM-Tool gibt, das sämtliche Bedürfnisse erfüllt. <a href="https://anchore.com/sbom/gartner-innovation-insights-sboms/" title="Gartner empfiehlt" target="_blank" rel="noopener">Gartner empfiehlt</a>, Tools zu verwenden, die folgende Funktionen mitbringen:</p>



<ul class="wp-block-list">
<li><p>SBOMs während des Build-Prozesses erstellen;</p></li>



<li><p>Quellcode und Binärdateien (wie Container-Images) analysieren;</p></li>



<li><p>SBOMs bearbeiten;</p></li>



<li><p>SBOMs in lesbaren Formaten anzeigen, vergleichen, importieren und validieren;</p></li>



<li><p>SBOM-Inhalte von einem Format oder Dateityp in andere übersetzen, beziehungsweise die Informationen zusammenführen; </p></li>



<li><p>Einbindung anderer Tools über APIs und Bibliotheken;</p></li>
</ul>



<p>Keines der folgenden acht Tools erfüllt (bislang) all diese Empfehlungen. Wir empfehlen Ihnen, die Tools auszuprobieren und anschließend zu ermitteln, welches für Ihre Zwecke am besten geeignet ist. Diese acht SBOM-Tools verdienen Ihre Aufmerksamkeit:</p>



<p><strong><a href="https://anchore.com/sbom/" title="Anchore" target="_blank" rel="noopener">Anchore</a></strong></p>



<p>Das Unternehmen ist bereits seit sechs Jahren im SBOM-Business tätig. Die Grundlage des Unternehmens bilden zwei Open-Source-Projekte:</p>



<ul class="wp-block-list">
<li><p>Syft ist ein Tool mit Kommandozeilen-Interface und eine Bibliothek, um SBOMs aus Container-Images und Dateisystemen zu erzeugen. </p></li>



<li><p>Grype ist ein einfach zu integrierendes Tool, um Container-Images und Dateisysteme auf Schwachstellen zu scannen.</p></li>
</ul>



<p>Zusammen können diese beiden Werkzeuge Software-Stücklisten in jeder Phase des Entwicklungsprozesses erzeugen, von Quellcode-Repositories und CI/CD-Pipelines bis hin zu Container-Registries und Laufzeiten. Diese SBOMs werden in einem zentralen Repository aufbewahrt, um vollständige Transparenz und kontinuierliches Monitoring zu gewährleisten – auch nach der Bereitstellung. Die Tools von Anchore unterstützen CycloneDX, SPDX und das proprietäre SBOM-Format von Syft. Das Anbieterunternehmen bündelt seine SBOM-Funktionalität in der Plattform Anchore Enterprise 4.0 Software SCM (Supply Chain Management).</p>



<p><strong><a href="https://fossa.com/lp/simplify-sbom-generation-fossa" title="FOSSA" target="_blank" rel="noopener">FOSSA</a></strong></p>



<p>Die Flaggschiff-Programme von FOSSA sind ein Open Source License Compliance Manager und ein Open Source Vulnerability Scanner. Der Ansatz von FOSSA sieht vor, dass Sie das SBOM-Tool in Ihr bevorzugtes Versionskontrollsystem wie GitHub, BitBucket oder GitLab integrieren. Sie können auch die CLI von FOSSA verwenden und das Tool lokal ausführen oder es in Ihre CI/CD-Pipeline integrieren.</p>



<p>In jedem Fall identifiziert FOSSA im Rahmen eines Projektscans automatisch sowohl direkte als auch indirekte Abhängigkeiten in der Codebasis.</p>



<p><strong><a href="https://about.gitlab.com/" target="_blank" rel="noreferrer noopener">GitLab (ehemals Rezilion)</a></strong></p>



<p>Beim DevSecOps-Anbieter ist SBOM Teil seiner ganzheitlichen Software-Sicherheits- und Schwachstellen-Systeme. Dynamic SBOM verwendet eine dynamische Laufzeitanalyse, um die Angriffsfläche Ihrer Software zu monitoren. Es sucht also ständig nach bekannten Schwachstellen in den Komponenten. Neben der Bereitstellung eines Live-Inventars aller Softwarekomponenten in Ihren CI/CD-, Staging- und Produktionsumgebungen wird Ihre SBOM ständig aktualisiert. Sie können Ihre Software Bill of Material im CycloneDX-Format und als Excel-Tabelle exportieren.</p>



<p>Nach der Übernahme durch GitLab wurden die SBOM-Funktionalitäten von Rezilion im Jahr 2022 <a href="https://about.gitlab.com/blog/2022/03/23/gitlab-rezilion-integration-reduces-vulnerability-backlog-identifies-exploitable-risks-to-fix/">in die DevSecOps-Plattform integriert</a>.</p>



<p><strong><a title="Mend" href="https://www.mend.io/sca/" target="_blank" rel="noopener">Mend</a></strong></p>



<p>Früher unter dem Namen WhiteSource bekannt, bietet Mend eine Vielzahl von SCA-Tools (Software Composition Analysis) an. Eine SBOM-Funktionalität ist in das SCA-Toolset integriert. Die Lösung von Mend ist weniger ein Entwicklerprogramm oder ein CI/CD-Tool – sondern vielmehr ein Open-Source-Lizenz- und Sicherheitsmechanismus für Programmierer.</p>



<p>Mit Hilfe von Mend lassen sich sämtliche Softwarekomponenten tracken, direkte und indirekte Abhängigkeiten identifizieren, Schwachstellen aufdecken, Remediationspfade bereitstellen und automatisch SBOM-Einträge aktualisieren.</p>



<p><strong><a href="https://github.com/opensbom-generator/spdx-sbom-generator" title="SPDX SBOM Generator" target="_blank" rel="noopener">SPDX SBOM Generator</a></strong></p>



<p>Dieses eigenständige Open-Source-Tool tut das, was sein Name verspricht: SPDX-SBOMs aus aktuellen Paketmanagern oder Build-Systemen erstellen. Sie können seine CLI verwenden, um SBOM-Daten aus Ihrem Code zu erzeugen. Das Tool erzeugt Berichte über Komponenten, Lizenzen, Copyrights und Sicherheitsreferenzen Ihres Codes. Diese Daten werden in der SPDX v2.2-Spezifikation exportiert.</p>



<p><strong><a href="https://www.startleftsecurity.com/tauruseer-application-security-posture-management-platform" title="Start Left Security" target="_blank" rel="noopener">Start Left Security</a></strong></p>



<p>Dieses SBOM-Tool wird als Software-as-a-Service (SaaS) angeboten. Auf der Grundlage einer patentierten, anwendungszentrierten Integrationsmethodik kombiniert das ehemals unter dem Namen TauruSeer bekannte Angebot seine Cognition-Engine-Sicherheitsüberprüfung mit SBOM. Das Paket hilft Ihnen, Ihren Code für Ihre Entwickler und Kunden abzusichern und zu tracken.</p>



<p><strong><a href="https://github.com/tern-tools/tern" title="Tern Project" target="_blank" rel="noopener">Tern Project</a></strong></p>



<p>Dieses quelloffene SBOM-Projekt lässt sich gut mit SPDX SBOM Generator kombinieren. Anstatt mit Paketmanagern oder Build-Systemen zu arbeiten, erzeugt dieses SCA-Tool und die Python-Bibliothek eine SBOM für Container-Images und Docker-Dateien. Darüber hinaus lassen sich auch SBOMs im SPDX-Format erzeugen.</p>



<p><strong><a href="https://www.vigilant-ops.com/products/" title="Vigilant Ops" target="_blank" rel="noopener">Vigilant Ops</a></strong></p>



<p>Dieser Cybersicherheitsanbieter aus dem Healthcare-Bereich konzentriert sich mit seiner InSight-Plattform auf Software-Stücklisten. Seine SaaS-Plattform generiert und pflegt zertifizierte SBOMs und sorgt für deren authentifizierten Austausch. Sie bietet Sicherheit durch kontinuierliche Schwachstellenüberwachung. Die SBOM-Zertifizierung verwendet patentierte Algorithmen, um sicherzustellen, dass alle Komponenten validiert und Schwachstellen verlinkt sind.</p>



<p>Die Sicherheitsfunktionen können auch für SBOMs verwendet werden, die von anderen Programmen erstellt wurden. Diese werden sowohl im Ruhezustand als auch während der Übertragung verschlüsselt.</p>



<p><strong>Dieser Artikel ist <a href="https://www.csoonline.com/article/573225/8-top-sbom-tools-to-consider.html" target="_blank">im Original</a> bei unserer Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Speed without control is a liability, not an advantage': GitLab study reveals AI code generation is outpacing controls]]></title>
<description><![CDATA[Rapid AI adoption is just shifting bottlenecks downstream as governance fails to keep up, making trust more critical than speed.]]></description>
<link>https://tsecurity.de/de/3637082/it-nachrichten/speed-without-control-is-a-liability-not-an-advantage-gitlab-study-reveals-ai-code-generation-is-outpacing-controls/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637082/it-nachrichten/speed-without-control-is-a-liability-not-an-advantage-gitlab-study-reveals-ai-code-generation-is-outpacing-controls/</guid>
<pubDate>Wed, 01 Jul 2026 01:32:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Rapid AI adoption is just shifting bottlenecks downstream as governance fails to keep up, making trust more critical than speed.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-9222 | GitLab Community Edition/Enterprise Edition up to 18.5.4/18.6.2/18.7.0 Flavored Markdown cross site scripting (Issue 562561 / Nessus ID 298869)]]></title>
<description><![CDATA[A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.5.4/18.6.2/18.7.0. It has been declared as problematic. Affected is an unknown function of the component Flavored Markdown. Such manipulation leads to cross site scripting.

This vulnerability is uniquely identi...]]></description>
<link>https://tsecurity.de/de/3634681/sicherheitsluecken/cve-2025-9222-gitlab-community-editionenterprise-edition-up-to-185418621870-flavored-markdown-cross-site-scripting-issue-562561-nessus-id-298869/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634681/sicherheitsluecken/cve-2025-9222-gitlab-community-editionenterprise-edition-up-to-185418621870-flavored-markdown-cross-site-scripting-issue-562561-nessus-id-298869/</guid>
<pubDate>Tue, 30 Jun 2026 08:05:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 18.5.4/18.6.2/18.7.0</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected is an unknown function of the component <em>Flavored Markdown</em>. Such manipulation leads to cross site scripting.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2025-9222">CVE-2025-9222</a>. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-13772 | GitLab Enterprise Edition up to 18.5.4/18.6.2/18.7.0 API Request authorization (Issue 581268 / EUVD-2026-1768)]]></title>
<description><![CDATA[A vulnerability has been found in GitLab Enterprise Edition up to 18.5.4/18.6.2/18.7.0 and classified as critical. The impacted element is an unknown function of the component API Request Handler. The manipulation leads to missing authorization.

This vulnerability is traded as CVE-2025-13772. It...]]></description>
<link>https://tsecurity.de/de/3634682/sicherheitsluecken/cve-2025-13772-gitlab-enterprise-edition-up-to-185418621870-api-request-authorization-issue-581268-euvd-2026-1768/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634682/sicherheitsluecken/cve-2025-13772-gitlab-enterprise-edition-up-to-185418621870-api-request-authorization-issue-581268-euvd-2026-1768/</guid>
<pubDate>Tue, 30 Jun 2026 08:05:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/gitlab:enterprise_edition">GitLab Enterprise Edition up to 18.5.4/18.6.2/18.7.0</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. The impacted element is an unknown function of the component <em>API Request Handler</em>. The manipulation leads to missing authorization.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2025-13772">CVE-2025-13772</a>. It is possible to initiate the attack remotely. There is no exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-13761 | GitLab Community Edition/Enterprise Edition up to 18.6.2/18.7.0 cross site scripting (Issue 582237 / EUVD-2026-1770)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in GitLab Community Edition and Enterprise Edition up to 18.6.2/18.7.0. Impacted is an unknown function. Performing a manipulation results in cross site scripting.

This vulnerability is reported as CVE-2025-13761. The attack is...]]></description>
<link>https://tsecurity.de/de/3634676/sicherheitsluecken/cve-2025-13761-gitlab-community-editionenterprise-edition-up-to-18621870-cross-site-scripting-issue-582237-euvd-2026-1770/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634676/sicherheitsluecken/cve-2025-13761-gitlab-community-editionenterprise-edition-up-to-18621870-cross-site-scripting-issue-582237-euvd-2026-1770/</guid>
<pubDate>Tue, 30 Jun 2026 08:05:51 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 18.6.2/18.7.0</a>. Impacted is an unknown function. Performing a manipulation results in cross site scripting.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2025-13761">CVE-2025-13761</a>. The attack is possible to be carried out remotely. No exploit exists.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.196]]></title>
<description><![CDATA[What's changed

Added support for organization default models — admins set it in the org console; it shows as "Org default" (or "Role default") in /model when you haven't picked one yourself
Added readable default names for sessions at start, making them easier to identify and message
Added click...]]></description>
<link>https://tsecurity.de/de/3634245/downloads/v21196/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634245/downloads/v21196/</guid>
<pubDate>Tue, 30 Jun 2026 01:46:34 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Added support for organization default models — admins set it in the org console; it shows as "Org default" (or "Role default") in <code>/model</code> when you haven't picked one yourself</li>
<li>Added readable default names for sessions at start, making them easier to identify and message</li>
<li>Added clickable file attachments in chat — Cmd/Ctrl-click reveals the file in Finder/Explorer</li>
<li>Security: <code>claude mcp list</code>/<code>get</code> no longer spawn <code>.mcp.json</code> servers that a repo self-approved via a committed <code>.claude/settings.json</code>; untrusted workspaces show <code>⏸ Pending approval</code></li>
<li>Fixed waking a background job permanently deleting its conversation and re-running the original prompt when the transcript probe misread a real transcript; the file is now set aside, never deleted</li>
<li>Fixed the rate-limit warning flickering off and rate-limit telemetry being over-counted when multiple parallel requests were in flight at the moment a usage limit was hit</li>
<li>Fixed duplicate recap lines after a background session's turn: a schema-rejected StructuredOutput attempt no longer renders alongside its retry</li>
<li>Fixed PowerShell <code>git diff</code>/<code>git grep</code>, <code>egrep</code>/<code>fgrep</code>, and quoted search patterns containing <code>|</code> being reported as failures when they exit 1, matching Bash behavior</li>
<li>Fixed multiple <code>claude agents</code> side panel issues: keyboard focus getting stuck when opening an agent, background jobs losing their subagent types on every open, and sessions showing incorrect status while actively running</li>
<li>Fixed <code>claude agents --dangerously-skip-permissions</code> silently falling back to auto mode instead of showing the bypass disclaimer and applying bypass mode to spawned agents</li>
<li>Fixed mid-turn crash recovery for Remote sessions — sessions interrupted by a server restart now auto-resume on the next worker</li>
<li>Fixed sessions moved with <code>/cd</code> reappearing in the old directory's resume list after a non-graceful exit when the old path contained special characters</li>
<li>Fixed <code>claude plugin validate</code> skipping local plugins whose source is "." and stopping after the first error class</li>
<li>Fixed Esc Esc at an idle prompt not opening the rewind menu (regression); use Ctrl+C or Ctrl+X Ctrl+K to stop background agents</li>
<li>Fixed MCP OAuth requesting the authorization server's full <code>scopes_supported</code> catalog when no scope is specified, causing <code>invalid_scope</code> failures on GitLab self-hosted and other enterprise IdPs</li>
<li>Fixed <code>/context</code> showing 0 tokens for all tool groups on Bedrock</li>
<li>Fixed <code>/deep-research</code> misreporting verifier failures as "all claims refuted" instead of <code>unverified</code></li>
<li>Fixed plugin dependency version pins not being honored when the marketplace was added as a local folder path backed by a git repo</li>
<li>Fixed <code>claude agents</code> session status: completed rows no longer flip between "Done" and "Needs your input", stalled agents are now labeled "Needs attention", and results that mention a PR show a clickable link</li>
<li>Fixed voice dictation swallowing spaces and spuriously starting a recording during very fast typing when voice mode is enabled</li>
<li>Improved background session reliability: long-running commands and workflows now survive the session's process being stopped, restarted, or updated — including on Windows, where background shells are handed off instead of being killed</li>
<li>Improved background agents: workers killed by a daemon restart are now automatically resumed from where they left off the next time the agents view opens</li>
<li>Improved <code>/code-review</code> workflow: merged five cleanup finders into one, cutting token usage by roughly 25%</li>
<li>Reduced per-frame rendering work in the terminal UI by skipping no-op subtree walks during streaming</li>
<li>The streaming idle watchdog is now on by default for all providers — it aborts and retries when a response stream produces no events for 5 minutes. Set <code>CLAUDE_ENABLE_STREAM_WATCHDOG=0</code> to disable.</li>
<li>Remote Control is now disabled when <code>ANTHROPIC_BASE_URL</code> points at a non-Anthropic host, matching the existing behavior under <code>CLAUDE_CODE_USE_BEDROCK</code>/<code>_VERTEX</code>/<code>_FOUNDRY</code></li>
<li>Changed opening the agents view from a foreground session to require a single <code>←</code> press instead of two, matching the behavior in background sessions</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kali Linux 2026.2 Release (GNOME 50, KDE 6.6, Helper Scripts, APT Formats & VM Boot Tweaking)]]></title>
<description><![CDATA[It’s the final week of Q2, and Kali Linux 2026.2 is here - right on schedule ;) We have been heads down since our last release, and we are ready to share what we have been working on. This release is a mix of desktop refreshes, infrastructure improvements, and quality-of-life changes that we thin...]]></description>
<link>https://tsecurity.de/de/3633508/tools/kali-linux-20262-release-gnome-50-kde-66-helper-scripts-apt-formats-vm-boot-tweaking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633508/tools/kali-linux-20262-release-gnome-50-kde-66-helper-scripts-apt-formats-vm-boot-tweaking/</guid>
<pubDate>Mon, 29 Jun 2026 18:25:00 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>It’s the final week of Q2, and Kali Linux 2026.2 is here - right on schedule ;) We have been heads down since our last release, and we are ready to share what we have been working on. This release is a mix of desktop refreshes, infrastructure improvements, and quality-of-life changes that we think you will appreciate.</p>
<p>The summary of the <a href="https://bugs.kali.org/changelog_page.php">changelog</a> since the <a href="https://www.kali.org/blog/kali-linux-2026-1-release/">2026.1 release from March</a> is:</p>
<ul>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#desktop-environments-updates">Desktop Environments</a></strong> - Bump to GNOME 50 and KDE Plasma 6.6</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#improved-consistency-for-services-helper-scripts">Helper Scripts Consistency</a></strong> - Consistency to our little launches at starting services</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#apt-gets-a-new-sources-format">APT Format</a></strong> - Goodbye <code>sources.list</code>, hello <code>sources.list.d/kali.source</code></li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#no-more-graphics-firmware-pre-installed-for-vm-use-cases">VM Boot Optimisation</a></strong> - Smaller initrd + faster boot times = happy virtual machine users</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#disruptive-package-updates">Reboot Warning</a></strong> - Heads-up, <code>polkit</code> and <code>xrdp</code> upgrades require a system reboot</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#linux-kernel-for-this-release-619">Kali Kernel Incoming</a></strong> - Staying with 6.19 for now, how to get 7.0 early</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#a-sneak-peek-build-scripts">Build Scripts Incoming</a></strong> - Heads-up with some changing on the way</li>
<li><strong><a href="https://www.kali.org/blog/kali-linux-2026-2-release/#new-tools-in-kali">New Tools</a></strong> - As always, various new shiny packages have been added <em>(9!)</em></li>
</ul>
<hr>
<h2>Desktop Environments Updates</h2>
<p>As we do roughly every six months, every other Kali release, our <a href="https://www.kali.org/docs/general-use/switching-desktop-environments/">desktop environments</a> get a major update. This time it’s for: <a href="https://www.kali.org/blog/kali-linux-2026-2-release/#gnome-50">GNOME</a> and <a href="https://www.kali.org/blog/kali-linux-2026-2-release/#kde-plasma-6-6">KDE Plasma</a>. Neither brings sweeping changes, but both have put real effort into <strong>refining performance and usability</strong> across the whole ecosystem.</p>
<h3>GNOME 50</h3>
<p>GNOME 50 brings usability and performance improvements across the desktop. The <strong>file manager received significant optimizations</strong>, resulting in faster thumbnail and icon loading, improved responsiveness, and reduced memory usage. The desktop also received new accessibility enhancements through a brand-new preferences window, tweaks to the screen reader, and automatic language switching.</p>
<p>Another addition is <strong>support for document annotations</strong> in the Document Viewer app, making it easier to add text notes and highlights directly to documents.</p>
<p>Here you can read more about all the changes with this new GNOME release: <a href="https://release.gnome.org/50/">GNOME 50 release announcement</a>.</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-2-release/images/gnome-50.png" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-2-release/images/gnome-50.png" alt="Kali + GNOME 50">
</a>
</p>

<h3>KDE Plasma 6.6</h3>
<p>KDE Plasma 6.6 focuses on improving usability and accessibility while introducing several new features, including a <strong>new on-screen keyboard</strong>, providing a better experience particularly for touch-enabled devices.</p>
<p>The <strong>Spectacle screenshot utility can now recognize and extract text</strong> directly from screenshots, making OCR functionality available from the desktop. Accessibility has also been enhanced with new color-vision support options, improvements to Zoom and Magnifier, support for Slow Keys on Wayland, and adoption of the standardized Reduced Motion setting.</p>
<p>Here you can read more about all the changes with this new Plasma release: <a href="https://kde.org/announcements/plasma/6/6.6.0/">KDE Plasma 6.6 release announcement</a>.</p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-2-release/images/kde-6.6.png" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-2-release/images/kde-6.6.png" alt="Kali + KDE Plasma 6.6">
</a>
</p>

<h2>Improved Consistency For Services Helper Scripts</h2>
<p>To improve consistency across tools that depend on a service, we have updated our helper scripts. Previously, a tool that required a service might only let you start it (with no way to stop) - and the information displayed back was inconsistent (mixture of service status, how to access, default credentials or nothing at all). With this change, multiple packages have been updated to use these new scripts, which now handle the following tasks:</p>
<ul>
<li>Manage the service - <strong>start/stop</strong></li>
<li><strong>Check if the service is already running</strong> - avoiding starting it twice</li>
<li>Show the <strong>service status</strong></li>
<li>Show any <strong><a href="https://www.kali.org/docs/introduction/default-credentials/">default credentials</a></strong></li>
<li>Show <strong>how to access it</strong> - such as if it’s a web UI, the URL <em>(and bonus, <strong>automatically open it in the browser</strong>!)</em></li>
</ul>
<p>We also make sure that any Kali packages which include a service use <strong><code>&lt;tool&gt;-start</code></strong>/<strong><code>&lt;tool&gt;-stop</code></strong> for their command names.</p>
<p><em>Hopefully this makes the little things a little easier.</em></p>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-2-release/images/kali-services.png" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-2-release/images/kali-services.png" alt="Kali Services Helper Scripts">
</a>
</p>

<h2>APT Gets A New Sources Format</h2>
<p>Since the beginning of time, the APT sources for Kali Linux were configured in the file <code>/etc/apt/sources.list</code>. This file tells APT from where to update your system, and it’s so fundamental that pretty much everyone (that is, Kali users) knows this file and its content:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ cat /etc/apt/sources.list
# See https://www.kali.org/docs/general-use/kali-linux-sources-list-repositories/
deb http://http.kali.org/kali kali-rolling main contrib non-free non-free-firmware
</code></pre>
<p>Well, it’s a <strong>“once in a distro lifetime” kind of thing, and here it is</strong> - <code>/etc/apt/sources.list</code> is retired, in favor of the new file <code>/etc/apt/sources.list.d/kali.sources</code>:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ cat /etc/apt/sources.list.d/kali.sources
# See https://www.kali.org/docs/general-use/kali-apt-sources/
Types: deb
URIs: http://http.kali.org/kali/
Suites: kali-rolling
Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/kali-archive-keyring.gpg
</code></pre>
<p><strong>All the freshly-installed systems will be configured</strong> as such. <strong>Existing systems won’t be changed</strong>. Both files are equivalent and work just the same. However, in the near future, APT will warn if the old file is in use, and will suggest modernizing it.</p>
<p>Note that, for those in the know, this isn’t anything new: both formats have existed for a long time now, and you could use either one or the other. What’s happening is that the <em>default</em> is slowly changing, from the <strong>old “one-line-style”</strong> to the <strong>new “deb822-style”</strong>. This is happening in Debian and in Debian-derivatives like Ubuntu. Kali is just following suit.</p>
<p>And for the curious, there’s a very complete and detailed manual page:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ man sources.list
</code></pre>
<h2>No More Graphics Firmware Pre-installed For VM Use-cases</h2>
<p>Kali has had a long tradition of pre-installing a lot of firmware in its images. The upside is that users didn’t need to know what firmware they needed to install for their hardware to work: it was already there. And the downside, obviously, was that all the firmware that wasn’t needed was nevertheless installed and taking space for nothing. </p>
<p>It worked for us so far, in the sense that we don’t get too many bug reports related to missing firmware. But lately the changing landscape of <em>graphics firmware</em> forced us to re-evaluate this decision.</p>
<p>The issue with graphics firmware is that it just keeps growing bigger, and right now having it installed for <a href="https://www.kali.org/docs/general-use/install-nvidia-drivers-on-kali-linux/">NVidia</a>, AMD and Intel GPUs takes almost 300 MB. But what’s even worse: some bits and pieces of these firmware packages need to be loaded very early, and therefore they are also installed in the initrd (note: the initrd, or initramfs, is this “minimal” system that is loaded early on by the kernel at boot time). And lately, the Kali initrd peaked at around 200 MB, mainly due to graphics firmware. What does that mean in practice? A bigger initrd means slower boot time, and can potentially fill up your <code>/boot</code> partition if ever it’s too small.</p>
<p>So we thought we could improve the situation for VM users here: the vast majority probably don’t need graphics firmware, ever. The only use-case we can think of is a VM with a dedicated GPU + GPU passthrough enabled. If you’re in this case, you might need graphics firmware.</p>
<p>So, what changed in practice, you may ask?</p>
<ul>
<li><strong><a href="https://www.kali.org/get-kali/#kali-virtual-machines">Pre-built VM images</a> don’t come with graphics firmware anymore</strong></li>
<li><a href="https://www.kali.org/get-kali/#kali-installer-images"><strong>Installer images</strong></a> now detect if installation happens <strong>in a VM</strong>, and in that case <strong>graphics firmware is not installed</strong></li>
</ul>
<p>As a result, the <strong>initrd is down to 60 MB for VM users, and the boot time is cut by ~3x</strong> (tested for QEMU VM on a Linux host, your mileage may vary). That’s a massive improvement in boot time.</p>
<p>For baremetal users: nothing changed, so you still get a 200 MB initrd with all graphics firmware pre-installed. If you’d like to optimize, it’s on you to uninstall the firmware that you don’t need. A word of caution though: make sure to know what you’re doing, because removing graphics firmware that is <em>needed</em> might leave you with a <a href="https://www.kali.org/docs/troubleshooting/graphics-issues-on-bare-metal-installation/">system without graphics after reboot</a>.</p>
<h2>Disruptive Package Updates</h2>
<p>We’ve got some slightly disruptive updates in this release.</p>
<p><strong>polkit: a reboot is required</strong></p>
<p>The update of the <code>polkitd</code> package requires a reboot, otherwise <em>trying to start GUI applications as root will fail with cryptic error messages</em>.</p>
<p>There’s an indication of this <strong>reboot requirement</strong> in the output of <code>apt full-upgrade</code>, when the <code>polkitd</code> package is updated. It’s just <strong>not very obvious</strong>, the hint is buried with the rest of the logs:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ sudo apt update &amp;&amp; sudo apt full-upgrade
[...]
Setting up libpolkit-gobject-1-0:amd64 (127+really127-0kali1)…
Setting up libpolkit-agent-1-0:amd64 (127+really127-0kali1)…
Setting up polkitd (127+really127-0kali1)…
Upgrading to this polkitd version requires a reboot, please reboot the system when convenient.
Created symlink '/etc/systemd/system/sockets.target.wants/polkit-agent-helper.socket' → '/usr/lib/systemd/system/polkit-agent-helper.socket'.
[...]
</code></pre>
<p>After a reboot, and if ever you still can’t run applications as root, make sure that <code>polkit-agent-helper</code> is started:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ sudo systemctl enable --now polkit-agent-helper.socket
</code></pre>
<p>If you’re still having issues, reach out on our <a href="https://bugs.kali.org/">bug tracker</a>.</p>
<hr>
<p><strong>xrdp: a reboot is required</strong></p>
<p>In this Kali release, we updated <code>xrdp</code> and <code>xorgxrdp</code> to the <code>v0.10</code> series. <a href="https://www.kali.org/docs/general-use/xfce-with-rdp/">xrdp</a> is an open-source Remote Desktop Protocol server: you might use it if you connect to your Kali instance remotely. <em>If you’re an xrdp user, you’ll need to reboot after this upgrade</em>.</p>
<p>For those who run Kali in Hyper-V, using the <a href="https://www.kali.org/docs/virtualization/install-hyper-v-guest-enhanced-session-mode/">Enhanced Session Mode</a>: you’re an xrdp user, even if you didn’t know it! We did our best to ensure a smooth transition, and yet we got reports that xrdp wasn’t functional after the upgrade. If ever you’re in this case, you can try to run <code>kali-tweaks</code>, and in the Virtualization section you can try to <strong>disable, and then enable again</strong> the Hyper-V Enhanced Session Mode. That might fix the issue. <strong>Don’t forget to reboot</strong>!</p>
<p>As always, if you’re still having issues after that, feel free to reach out on the <a href="https://bugs.kali.org/">Kali bug tracker</a>.</p>
<h2>Linux Kernel For This Release: 6.19</h2>
<p>Regarding the version of the <a href="https://pkg.kali.org/pkg/linux">Linux kernel</a> to include in this release of Kali, it’s been a tough decision.</p>
<p>On one hand, we’d like to release with the latest version of the Linux kernel, due to all the recent vulnerability disclosures (<a href="https://en.wikipedia.org/wiki/Copy_Fail">Copy Fail/CVE-2026-31431</a>, <a href="https://github.com/V4bel/dirtyfrag">Dirty Frag/CVE-2026-43284 &amp; CVE-2026-43500</a> and others ). On the other hand, when the 7.0 kernel reached Debian, there were <a href="https://bugs.debian.org/1135362">reports of incompatibilities with the NVidia DKMS drivers</a> .</p>
<p>We decided to release with a 6.19 kernel to avoid breaking <a href="https://www.kali.org/docs/general-use/install-nvidia-drivers-on-kali-linux/">NVidia users</a>. At the same time, for <strong>those who prefer to get the latest kernel</strong> and don’t care about NVidia compatibility, <strong>we have the kernel 7.0 ready for you in <code>kali-experimental</code></strong>. Make sure to check our documentation that explains <a href="https://www.kali.org/docs/general-use/kali-apt-sources/#enabling-kali-additional-branches">how to enable the kali-experimental repository</a>. The 7.0 kernel is also available in kali-rolling, so you can just <a href="https://www.kali.org/docs/general-use/updating-kali/">update your whole system</a> and get the latest packages from <a href="https://www.kali.org/docs/general-use/kali-branches/">kali-rolling</a>.</p>
<h2>A Sneak Peek: Build Scripts</h2>
<p>Our <a href="https://gitlab.com/kalilinux/build-scripts/">build scripts</a> are what we use to produce every Kali image - ARM SBCs, Base (Installer and live ISOs), Cloud, Containers, VMs, WSL &amp; NetHunter/Pro. Each lives in its own repo, and over time they have each grown in slightly different directions. For the next release, Kali 2026.3, we are doing <strong>a consistency pass across all of them: same structure, same conventions, same behaviour throughout</strong>.</p>
<p>As a result of these changes, some CI pipelines or workflows may need tweaking.</p>
<h2>New Tools in Kali</h2>
<p>This release brings <strong>9 new tools</strong> <em>(to the network repositories)</em>. As always, we have been busy adding to the arsenal:</p>
<ul>
<li><a href="https://www.kali.org/tools/arsenal-ng/">arsenal-ng</a> - Go-based command library equipped with 200+ cybersecurity cheat-sheets</li>
<li><a href="https://www.kali.org/tools/hydra/">hydra-gtk</a> - [Re-added] Very fast network logon cracker - GTK+ based GUI</li>
<li><a href="https://www.kali.org/tools/legba/">legba</a> - Multiprotocol credentials bruteforcer / password sprayer and enumerator</li>
<li><a href="https://www.kali.org/tools/oletools/">oletools</a> - Analyze MS OLE2 files and MS Office documents</li>
<li><a href="https://www.kali.org/tools/penelope/">penelope</a> - Powerful shell handler</li>
<li><a href="https://www.kali.org/tools/shell-gpt/">shell-gpt</a> - Command-line productivity tool powered by AI large language models</li>
<li><a href="https://www.kali.org/tools/tailscale/">tailscale</a> - Secure connectivity platform</li>
<li><a href="https://www.kali.org/tools/tookie-osint/">tookie-osint</a> - OSINT information gathering tool for finding social media accounts</li>
<li><a href="https://www.kali.org/tools/uro/">uro</a> - Declutter URLs for crawling/pentesting</li>
</ul>
<p><em>There has also been numerous packages updates and new libraries as well. We also bump the <a href="https://www.kali.org/blog/kali-linux-2026-2-release/#linux-kernel-for-this-release-619">Kali kernel to 6.19</a>.</em></p>
<h2>Kali NetHunter Updates</h2>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-2-release/images/nethunter-eviltwin.jpg" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-2-release/images/nethunter-eviltwin.jpg" alt="Kali NetHunter EvilTwin">
</a>
</p>

<p>We have a tremendous amount of news for the lovers of mobile hacking! The <a href="https://store.nethunter.com/packages/com.offsec.nethunter/">Kali NetHunter app</a> <strong>launches instantly</strong> now, various <strong>bugs have been fixed</strong> with the <a href="https://www.kali.org/docs/nethunter/nethunter-custom-commands/">custom commands</a> and <a href="https://www.kali.org/docs/nethunter/nethunter-chroot-manager/">chroot manager</a> . A <strong>new EvilTwin</strong> (Wi-Fi Fake AP) tab has been added with password verification captive portal, <em>which brought along a really needed iptables fix</em>. So now after using <a href="https://www.kali.org/docs/nethunter/nethunter-wifipumpkin/">Wifipumpkin3</a> or EvilTwin, Android Hotspot will work properly. Huge thanks to the incredible work by <a href="https://gitlab.com/dr1408">@dr.rootsu</a>. The <a href="https://www.kali.org/docs/nethunter/nethunter-kernel/">kernel flasher tab</a> has also <strong>received a refresh</strong>.</p>
<p>However, this release’s spotlight is on the beginning of the <a href="https://www.kali.org/blog/kali-linux-2026-2-release/#the-qcacld30-injection-story">Qcacld-3.0 injection patch</a> wave.</p>
<h3>The Qcacld3.0 Injection Story</h3>
<p>We finally came to a milestone, shout-out to all the developers that worked on injection through the <em>years</em>!</p>
<p><a href="https://gitlab.com/kimocoder">@kimocoder</a> easily spent more than anyone else on this goal. His original injection implementation came to life, on a specific device: the OnePlus Nord (AC2003). You can find the commit <a href="https://github.com/kimocoder/android_kernel_oneplus_avicii/commit/8eb5de1047e7bf069cb4de38c3a35489b35df189">here</a>. Then <a href="https://gitlab.com/Loukious">@Loukious</a> came in the mix and his modifications made it to work on other devices with <a href="https://github.com/Loukious/android_kernel_xiaomi_sm8150/commit/18c57c61ecd8f02de778e36db6be9b41167a8825">this port</a>. Finally, <a href="https://gitlab.com/cyberknight777">@cyberknight777</a> did some housekeeping, removed unnecessary changes, logging, and restored the correct authorship while attributing @Loukious as co-author. The result, <a href="https://github.com/Neternels/android_kernel_xiaomi_sunny/commit/1a4a7d313acc75cfca9a5e97673745d721b6ccea">this patch</a> is the <strong>almost universal</strong> one which brought many devices into the injection world, starting with the ones below for both kernel 4.x and 5.x versions:</p>
<ul>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-oneplus-7/">OnePlus 7</a> (LineageOS 23.2)</li>
<li>OnePlus 9 / 9 Pro</li>
<li>OnePlus Nord</li>
<li>POCO X3 Pro</li>
<li>Redmi Note 10</li>
<li>Samsung A73</li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-xiaomi-mi-a3/">Xiaomi Mi A3</a> (LineageOS 23.2)</li>
<li>Xiaomi Poco X3 NFC (PixelOS Android 16)</li>
<li>Xiaomi Redmi Note 8</li>
</ul>
<h3>Wifite On TV</h3>
<p></p><p>
<a href="https://www.kali.org/blog/kali-linux-2026-2-release/images/nethunter-wifite2-netflix-bloodhounds-s02e01.jpg" target="_blank">
<img src="https://www.kali.org/blog/kali-linux-2026-2-release/images/nethunter-wifite2-netflix-bloodhounds-s02e01.jpg" alt="Kali Wifite Netflix Bloodhounds S02E01">
</a>
</p>

<p>In the meantime, his continuous work on improving <a href="https://www.kali.org/tools/wifite/">wifite</a> caught some attention - spotted on Netflix twice. Not bad!</p>
<h3>Magisk Standalone Kernel Installer</h3>
<p>The kernel flasher tab <em>(still experimental on some devices)</em> is back in a new shape, giving a hint for the possible future look for the NetHunter app.</p>
<p>The <strong>Magisk standalone kernel flashing support is now here</strong> - you can simply open any newly built kernel installer zip in the Magisk app that was built using the <a href="https://gitlab.com/kalilinux/nethunter/build-scripts/kali-nethunter-installer">kali-nethunter-installer</a>.</p>
<h3>New Kernels</h3>
<p>In addition to the kernels that now support the qcacld3 injection, there are several <a href="https://nethunter.kali.org/kernels.html">new versions and phones</a>:</p>
<ul>
<li>Google Pixel 6a (LineageOS 23.2)</li>
<li>Redmi 5A (crDroid 14)</li>
<li>Samsung Note 20 Ultra (Android 13)</li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-samsung-galaxy-s10/">Samsung S10</a> (LineageOS 23.2)</li>
<li>Samsung S10 5G (LineageOS 23.2)</li>
<li>Samsung S10+ (LineageOS 23.2)</li>
<li>Samsung S10e (LineageOS 23.2)</li>
</ul>
<h3>NetHunter Pro</h3>
<p>Kali bare metal now on more phones! New devices added in build thanks to the awesome work by <a href="https://github.com/taygoth">@Max Furman</a>:</p>
<ul>
<li>Fairphone FP5 (QCM6490) (fp5)</li>
<li>Google Pixel 3 (SDM845) (blueline)</li>
<li>Google Pixel 3a (SDM670) (sargo)</li>
<li>Google Pixel 3a XL SDC panel (SDM670) (bonito-sdc)</li>
<li>Google Pixel 3a XL Tianma panel (SDM670) (bonito-tianma)</li>
<li>Google Pixel 4a (SDM730) (sunfish)</li>
<li>LG G7 ThinQ (SDM845) (judyln)</li>
<li>LG V35 ThinQ (SDM845) (judyp)</li>
<li>Samsung Galaxy S9 China (SDM845) (starqltechn)</li>
<li>SHIFTphone 8 (QCM6490) (otter)</li>
<li>Sony Xperia 10 III (SM6350) (pdx213)</li>
<li>Sony Xperia XZ2 (SDM845) (xperia-tama-apollo)</li>
<li>Sony Xperia XZ2 Compact (SDM845) (xperia-tama-akari)</li>
<li>Sony Xperia XZ2 Premium (SDM845) (xperia-tama-akatsuki)</li>
<li>Xiaomi Mi 10T Lite (SM7225) (toco)</li>
<li>Xiaomi Mi 9 Pro 5G (SM8150) (tucana)</li>
<li>Xiaomi Mi 9T Pro Samsung panel (SM8150) (davinci-samsung)</li>
<li>Xiaomi Mi 9T Pro Visionox panel (SM8150) (davinci-visionox)</li>
<li>Xiaomi Mi Mix 2S (SDM845) (polaris)</li>
<li>Xiaomi Poco X3 Huaxing panel (SM7150) (surya-huaxing)</li>
<li>Xiaomi Poco X3 Tianma panel (SM7150) (surya-tianma)</li>
<li>Xiaomi Redmi Note 10 Pro (SM7150) (sweet)</li>
</ul>
<h3>NetHunter Podcast Episode 3</h3>
<p><a href="https://gitlab.com/yesimxev">@yesimxev</a> and <a href="https://www.linkedin.com/in/kristopher-wilson-208b59123">@Kristopher Wilson</a> joined for a discussion about NetHunter in cars, and leveraging AI for Bug Bounty projects and more.</p>
<div>

</div>
<h2>Kali Website Updates</h2>
<p>Since our last release, Kali 2026.1, we have been keeping the website and documentation up-to-date. Here is a quick summary of what has changed.</p>
<h3>Kali Documentation</h3>
<p>Most of the <a href="https://www.kali.org/docs/">documentation</a> updates this cycle are around NetHunter device support and the new APT sources format. Pages which got something more than a tweak:</p>
<ul>
<li><a href="https://www.kali.org/docs/development/live-build-a-custom-kali-iso/">Creating A Custom Kali ISO</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/troubleshooting/handling-common-apt-errors/">Handling common APT problems</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-samsung-galaxy-s10/">Installing NetHunter on the Samsung Galaxy S10</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-ticwatch-pro-3/">Installing NetHunter on the TicWatch Pro 3</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-ticwatch-pro/">Installing NetHunter on the TicWatch Pro</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-xiaomi-mi-a2/">Installing NetHunter on the Xiaomi Mi A2</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/nethunter/installing-nethunter-on-the-xiaomi-mi-a3/">Installing NetHunter on the Xiaomi Mi A3</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/nethunter/">Kali NetHunter</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/general-use/kali-apt-sources/">Kali Network Repositories (/etc/apt/sources.list)</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/introduction/default-credentials/">Kali’s Default Credentials</a> <em>(updated)</em></li>
<li><a href="https://www.kali.org/docs/community/submitting-issues-kali-bug-tracker/">Submitting Bugs for Kali Linux</a> <em>(updated)</em></li>
</ul>
<p>We also want to say a little thank you to the following for their work on the sites:</p>
<ul>
<li><a href="https://gitlab.com/chrisjr404">@Chris Southerland Jr</a></li>
<li><a href="https://gitlab.com/mr00k3">@mr00k3</a></li>
<li><a href="https://gitlab.com/Simeon53424">@Simeon_YT</a></li>
<li><a href="https://gitlab.com/V0lk3n">@V0lk3n</a></li>
</ul>
<p>Anyone can help out, anyone can get <a href="https://www.kali.org/docs/community/contribute/">involved</a>!</p>
<h3>New Kali Mirrors</h3>
<p>We welcomed <strong>1 new mirror</strong> during this release cycle, but that’s a significant one: <strong>our first mirror in Africa!</strong> Hoping that many others will follow ;)</p>
<p>The mirror is located in <strong>South Africa</strong>, online at <a href="https://mirror.africloud.com/kali/">mirror.africloud.com</a>. It is sponsored by <a href="https://africloud.com/">AFRICLOUD</a>, and was setup thanks to Oluniyi Ajao.</p>
<p>If you have the disk space and bandwidth, <a href="https://www.kali.org/docs/community/setting-up-a-kali-linux-mirror/">we always welcome new mirrors</a>.</p>
<hr>
<h2>Get Kali Linux 2026.2</h2>
<p><strong>Fresh Images</strong></p>
<p>So what’s stopping you? Go and <a href="https://www.kali.org/get-kali/">get Kali</a> already!</p>
<p>If you cannot wait for the next release, we also produce <strong><a href="https://cdimage.kali.org/kali-images/kali-weekly/">weekly builds</a></strong> which include the latest packages at the time of download, meaning fewer updates needed on first boot. These are automated builds rather than QA’d releases like our standard <a href="https://www.kali.org/releases/">release images</a>, but we still welcome <a href="https://bugs.kali.org/">bug reports</a> on them. The earlier we catch issues, the sooner they get fixed.</p>
<p><strong>Existing Installs</strong></p>
<p>Using Kali already? Great! You can <a href="https://www.kali.org/docs/general-use/updating-kali/">keep it up-to-date</a> by doing:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ sudo tee /etc/apt/sources.list.d/kali.sources &lt;&lt; 'EOF'
Types: deb
URIs: http://http.kali.org/kali/
Suites: kali-rolling
Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/kali-archive-keyring.gpg
EOF
[...]
┌──(kali㉿kali)-[~]
└─$ sudo apt update &amp;&amp; sudo apt -y full-upgrade
[...]
┌──(kali㉿kali)-[~]
└─$ cp -vrbi /etc/skel/. ~/
[...]
┌──(kali㉿kali)-[~]
└─$ sudo reboot -f
</code></pre>
<p><em>Remember, we recommend doing <a href="https://www.kali.org/blog/kali-linux-2026-2-release/#disruptive-package-updates">a reboot for this release</a>!</em></p>
<p>You should now be on Kali Linux 2026.2. We can double check this by doing:</p>
<pre><code class="language-console">┌──(kali㉿kali)-[~]
└─$ grep VERSION /etc/os-release
VERSION="2026.2"
VERSION_ID="2026.2"
VERSION_CODENAME="kali-rolling"
┌──(kali㉿kali)-[~]
└─$ uname -v
#1 SMP PREEMPT_DYNAMIC Kali 6.19.14-1+kali1 (2026-05-05)
┌──(kali㉿kali)-[~]
└─$ uname -r
6.19.14+kali-amd64
</code></pre>
<p><em>NOTE: The output of <code>uname -r</code> may be different depending on the system <a href="https://pkg.kali.org/pkg/linux">architecture</a>.</em></p>
<hr>
<p>As always, if you run into anything broken, please <a href="https://bugs.kali.org/">report it</a>. <em>We will never be able to fix what we do not know is broken!</em> <strong>And Social networks are not bug trackers!</strong></p>
<hr>
<p>Want to keep up-to-date easier? We’ve got you!</p>
<ul>
<li><a href="https://www.kali.org/blog/">Blog</a>? Use our <a href="https://www.kali.org/rss.xml">RSS feed</a> and <a href="https://www.kali.org/newsletter/">newsletter</a></li>
<li><a href="https://www.kali.org/get-kali/">Download</a>? We have a <a href="https://www.kali.org/torrents.xml">Torrent RSS feed</a></li>
<li><a href="https://www.kali.org/docs/community/list-of-official-kali-sites/#social-media-networks">Socials</a>? <a href="https://bsky.app/profile/kalilinux.bsky.social">Bluesky</a>, <a href="https://www.facebook.com/KaliLinux/">Facebook</a>, <a href="https://www.instagram.com/kalilinux/">Instagram</a>, <a href="https://infosec.exchange/@kalilinux">Mastodon</a> &amp; <a href="https://x.com/kalilinux">X</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Run a 30-year old version of GIMP on modern Linux via Flatpak]]></title>
<description><![CDATA[Every wondered what GIMP looked like in 1996, before GTK? Well, now you can. Developer balooii has packaged GIMP 0.54 as a Flatpak that runs on modern 64-bit Linux desktops with Wayland. It’s apparently the earliest version of the app with the source code still available to build. It’s not an off...]]></description>
<link>https://tsecurity.de/de/3631756/linux-tipps/run-a-30-year-old-version-of-gimp-on-modern-linux-via-flatpak/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631756/linux-tipps/run-a-30-year-old-version-of-gimp-on-modern-linux-via-flatpak/</guid>
<pubDate>Mon, 29 Jun 2026 03:39:42 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Every wondered what GIMP looked like in 1996, before GTK? Well, now you can. Developer balooii has packaged GIMP 0.54 as a Flatpak that runs on modern 64-bit Linux desktops with Wayland. It’s apparently the earliest version of the app with the source code still available to build. It’s not an official GIMP effort, but an enthusiast project hosted on the GNOME GitLab. It’s also something of a work-in-progress package of an ancient work-in-progress beta release, with the maintainer promising more plugins and tutorials in time. Before we get to the install bit, there is a bit of trivia-laden history […]</p>
<p>You're reading <a href="https://www.omgubuntu.co.uk/2026/06/gimp-1996-flatpak">Run a 30-year old version of GIMP on modern Linux via Flatpak</a>, a blog post from <a href="https://www.omgubuntu.co.uk/">OMG! Ubuntu</a>. Do not reproduce elsewhere without permission.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Stable Update] 2026-06-26 - Kernels, Systemd, PipeWire, NVIDIA, KDE, LibreOffice]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected end of June, Mid of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you...]]></description>
<link>https://tsecurity.de/de/3626452/unix-server/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626452/unix-server/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/</guid>
<pubDate>Fri, 26 Jun 2026 08:16:20 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected end of June, Mid of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may found thus far.</p>
<h3><a name="p-862931-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-862931-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-862931-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-862931-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/188521/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/188521/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/188521/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/188521/1">(click for more details)</a>
<h2><a name="p-862931-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-862931-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>Kernels</strong> got updated
<ul>
<li>introducing <strong>linux72</strong> series</li>
</ul>
</li>
<li><strong>Systemd</strong> <a href="https://github.com/systemd/systemd/compare/v260.1...v260.2">260.2</a></li>
<li><strong>PipeWire</strong> <a href="https://gitlab.freedesktop.org/pipewire/pipewire/-/releases/1.6.6">1.6.6</a></li>
<li><strong>COSMIC</strong> Epoch <a href="https://github.com/pop-os/cosmic-epoch/releases/tag/epoch-1.0.16">1.0.16</a></li>
<li><strong>NVIDIA</strong> <a href="https://www.nvidia.com/en-us/drivers/details/271414/">610.43.02</a></li>
<li><strong>VLC</strong> <a href="https://images.videolan.org/vlc/releases/3.0.23.html">3.0.23_2</a></li>
<li><strong>Arkdep</strong> <a href="https://github.com/arkanelinux/arkdep/compare/2025.12.18...2026.06.10">20260610</a></li>
<li><strong>Xorg-Server</strong> <a href="https://lists.x.org/archives/xorg-announce/2026-June/003702.html">21.1.23</a></li>
<li><strong>KDE Gear</strong> <a href="https://kde.org/announcements/gear/26.04.2/">26.04.2</a></li>
<li><strong>KDE Frameworks</strong> <a href="https://kde.org/announcements/frameworks/6/6.27.0/">6.27.0</a></li>
<li><strong>LibreOffice</strong> <a href="https://blog.documentfoundation.org/blog/2026/06/05/tdf-releases-libreoffice-26-2-4/">26.2.4</a></li>
<li><strong>QEmu</strong> <a href="https://www.qemu.org/2026/04/22/qemu-11-0-0/">11.0.1</a></li>
</ul>
<h2><a name="p-862931-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-862931-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/188521/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/188521/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.176</li>
<li>linux66 6.6.143</li>
<li>linux612 6.12.94</li>
<li>linux618 6.18.36</li>
<li>linux70 7.0.13</li>
<li>linux71 7.1.1</li>
<li>linux72 7.2.0-rc0</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (Tue Jun 16 2026 12:41:23 GMT+0000)</p>
<ul>
<li>stable core x86_64:  50 new and 49 removed package(s)</li>
<li>stable extra x86_64:  3915 new and 3839 removed package(s)</li>
<li>stable multilib x86_64:  50 new and 50 removed package(s)</li>
</ul>
<p>A list of all package changes can be found <a href="https://termbin.com/37b6">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/188521/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/stable-update-2026-06-26-kernels-systemd-pipewire-nvidia-kde-libreoffice/188521">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-11379 | GitLab Enterprise Edition up to 18.11.5/19.0.2/19.1.0 authorization (Nessus ID 322739)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in GitLab Enterprise Edition up to 18.11.5/19.0.2/19.1.0. Affected is an unknown function. This manipulation causes incorrect authorization.

The identification of this vulnerability is CVE-2026-11379. It is possible to initiate the atta...]]></description>
<link>https://tsecurity.de/de/3624541/sicherheitsluecken/cve-2026-11379-gitlab-enterprise-edition-up-to-1811519021910-authorization-nessus-id-322739/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624541/sicherheitsluecken/cve-2026-11379-gitlab-enterprise-edition-up-to-1811519021910-authorization-nessus-id-322739/</guid>
<pubDate>Thu, 25 Jun 2026 14:40:10 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/gitlab:enterprise_edition">GitLab Enterprise Edition up to 18.11.5/19.0.2/19.1.0</a>. Affected is an unknown function. This manipulation causes incorrect authorization.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-11379">CVE-2026-11379</a>. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-12635 | GitLab Community Edition/Enterprise Edition up to 18.11.5/19.0.2/19.1.0 URL Validation dns rebinding (Nessus ID 322745)]]></title>
<description><![CDATA[A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.11.5/19.0.2/19.1.0 and classified as problematic. Impacted is an unknown function of the component URL Validation Handler. Such manipulation leads to reliance on reverse dns resolution.

This vulnerability is tr...]]></description>
<link>https://tsecurity.de/de/3624441/sicherheitsluecken/cve-2026-12635-gitlab-community-editionenterprise-edition-up-to-1811519021910-url-validation-dns-rebinding-nessus-id-322745/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624441/sicherheitsluecken/cve-2026-12635-gitlab-community-editionenterprise-edition-up-to-1811519021910-url-validation-dns-rebinding-nessus-id-322745/</guid>
<pubDate>Thu, 25 Jun 2026 14:08:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 18.11.5/19.0.2/19.1.0</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Impacted is an unknown function of the component <em>URL Validation Handler</em>. Such manipulation leads to reliance on reverse dns resolution.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-12635">CVE-2026-12635</a>. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab Patches Code Execution, Information Disclosure Vulnerabilities]]></title>
<description><![CDATA[The latest GitLab CE/EE updates address 13 vulnerabilities, including three high-severity defects. The post GitLab Patches Code Execution, Information Disclosure Vulnerabilities appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: GitLab Patch...]]></description>
<link>https://tsecurity.de/de/3624302/it-security-nachrichten/gitlab-patches-code-execution-information-disclosure-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624302/it-security-nachrichten/gitlab-patches-code-execution-information-disclosure-vulnerabilities/</guid>
<pubDate>Thu, 25 Jun 2026 13:38:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The latest GitLab CE/EE updates address 13 vulnerabilities, including three high-severity defects. The post GitLab Patches Code Execution, Information Disclosure Vulnerabilities appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: GitLab Patches Code Execution,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/gitlab-patches-code-execution-information-disclosure-vulnerabilities/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/gitlab-patches-code-execution-information-disclosure-vulnerabilities/">GitLab Patches Code Execution, Information Disclosure Vulnerabilities</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab Patches Code Execution, Information Disclosure Vulnerabilities]]></title>
<description><![CDATA[The latest GitLab CE/EE updates address 13 vulnerabilities, including three high-severity defects.
The post GitLab Patches Code Execution, Information Disclosure Vulnerabilities appeared first on SecurityWeek.]]></description>
<link>https://tsecurity.de/de/3624269/it-security-nachrichten/gitlab-patches-code-execution-information-disclosure-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624269/it-security-nachrichten/gitlab-patches-code-execution-information-disclosure-vulnerabilities/</guid>
<pubDate>Thu, 25 Jun 2026 13:23:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The latest GitLab CE/EE updates address 13 vulnerabilities, including three high-severity defects.</p>
<p>The post <a href="https://www.securityweek.com/gitlab-patches-code-execution-information-disclosure-vulnerabilities/">GitLab Patches Code Execution, Information Disclosure Vulnerabilities</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-12053 | GitLab Enterprise Edition up to 19.1.0 log file (Nessus ID 322750)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in GitLab Enterprise Edition up to 19.1.0. This vulnerability affects unknown code. The manipulation results in sensitive information in log files.

This vulnerability is reported as CVE-2026-12053. The attack can be launched remotel...]]></description>
<link>https://tsecurity.de/de/3624219/sicherheitsluecken/cve-2026-12053-gitlab-enterprise-edition-up-to-1910-log-file-nessus-id-322750/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624219/sicherheitsluecken/cve-2026-12053-gitlab-enterprise-edition-up-to-1910-log-file-nessus-id-322750/</guid>
<pubDate>Thu, 25 Jun 2026 13:09:32 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/gitlab:enterprise_edition">GitLab Enterprise Edition up to 19.1.0</a>. This vulnerability affects unknown code. The manipulation results in sensitive information in log files.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-12053">CVE-2026-12053</a>. The attack can be launched remotely. No exploit exists.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [hoch] GitLab CE/EE: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.]]></description>
<link>https://tsecurity.de/de/3624048/it-security-nachrichten/neu-hoch-gitlab-ceee-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624048/it-security-nachrichten/neu-hoch-gitlab-ceee-mehrere-schwachstellen/</guid>
<pubDate>Thu, 25 Jun 2026 12:08:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10086 | GitLab Enterprise Edition up to 18.11.5/19.0.2/19.1.0 cross site scripting (EUVD-2026-39181)]]></title>
<description><![CDATA[A vulnerability was found in GitLab Enterprise Edition up to 18.11.5/19.0.2/19.1.0. It has been rated as problematic. This affects an unknown function. The manipulation leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2026-10086. The attack is possible to be carrie...]]></description>
<link>https://tsecurity.de/de/3623979/sicherheitsluecken/cve-2026-10086-gitlab-enterprise-edition-up-to-1811519021910-cross-site-scripting-euvd-2026-39181/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623979/sicherheitsluecken/cve-2026-10086-gitlab-enterprise-edition-up-to-1811519021910-cross-site-scripting-euvd-2026-39181/</guid>
<pubDate>Thu, 25 Jun 2026 11:40:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gitlab:enterprise_edition">GitLab Enterprise Edition up to 18.11.5/19.0.2/19.1.0</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown function. The manipulation leads to cross site scripting.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-10086">CVE-2026-10086</a>. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-0934 | GitLab Enterprise Edition up to 18.11.5/19.0.2/19.1.0 authorization (EUVD-2026-39179)]]></title>
<description><![CDATA[A vulnerability was found in GitLab Enterprise Edition up to 18.11.5/19.0.2/19.1.0. It has been declared as problematic. The impacted element is an unknown function. Executing a manipulation can lead to incorrect authorization.

This vulnerability is handled as CVE-2026-0934. The attack can be ex...]]></description>
<link>https://tsecurity.de/de/3623978/sicherheitsluecken/cve-2026-0934-gitlab-enterprise-edition-up-to-1811519021910-authorization-euvd-2026-39179/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623978/sicherheitsluecken/cve-2026-0934-gitlab-enterprise-edition-up-to-1811519021910-authorization-euvd-2026-39179/</guid>
<pubDate>Thu, 25 Jun 2026 11:40:03 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gitlab:enterprise_edition">GitLab Enterprise Edition up to 18.11.5/19.0.2/19.1.0</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. The impacted element is an unknown function. Executing a manipulation can lead to incorrect authorization.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-0934">CVE-2026-0934</a>. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-1606 | GitLab Community Edition/Enterprise Edition up to 18.11.5/19.0.2/19.1.0 code injection (EUVD-2026-39178)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in GitLab Community Edition and Enterprise Edition up to 18.11.5/19.0.2/19.1.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to code injection.

This vulnerability is referenced as CVE-2026-1606. It is possi...]]></description>
<link>https://tsecurity.de/de/3623977/sicherheitsluecken/cve-2026-1606-gitlab-community-editionenterprise-edition-up-to-1811519021910-code-injection-euvd-2026-39178/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623977/sicherheitsluecken/cve-2026-1606-gitlab-community-editionenterprise-edition-up-to-1811519021910-code-injection-euvd-2026-39178/</guid>
<pubDate>Thu, 25 Jun 2026 11:40:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 18.11.5/19.0.2/19.1.0</a>. Affected by this vulnerability is an unknown functionality. Such manipulation leads to code injection.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-1606">CVE-2026-1606</a>. It is possible to launch the attack remotely. No exploit is available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-2238 | GitLab Community Edition/Enterprise Edition up to 18.11.5/19.0.2/19.1.0 Public Project authorization (EUVD-2026-39177)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in GitLab Community Edition and Enterprise Edition up to 18.11.5/19.0.2/19.1.0. Affected by this issue is some unknown functionality of the component Public Project Handler. Performing a manipulation results in missing authorization.

This v...]]></description>
<link>https://tsecurity.de/de/3623976/sicherheitsluecken/cve-2026-2238-gitlab-community-editionenterprise-edition-up-to-1811519021910-public-project-authorization-euvd-2026-39177/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623976/sicherheitsluecken/cve-2026-2238-gitlab-community-editionenterprise-edition-up-to-1811519021910-public-project-authorization-euvd-2026-39177/</guid>
<pubDate>Thu, 25 Jun 2026 11:40:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 18.11.5/19.0.2/19.1.0</a>. Affected by this issue is some unknown functionality of the component <em>Public Project Handler</em>. Performing a manipulation results in missing authorization.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-2238">CVE-2026-2238</a>. The attack can be initiated remotely. There is not any exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-3176 | GitLab Enterprise Edition up to 18.11.5/19.0.2/19.1.0 authorization (EUVD-2026-39176)]]></title>
<description><![CDATA[A vulnerability was found in GitLab Enterprise Edition up to 18.11.5/19.0.2/19.1.0. It has been classified as problematic. The affected element is an unknown function. Performing a manipulation results in missing authorization.

This vulnerability is known as CVE-2026-3176. Remote exploitation of...]]></description>
<link>https://tsecurity.de/de/3623975/sicherheitsluecken/cve-2026-3176-gitlab-enterprise-edition-up-to-1811519021910-authorization-euvd-2026-39176/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623975/sicherheitsluecken/cve-2026-3176-gitlab-enterprise-edition-up-to-1811519021910-authorization-euvd-2026-39176/</guid>
<pubDate>Thu, 25 Jun 2026 11:39:59 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gitlab:enterprise_edition">GitLab Enterprise Edition up to 18.11.5/19.0.2/19.1.0</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. The affected element is an unknown function. Performing a manipulation results in missing authorization.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-3176">CVE-2026-3176</a>. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-5309 | GitLab Enterprise Edition up to 18.11.5/19.0.2/19.1.0 authorization (EUVD-2026-39175)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in GitLab Enterprise Edition up to 18.11.5/19.0.2/19.1.0. This affects an unknown part. Executing a manipulation can lead to authorization bypass.

This vulnerability is tracked as CVE-2026-5309. The attack can be launched remotely. No exp...]]></description>
<link>https://tsecurity.de/de/3623974/sicherheitsluecken/cve-2026-5309-gitlab-enterprise-edition-up-to-1811519021910-authorization-euvd-2026-39175/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623974/sicherheitsluecken/cve-2026-5309-gitlab-enterprise-edition-up-to-1811519021910-authorization-euvd-2026-39175/</guid>
<pubDate>Thu, 25 Jun 2026 11:39:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/gitlab:enterprise_edition">GitLab Enterprise Edition up to 18.11.5/19.0.2/19.1.0</a>. This affects an unknown part. Executing a manipulation can lead to authorization bypass.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-5309">CVE-2026-5309</a>. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-5796 | GitLab Community Edition/Enterprise Edition up to 18.11.5/19.0.2/19.1.0 Group Packages Feature authorization (EUVD-2026-39174)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in GitLab Community Edition and Enterprise Edition up to 18.11.5/19.0.2/19.1.0. This vulnerability affects unknown code of the component Group Packages Feature. The manipulation leads to incorrect authorization.

This vulnerability is liste...]]></description>
<link>https://tsecurity.de/de/3623972/sicherheitsluecken/cve-2026-5796-gitlab-community-editionenterprise-edition-up-to-1811519021910-group-packages-feature-authorization-euvd-2026-39174/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623972/sicherheitsluecken/cve-2026-5796-gitlab-community-editionenterprise-edition-up-to-1811519021910-group-packages-feature-authorization-euvd-2026-39174/</guid>
<pubDate>Thu, 25 Jun 2026 11:39:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 18.11.5/19.0.2/19.1.0</a>. This vulnerability affects unknown code of the component <em>Group Packages Feature</em>. The manipulation leads to incorrect authorization.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-5796">CVE-2026-5796</a>. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-5952 | GitLab Community Edition/Enterprise Edition up to 18.11.5/19.0.2/19.1.0 authorization (EUVD-2026-39173)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in GitLab Community Edition and Enterprise Edition up to 18.11.5/19.0.2/19.1.0. This issue affects some unknown processing. The manipulation results in incorrect authorization.

This vulnerability is cataloged as CVE-2026-5952. The attack may be...]]></description>
<link>https://tsecurity.de/de/3623971/sicherheitsluecken/cve-2026-5952-gitlab-community-editionenterprise-edition-up-to-1811519021910-authorization-euvd-2026-39173/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623971/sicherheitsluecken/cve-2026-5952-gitlab-community-editionenterprise-edition-up-to-1811519021910-authorization-euvd-2026-39173/</guid>
<pubDate>Thu, 25 Jun 2026 11:39:54 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 18.11.5/19.0.2/19.1.0</a>. This issue affects some unknown processing. The manipulation results in incorrect authorization.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-5952">CVE-2026-5952</a>. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-8330 | GitLab Community Edition/Enterprise Edition up to 18.11.5/19.0.2/19.1.0 CD API Endpoint log file (EUVD-2026-39172)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in GitLab Community Edition and Enterprise Edition up to 18.11.5/19.0.2/19.1.0. Impacted is an unknown function of the component CD API Endpoint. This manipulation causes sensitive information in log files.

This vulnerability i...]]></description>
<link>https://tsecurity.de/de/3623970/sicherheitsluecken/cve-2026-8330-gitlab-community-editionenterprise-edition-up-to-1811519021910-cd-api-endpoint-log-file-euvd-2026-39172/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623970/sicherheitsluecken/cve-2026-8330-gitlab-community-editionenterprise-edition-up-to-1811519021910-cd-api-endpoint-log-file-euvd-2026-39172/</guid>
<pubDate>Thu, 25 Jun 2026 11:39:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 18.11.5/19.0.2/19.1.0</a>. Impacted is an unknown function of the component <em>CD API Endpoint</em>. This manipulation causes sensitive information in log files.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-8330">CVE-2026-8330</a>. The attack needs to be launched locally. No exploit is available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10712 | GitLab Community Edition/Enterprise Edition up to 18.11.5/19.0.2/19.1.0 Path Validation cross site scripting (EUVD-2026-39171)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in GitLab Community Edition and Enterprise Edition up to 18.11.5/19.0.2/19.1.0. This impacts an unknown function of the component Path Validation Handler. The manipulation results in cross site scripting.

This vulnerability was named...]]></description>
<link>https://tsecurity.de/de/3623969/sicherheitsluecken/cve-2026-10712-gitlab-community-editionenterprise-edition-up-to-1811519021910-path-validation-cross-site-scripting-euvd-2026-39171/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623969/sicherheitsluecken/cve-2026-10712-gitlab-community-editionenterprise-edition-up-to-1811519021910-path-validation-cross-site-scripting-euvd-2026-39171/</guid>
<pubDate>Thu, 25 Jun 2026 11:39:51 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 18.11.5/19.0.2/19.1.0</a>. This impacts an unknown function of the component <em>Path Validation Handler</em>. The manipulation results in cross site scripting.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-10712">CVE-2026-10712</a>. The attack may be performed from remote. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[2026-06-24, Version 26.4.0 (Current), @aduh95]]></title>
<description><![CDATA[Notable Changes

[cde0daabcc] - (SEMVER-MINOR) doc: update blockList stability status to release candidate (alphaleadership) #63050
[b78f5a7537] - (SEMVER-MINOR) fs: support caller-supplied readFile() buffers (Matteo Collina) #63634
[417aacbc36] - (SEMVER-MINOR) http: close pre-request sockets in...]]></description>
<link>https://tsecurity.de/de/3623069/downloads/2026-06-24-version-2640-current-aduh95/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623069/downloads/2026-06-24-version-2640-current-aduh95/</guid>
<pubDate>Thu, 25 Jun 2026 01:46:32 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Notable Changes</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/cde0daabcc"><code>cde0daabcc</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>doc</strong>: update <code>blockList</code> stability status to release candidate (alphaleadership) <a href="https://github.com/nodejs/node/pull/63050" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63050/hovercard">#63050</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b78f5a7537"><code>b78f5a7537</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>fs</strong>: support caller-supplied <code>readFile()</code> buffers (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63634" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63634/hovercard">#63634</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/417aacbc36"><code>417aacbc36</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>http</strong>: close pre-request sockets in <code>closeIdleConnections</code> (semimikoh) <a href="https://github.com/nodejs/node/pull/63470" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63470/hovercard">#63470</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fbb108be7d"><code>fbb108be7d</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>loader</strong>: implement package maps (Maël Nison) <a href="https://github.com/nodejs/node/pull/62239" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62239/hovercard">#62239</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/45494d5a8a"><code>45494d5a8a</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>net</strong>: support <code>TCP_KEEPINTVL</code> and <code>TCP_KEEPCNT</code> in <code>setKeepAlive</code> (Guy Bedford) <a href="https://github.com/nodejs/node/pull/63825" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63825/hovercard">#63825</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ee29465e77"><code>ee29465e77</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>tls</strong>: add certificateCompression option (Tim Perry) <a href="https://github.com/nodejs/node/pull/62217" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62217/hovercard">#62217</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b17817eb2b"><code>b17817eb2b</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>vfs</strong>: dispatch <code>node:fs/promises</code> to mounted VFS instances (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63537" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63537/hovercard">#63537</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7bc93a6ac5"><code>7bc93a6ac5</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>vfs</strong>: add minimal <code>node:vfs</code> subsystem (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63115" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63115/hovercard">#63115</a></li>
</ul>
<h3>Commits</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/c7eb83b46a"><code>c7eb83b46a</code></a>] - <strong>benchmark</strong>: add child_process async path baselines (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/63929" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63929/hovercard">#63929</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/066fff17a5"><code>066fff17a5</code></a>] - <strong>benchmark</strong>: remove old alias usage in ffi benchmarks (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/63666" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63666/hovercard">#63666</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/509cd1b94f"><code>509cd1b94f</code></a>] - <strong>buffer</strong>: optimize Buffer.prototype.copy (Robert Nagy) <a href="https://github.com/nodejs/node/pull/63828" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63828/hovercard">#63828</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/86e651bbd0"><code>86e651bbd0</code></a>] - <strong>buffer</strong>: use simdutf for two-byte utf8 byteLength (Mert Can Altin) <a href="https://github.com/nodejs/node/pull/63639" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63639/hovercard">#63639</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d3f4ed9015"><code>d3f4ed9015</code></a>] - <strong>build</strong>: suppress compiler warnings for histogram (Richard Lau) <a href="https://github.com/nodejs/node/pull/63980" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63980/hovercard">#63980</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/82dd7ddbe6"><code>82dd7ddbe6</code></a>] - <strong>build</strong>: add QUIC CI job for PRs matching QUIC related paths (Tim Perry) <a href="https://github.com/nodejs/node/pull/63875" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63875/hovercard">#63875</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1124c0652d"><code>1124c0652d</code></a>] - <strong>build</strong>: remove redundant intermediate node_aix_shared (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63747" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63747/hovercard">#63747</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e510ee8087"><code>e510ee8087</code></a>] - <strong>build</strong>: build codecache and snapshot with libnode (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63626" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63626/hovercard">#63626</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5b583dace5"><code>5b583dace5</code></a>] - <strong>build</strong>: enable maglev by default on Linux ppc64le (Richard Lau) <a href="https://github.com/nodejs/node/pull/63474" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63474/hovercard">#63474</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a2324246b4"><code>a2324246b4</code></a>] - <strong>build</strong>: remove duplicated node_use_sqlite and node_use_ffi conditions (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63629" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63629/hovercard">#63629</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2a467a5f69"><code>2a467a5f69</code></a>] - <em><strong>Revert</strong></em> "<strong>build, doc</strong>: generate node.1 with doc-kit" (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/64091" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64091/hovercard">#64091</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e01dec45b8"><code>e01dec45b8</code></a>] - <strong>build, doc</strong>: generate node.1 with doc-kit (Aviv Keller) <a href="https://github.com/nodejs/node/pull/62044" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62044/hovercard">#62044</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2ab9848fe4"><code>2ab9848fe4</code></a>] - <strong>child_process</strong>: pass spawn options to the binding positionally (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/63930" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63930/hovercard">#63930</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/04c04c8b5c"><code>04c04c8b5c</code></a>] - <strong>child_process</strong>: serialize advanced IPC messages natively (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/63933" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63933/hovercard">#63933</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1eef57293d"><code>1eef57293d</code></a>] - <strong>crypto</strong>: support non-byte WebCrypto lengths and cSHAKE (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63988" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63988/hovercard">#63988</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/788a66e147"><code>788a66e147</code></a>] - <strong>crypto</strong>: share WebCrypto method and usage helpers (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63975" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63975/hovercard">#63975</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f9fdce3f46"><code>f9fdce3f46</code></a>] - <strong>crypto</strong>: use EVP_MAC for HMAC on OpenSSL &gt;=3 (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63942" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63942/hovercard">#63942</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7e9ca87e58"><code>7e9ca87e58</code></a>] - <strong>crypto</strong>: make webcrypto aliasKeyFormat directional (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63910" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63910/hovercard">#63910</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/656e57ebbf"><code>656e57ebbf</code></a>] - <strong>crypto</strong>: fix unhandled error in Hash._transform (Haram Jeong) <a href="https://github.com/nodejs/node/pull/63261" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63261/hovercard">#63261</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/65536f0d98"><code>65536f0d98</code></a>] - <strong>crypto</strong>: refactor keyObject.toCryptoKey() and SubtleCrypto.getPublicKey() (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63622" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63622/hovercard">#63622</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/978f1d2bcc"><code>978f1d2bcc</code></a>] - <strong>crypto</strong>: handle cipher context allocation failures (Tian Teng) <a href="https://github.com/nodejs/node/pull/63542" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63542/hovercard">#63542</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5551e8f773"><code>5551e8f773</code></a>] - <strong>crypto</strong>: deduplicate X509 subject matching logic (Tobias Nießen) <a href="https://github.com/nodejs/node/pull/63644" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63644/hovercard">#63644</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/57ae87640a"><code>57ae87640a</code></a>] - <strong>crypto</strong>: fix warnings in test_node_crypto.cc (Maya Lekova) <a href="https://github.com/nodejs/node/pull/63490" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63490/hovercard">#63490</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9984b05dff"><code>9984b05dff</code></a>] - <strong>crypto</strong>: coerce -0 to +0 before native calls (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63556" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63556/hovercard">#63556</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/88011a3689"><code>88011a3689</code></a>] - <strong>crypto,tls</strong>: do not ignore BN_get_word error (Tobias Nießen) <a href="https://github.com/nodejs/node/pull/63895" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63895/hovercard">#63895</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9a3393d14f"><code>9a3393d14f</code></a>] - <strong>debugger</strong>: lazily wait for initial break output (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63969" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63969/hovercard">#63969</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b0bfcb9c59"><code>b0bfcb9c59</code></a>] - <strong>debugger</strong>: defer probe pause handling until startup (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63608" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63608/hovercard">#63608</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8516003953"><code>8516003953</code></a>] - <strong>debugger</strong>: await initialization after run and restart (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63607" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63607/hovercard">#63607</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4438cb5284"><code>4438cb5284</code></a>] - <strong>debugger</strong>: add --max-hit option to probe mode (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63704" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63704/hovercard">#63704</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/238b54ed2a"><code>238b54ed2a</code></a>] - <strong>debugger</strong>: add more logs to probe mode (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63663" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63663/hovercard">#63663</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bbef54b413"><code>bbef54b413</code></a>] - <strong>deps</strong>: libffi: cherry-pick 9ca53a19833d (Anthony Green) <a href="https://github.com/nodejs/node/pull/64040" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64040/hovercard">#64040</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9761385dbd"><code>9761385dbd</code></a>] - <strong>deps</strong>: update libffi to 3.6.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/64040" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64040/hovercard">#64040</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/373ec2d092"><code>373ec2d092</code></a>] - <strong>deps</strong>: update acorn to 8.17.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63901" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63901/hovercard">#63901</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e44b5d487e"><code>e44b5d487e</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>deps</strong>: update OpenSSL build config to support compression (Tim Perry) <a href="https://github.com/nodejs/node/pull/62217" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62217/hovercard">#62217</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3ed287a2e2"><code>3ed287a2e2</code></a>] - <strong>deps</strong>: upgrade npm to 11.17.0 (npm team) <a href="https://github.com/nodejs/node/pull/63857" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63857/hovercard">#63857</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b1b597c797"><code>b1b597c797</code></a>] - <strong>deps</strong>: add ngtcp2_fmt.c to build configuration (ngtcp2.gyp) (沈鸿飞) <a href="https://github.com/nodejs/node/pull/63821" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63821/hovercard">#63821</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0bf8e12305"><code>0bf8e12305</code></a>] - <strong>deps</strong>: V8: add CopyArrayBufferBytes API (Robert Nagy) <a href="https://github.com/nodejs/node/pull/63828" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63828/hovercard">#63828</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e49d7301a5"><code>e49d7301a5</code></a>] - <strong>deps</strong>: update ngtcp2 to 1.23.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63777" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63777/hovercard">#63777</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e5c079004b"><code>e5c079004b</code></a>] - <strong>deps</strong>: update nghttp3 to 1.16.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63776" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63776/hovercard">#63776</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d599fa2346"><code>d599fa2346</code></a>] - <strong>deps</strong>: update googletest to 7140cd416cecd7462a8aae488024abeee55598e4 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63775" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63775/hovercard">#63775</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bc09f1508c"><code>bc09f1508c</code></a>] - <strong>deps</strong>: update sqlite to 3.53.2 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63774" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63774/hovercard">#63774</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/60787746c4"><code>60787746c4</code></a>] - <strong>deps</strong>: update zlib to 1.3.2.1-motley-3246f1b (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63773" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63773/hovercard">#63773</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/971af104f1"><code>971af104f1</code></a>] - <strong>deps</strong>: update amaro to 1.1.10 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63670" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63670/hovercard">#63670</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e17f665444"><code>e17f665444</code></a>] - <strong>deps</strong>: update googletest to 8736d2cd5c1dcba41170ed2fddca14021d4916c3 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63669" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63669/hovercard">#63669</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7591949457"><code>7591949457</code></a>] - <strong>dgram</strong>: add synchronous Socket connectSync() (Guy Bedford) <a href="https://github.com/nodejs/node/pull/63932" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63932/hovercard">#63932</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d75222d7cb"><code>d75222d7cb</code></a>] - <strong>dgram</strong>: add synchronous Socket.prototype.bindSync() (Guy Bedford) <a href="https://github.com/nodejs/node/pull/63838" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63838/hovercard">#63838</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0cf8342ae2"><code>0cf8342ae2</code></a>] - <strong>dns</strong>: coerce -0 to +0 in lookup and resolver inputs (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63556" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63556/hovercard">#63556</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e068299320"><code>e068299320</code></a>] - <strong>doc</strong>: update gcc toolchains to <code>gcc-13</code> and <code>g++-13</code> (Louie Llaneta) <a href="https://github.com/nodejs/node/pull/64018" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64018/hovercard">#64018</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/65178bdcf3"><code>65178bdcf3</code></a>] - <strong>doc</strong>: add aduh95 to last security release steward (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63981" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63981/hovercard">#63981</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/83eedfe85b"><code>83eedfe85b</code></a>] - <strong>doc</strong>: fix typo in util.md (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63961" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63961/hovercard">#63961</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/54948c78e7"><code>54948c78e7</code></a>] - <strong>doc</strong>: clarify callback exceptions (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63939" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63939/hovercard">#63939</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/205d0a57f2"><code>205d0a57f2</code></a>] - <strong>doc</strong>: fix incorrect test runner mock examples (Kimaswa Emmanuel Yusufu) <a href="https://github.com/nodejs/node/pull/63656" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63656/hovercard">#63656</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/44809b176c"><code>44809b176c</code></a>] - <strong>doc</strong>: clarify fromReadable() duck-typed contract (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63682" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63682/hovercard">#63682</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9cb15fcc85"><code>9cb15fcc85</code></a>] - <strong>doc</strong>: fix typo in cli.md (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63883" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63883/hovercard">#63883</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/394d0bb928"><code>394d0bb928</code></a>] - <strong>doc</strong>: fix typo in vm.md (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63881" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63881/hovercard">#63881</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/59b7be8193"><code>59b7be8193</code></a>] - <strong>doc</strong>: fix typo in packages.md (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63882" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63882/hovercard">#63882</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/33c236cea9"><code>33c236cea9</code></a>] - <strong>doc</strong>: fix a/an article typos in module, util, and dns (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63766" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63766/hovercard">#63766</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/30595da67b"><code>30595da67b</code></a>] - <strong>doc</strong>: update npm supported versions link (hojeong park) <a href="https://github.com/nodejs/node/pull/63672" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63672/hovercard">#63672</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5919ba7e97"><code>5919ba7e97</code></a>] - <strong>doc</strong>: fix AES-OCB IV length in SubtleCrypto.supports example (Anshika Jain) <a href="https://github.com/nodejs/node/pull/63717" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63717/hovercard">#63717</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/51cab5cb72"><code>51cab5cb72</code></a>] - <strong>doc</strong>: add webstreams to args for <code>pipeline</code> from <code>stream/promises</code> (David Sanders) <a href="https://github.com/nodejs/node/pull/63628" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63628/hovercard">#63628</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ce85b2af88"><code>ce85b2af88</code></a>] - <strong>doc</strong>: fix "used to sent" → "used to send" in http2 (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63700" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63700/hovercard">#63700</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/298735e8df"><code>298735e8df</code></a>] - <strong>doc</strong>: mark Node.js 25 as End-of-Life (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63692" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63692/hovercard">#63692</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/56948518b9"><code>56948518b9</code></a>] - <strong>doc</strong>: clarify tty raw mode applies to input processing only (Muhammad Zeeshan) <a href="https://github.com/nodejs/node/pull/63438" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63438/hovercard">#63438</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/32ff731248"><code>32ff731248</code></a>] - <strong>doc</strong>: add worker_threads history entries (Bob Put) <a href="https://github.com/nodejs/node/pull/63545" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63545/hovercard">#63545</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cde0daabcc"><code>cde0daabcc</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>doc</strong>: update <code>blockList</code> stability status to release candidate (alphaleadership) <a href="https://github.com/nodejs/node/pull/63050" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63050/hovercard">#63050</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d29483fc4f"><code>d29483fc4f</code></a>] - <strong>doc,crypto</strong>: mark argon2 and encap/decap as stable (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63924" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63924/hovercard">#63924</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6e668331d9"><code>6e668331d9</code></a>] - <strong>events</strong>: improve <code>addAbortListener</code> perf by caching options object (Raz Luvaton) <a href="https://github.com/nodejs/node/pull/52367" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/52367/hovercard">#52367</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/97aafe2519"><code>97aafe2519</code></a>] - <strong>ffi</strong>: add fast support for almost all other platforms (Paolo Insogna) <a href="https://github.com/nodejs/node/pull/63941" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63941/hovercard">#63941</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f52cf5eeaa"><code>f52cf5eeaa</code></a>] - <strong>ffi</strong>: add experimental fast FFI call API for AArch64 and x86_64 (Paolo Insogna) <a href="https://github.com/nodejs/node/pull/63068" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63068/hovercard">#63068</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d9461fee05"><code>d9461fee05</code></a>] - <strong>ffi</strong>: port semi-colon fix for riscv64 (and others) (Stewart X Addison) <a href="https://github.com/nodejs/node/pull/63794" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63794/hovercard">#63794</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4c8402e0a8"><code>4c8402e0a8</code></a>] - <strong>fs</strong>: do not treat EPERM as ENOTEMPTY on Windows (Kirill Saied) <a href="https://github.com/nodejs/node/pull/63709" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63709/hovercard">#63709</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b78f5a7537"><code>b78f5a7537</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>fs</strong>: support caller-supplied readFile() buffers (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63634" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63634/hovercard">#63634</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3d0097d489"><code>3d0097d489</code></a>] - <strong>fs</strong>: prevent spurious recursive watch events on prefix siblings (Marco) <a href="https://github.com/nodejs/node/pull/63095" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63095/hovercard">#63095</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/14d829cb3c"><code>14d829cb3c</code></a>] - <strong>fs</strong>: ignore deleted dirs in recursive watch scan (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63686" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63686/hovercard">#63686</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ceba08a1ea"><code>ceba08a1ea</code></a>] - <strong>fs</strong>: coerce -0 to +0 in mode flags and watch intervals (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63556" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63556/hovercard">#63556</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6577d3b282"><code>6577d3b282</code></a>] - <strong>http</strong>: avoid stream listeners on idle agent sockets (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64004" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64004/hovercard">#64004</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/417aacbc36"><code>417aacbc36</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>http</strong>: close pre-request sockets in closeIdleConnections (semimikoh) <a href="https://github.com/nodejs/node/pull/63470" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63470/hovercard">#63470</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b7fd13a59a"><code>b7fd13a59a</code></a>] - <strong>http2</strong>: retain header memory in session accounting (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63752" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63752/hovercard">#63752</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e611ccd167"><code>e611ccd167</code></a>] - <strong>inspector</strong>: fix inspector.close() documented behavior (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63837" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63837/hovercard">#63837</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a44f51eef3"><code>a44f51eef3</code></a>] - <strong>lib</strong>: fix missing lazyDOMException import (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64033" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64033/hovercard">#64033</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/27cc4ec598"><code>27cc4ec598</code></a>] - <strong>lib</strong>: add lint rule to enforce use of <code>kEmptyObject</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63790" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63790/hovercard">#63790</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7ee31b0bf4"><code>7ee31b0bf4</code></a>] - <strong>lib</strong>: improve control abstraction coverage in frozen intrinsics (Renegade334) <a href="https://github.com/nodejs/node/pull/63698" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63698/hovercard">#63698</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/078457839a"><code>078457839a</code></a>] - <strong>lib</strong>: add Iterator global to primordials (Renegade334) <a href="https://github.com/nodejs/node/pull/63698" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63698/hovercard">#63698</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/58837dc4dd"><code>58837dc4dd</code></a>] - <strong>lib</strong>: remove source map deadcode in type stripping (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63738" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63738/hovercard">#63738</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e7513a8b9e"><code>e7513a8b9e</code></a>] - <strong>lib</strong>: make <code>Navigator#language</code> getter throw on invalid <code>this</code> (Mohamed Sayed) <a href="https://github.com/nodejs/node/pull/63601" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63601/hovercard">#63601</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fbb108be7d"><code>fbb108be7d</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>loader</strong>: implement package maps (Maël Nison) <a href="https://github.com/nodejs/node/pull/62239" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62239/hovercard">#62239</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ea0b8e1dc2"><code>ea0b8e1dc2</code></a>] - <strong>meta</strong>: bump github/codeql-action from 4.35.3 to 4.36.1 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63724" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63724/hovercard">#63724</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ac90719532"><code>ac90719532</code></a>] - <strong>meta</strong>: bump actions/cache from 5.0.4 to 5.0.5 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/62847" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62847/hovercard">#62847</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3ed3de3062"><code>3ed3de3062</code></a>] - <strong>meta</strong>: bump actions/checkout from 6.0.2 to 6.0.3 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63726" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63726/hovercard">#63726</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d08d57bf70"><code>d08d57bf70</code></a>] - <strong>meta</strong>: bump codecov/codecov-action from 6.0.0 to 6.0.1 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63725" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63725/hovercard">#63725</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e748d192cf"><code>e748d192cf</code></a>] - <strong>meta</strong>: bump cachix/cachix-action (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63729" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63729/hovercard">#63729</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/10554eb131"><code>10554eb131</code></a>] - <strong>meta</strong>: bump actions/stale from 10.2.0 to 10.3.0 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63728" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63728/hovercard">#63728</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/791885f2af"><code>791885f2af</code></a>] - <strong>meta</strong>: bump step-security/harden-runner from 2.19.0 to 2.19.4 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63727" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63727/hovercard">#63727</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/32d9a407d9"><code>32d9a407d9</code></a>] - <strong>meta</strong>: bump cachix/install-nix-action from 31.10.5 to 31.10.6 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63723" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63723/hovercard">#63723</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b97c7bed07"><code>b97c7bed07</code></a>] - <strong>module</strong>: enable existing machinery for deferred import of static modules (Maya Lekova) <a href="https://github.com/nodejs/node/pull/63712" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63712/hovercard">#63712</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4becad2117"><code>4becad2117</code></a>] - <strong>module</strong>: use file: URL as sourceURL for type-stripped CommonJS (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63705" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63705/hovercard">#63705</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c71c85b95f"><code>c71c85b95f</code></a>] - <strong>net</strong>: early TCP binding via synchronous net.BoundSocket (Guy Bedford) <a href="https://github.com/nodejs/node/pull/63951" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63951/hovercard">#63951</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/45494d5a8a"><code>45494d5a8a</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>net</strong>: support TCP_KEEPINTVL and TCP_KEEPCNT in setKeepAlive (Guy Bedford) <a href="https://github.com/nodejs/node/pull/63825" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63825/hovercard">#63825</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3988efa1f3"><code>3988efa1f3</code></a>] - <strong>net</strong>: coerce -0 to +0 in BlockList prefixes (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63556" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63556/hovercard">#63556</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/484efd1c44"><code>484efd1c44</code></a>] - <strong>quic</strong>: fix get_reader bug that dropped data on FIN (Tim Perry) <a href="https://github.com/nodejs/node/pull/63946" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63946/hovercard">#63946</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/04a17fe6f0"><code>04a17fe6f0</code></a>] - <strong>quic</strong>: expose QUIC certificates as JS X509Certificate, not raw handles (Tim Perry) <a href="https://github.com/nodejs/node/pull/63191" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63191/hovercard">#63191</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b62d5696dc"><code>b62d5696dc</code></a>] - <strong>quic</strong>: fix reader backpressure deadlock on idle connections (Tim Perry) <a href="https://github.com/nodejs/node/pull/63950" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63950/hovercard">#63950</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3f1c8d7453"><code>3f1c8d7453</code></a>] - <strong>quic</strong>: fix broken listEndpoints export, test callbacks &amp; nghttp3 include (Tim Perry) <a href="https://github.com/nodejs/node/pull/63874" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63874/hovercard">#63874</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d8538b9deb"><code>d8538b9deb</code></a>] - <strong>quic</strong>: impl. cb for http/3 settings/app. options (Marten Richter) <a href="https://github.com/nodejs/node/pull/63558" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63558/hovercard">#63558</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/643b19716e"><code>643b19716e</code></a>] - <strong>quic</strong>: add listEndpoints API (James M Snell) <a href="https://github.com/nodejs/node/pull/63536" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63536/hovercard">#63536</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2bce35bea4"><code>2bce35bea4</code></a>] - <strong>sqlite</strong>: do not leave database open after failed open (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/63854" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63854/hovercard">#63854</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/394af52abb"><code>394af52abb</code></a>] - <strong>sqlite</strong>: fix stack-use-after-scope with function callback (ndossche) <a href="https://github.com/nodejs/node/pull/63640" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63640/hovercard">#63640</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/10f03e5958"><code>10f03e5958</code></a>] - <strong>src</strong>: omit unconvertible names in cjs_lexer::Parse (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/63943" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63943/hovercard">#63943</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1723773d41"><code>1723773d41</code></a>] - <strong>src</strong>: keep global list of addon-provided cleanup hooks (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/63985" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63985/hovercard">#63985</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ef12e9ea44"><code>ef12e9ea44</code></a>] - <strong>src</strong>: guard OpenSSL compression header include (Filip Skokan) <a href="https://github.com/nodejs/node/pull/64009" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64009/hovercard">#64009</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/48af8a6d8d"><code>48af8a6d8d</code></a>] - <strong>src</strong>: handle empty MaybeLocal in cjs_lexer::Parse (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/63885" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63885/hovercard">#63885</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2a672ee9e8"><code>2a672ee9e8</code></a>] - <strong>src</strong>: fast path empty native immediate drain (Gürgün Dayıoğlu) <a href="https://github.com/nodejs/node/pull/62969" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62969/hovercard">#62969</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/db6a31d1a1"><code>db6a31d1a1</code></a>] - <strong>src</strong>: do not track weak <code>BaseObject</code>s as childrens of <code>Realm</code>s (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/63842" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63842/hovercard">#63842</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5fb837ff46"><code>5fb837ff46</code></a>] - <strong>src</strong>: allow tracking children in <code>MemoryTracker</code> with weak edges (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/63842" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63842/hovercard">#63842</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6d22d373a9"><code>6d22d373a9</code></a>] - <strong>src</strong>: use C++14 deprecated attribute for <code>NODE_DEPRECATED</code> (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/63755" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63755/hovercard">#63755</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7ac3fe1992"><code>7ac3fe1992</code></a>] - <strong>src</strong>: add cleanup hooks to <code>node::ObjectWrap</code> (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/63642" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63642/hovercard">#63642</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d82d369155"><code>d82d369155</code></a>] - <strong>src</strong>: fix edge case when deflateInit2() fails with Z_VERSION_ERROR (Nora Dossche) <a href="https://github.com/nodejs/node/pull/63476" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63476/hovercard">#63476</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/03858d152b"><code>03858d152b</code></a>] - <strong>src</strong>: remove redundant <code>handle_</code> field in ffi (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/63665" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63665/hovercard">#63665</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1682264f6b"><code>1682264f6b</code></a>] - <strong>src</strong>: add Latin1 fast path in StringBytes::Encode utf8 (Mert Can Altin) <a href="https://github.com/nodejs/node/pull/63385" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63385/hovercard">#63385</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cc29696acf"><code>cc29696acf</code></a>] - <strong>stream</strong>: fix Writable.toWeb() desiredSize for non-object-mode (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62986" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62986/hovercard">#62986</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d9967a25b2"><code>d9967a25b2</code></a>] - <strong>stream</strong>: handle falsy push writer fail reasons (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63569" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63569/hovercard">#63569</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b53f8f75c9"><code>b53f8f75c9</code></a>] - <strong>stream</strong>: reduce allocations on WHATWG streams hot paths (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63876" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63876/hovercard">#63876</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/315ca426d8"><code>315ca426d8</code></a>] - <strong>stream</strong>: handle setEncoding after buffered data (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63973" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63973/hovercard">#63973</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/06413cd6bd"><code>06413cd6bd</code></a>] - <strong>stream</strong>: fix Utf8Stream stall after full write of multi-byte data (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63964" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63964/hovercard">#63964</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a9f9a3dafa"><code>a9f9a3dafa</code></a>] - <strong>stream</strong>: keep overlapping broadcast reads pending (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63500" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63500/hovercard">#63500</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/009cca11bd"><code>009cca11bd</code></a>] - <strong>stream</strong>: refine the stream/iter backpressure (James M Snell) <a href="https://github.com/nodejs/node/pull/63697" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63697/hovercard">#63697</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3f81dcfc99"><code>3f81dcfc99</code></a>] - <strong>stream</strong>: only pass the expected number of parameters to callbacks (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63909" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63909/hovercard">#63909</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9a83b5d1fe"><code>9a83b5d1fe</code></a>] - <strong>stream</strong>: fix dropped first chunk in Utf8Stream buffer mode (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63833" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63833/hovercard">#63833</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0bdf5adea9"><code>0bdf5adea9</code></a>] - <strong>stream</strong>: remove transform-writer handling in pipeTo (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63684" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63684/hovercard">#63684</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/10272a94b6"><code>10272a94b6</code></a>] - <strong>stream</strong>: check done before backpressure in stream reader (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63699" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63699/hovercard">#63699</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/792c410631"><code>792c410631</code></a>] - <strong>stream</strong>: fix pipeToSync byte accounting (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63564" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63564/hovercard">#63564</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3cfafbc54b"><code>3cfafbc54b</code></a>] - <strong>stream</strong>: reject pull() reads on abort (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63498" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63498/hovercard">#63498</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/640a8cede5"><code>640a8cede5</code></a>] - <strong>stream</strong>: fast-path stateless transform flush results (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63605" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63605/hovercard">#63605</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ece4477872"><code>ece4477872</code></a>] - <strong>stream</strong>: optimize pipeTo promise handling (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63572" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63572/hovercard">#63572</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2cb84c2daf"><code>2cb84c2daf</code></a>] - <strong>stream</strong>: handle sync writev completion in pipeTo (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63561" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63561/hovercard">#63561</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7d9fdda5fa"><code>7d9fdda5fa</code></a>] - <strong>stream</strong>: settle pending broadcast reads on return (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63603" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63603/hovercard">#63603</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e2aea3aac7"><code>e2aea3aac7</code></a>] - <strong>test</strong>: tolerate duplicate watch change events (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63937" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63937/hovercard">#63937</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ea6300593a"><code>ea6300593a</code></a>] - <strong>test</strong>: mark test-debugger-run-after-quit-restart as flaky on macOS (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64006" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64006/hovercard">#64006</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/be1b204fa4"><code>be1b204fa4</code></a>] - <strong>test</strong>: update WPT for url to d4598eba09 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63899" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63899/hovercard">#63899</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b3d0d05b05"><code>b3d0d05b05</code></a>] - <strong>test</strong>: update WPT for WebCryptoAPI to 03a1476844 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63900" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63900/hovercard">#63900</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/046af2609f"><code>046af2609f</code></a>] - <strong>test</strong>: update WPT for urlpattern to 23aac92784 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63898/hovercard">#63898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/562b831a98"><code>562b831a98</code></a>] - <strong>test</strong>: add tests for 3 methods in utils (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63765" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63765/hovercard">#63765</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/28e3629dd3"><code>28e3629dd3</code></a>] - <strong>test</strong>: mark SEA tests flaky on linux arm debug (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63743" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63743/hovercard">#63743</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/243aa846de"><code>243aa846de</code></a>] - <strong>test</strong>: validate ERR_INVALID_THIS for scheduler methods (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63764" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63764/hovercard">#63764</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6bd07df2bc"><code>6bd07df2bc</code></a>] - <strong>test</strong>: add coverage outside SEA (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63744" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63744/hovercard">#63744</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bd67c9d11b"><code>bd67c9d11b</code></a>] - <strong>test</strong>: update WPT for urlpattern to 2f28df545c (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63771" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63771/hovercard">#63771</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e40bfe7081"><code>e40bfe7081</code></a>] - <strong>test</strong>: make Brotli 16GB test wait for backpressure (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63389" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63389/hovercard">#63389</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/444c03fd3b"><code>444c03fd3b</code></a>] - <strong>test</strong>: add regression test for using <code>ObjectWrap</code> in worker (Mohamed Akram) <a href="https://github.com/nodejs/node/pull/63642" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63642/hovercard">#63642</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/771230df78"><code>771230df78</code></a>] - <strong>test</strong>: accept SIGILL aborts in async-hooks tests (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63687" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63687/hovercard">#63687</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0b3cd8e5e6"><code>0b3cd8e5e6</code></a>] - <strong>test</strong>: add more test cases for pathToFileURL (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/63293" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63293/hovercard">#63293</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0cbc77c60e"><code>0cbc77c60e</code></a>] - <strong>test</strong>: update test426-fixtures to 2965987bf4c96afa400c9356c8e620cb340aaee (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63668" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63668/hovercard">#63668</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f53dee5fe4"><code>f53dee5fe4</code></a>] - <strong>test</strong>: update WPT for WebCryptoAPI to 0c413fb56b (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63647" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63647/hovercard">#63647</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3048f8dc1a"><code>3048f8dc1a</code></a>] - <strong>test,debugger</strong>: add test for type stripping in debugger probe mode (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63748" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63748/hovercard">#63748</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9485caa97e"><code>9485caa97e</code></a>] - <strong>test_runner</strong>: remove unused shuffleArrayWithSeed (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63847" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63847/hovercard">#63847</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/34433a4a87"><code>34433a4a87</code></a>] - <strong>test_runner</strong>: fix watch cwd with isolation none (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63690" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63690/hovercard">#63690</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2e7da29b7c"><code>2e7da29b7c</code></a>] - <strong>test_runner</strong>: avoid recompiling coverage globs for every file (sangwook) <a href="https://github.com/nodejs/node/pull/63675" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63675/hovercard">#63675</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/205295a31e"><code>205295a31e</code></a>] - <strong>test_runner</strong>: cache <code>shouldSkipFileCoverage</code> result per URL (sangwook) <a href="https://github.com/nodejs/node/pull/63675" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63675/hovercard">#63675</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ee29465e77"><code>ee29465e77</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>tls</strong>: add certificateCompression option (Tim Perry) <a href="https://github.com/nodejs/node/pull/62217" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62217/hovercard">#62217</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/57d060ed2b"><code>57d060ed2b</code></a>] - <strong>tls</strong>: route event listener exceptions through error handlers (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63822" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63822/hovercard">#63822</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d2dc6f8506"><code>d2dc6f8506</code></a>] - <strong>tools</strong>: bump piscina from 5.1.4 to 5.2.0 in /tools/doc (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/64002" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64002/hovercard">#64002</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b0c418f605"><code>b0c418f605</code></a>] - <strong>tools</strong>: update sccache to v0.16.0 (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/63078" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63078/hovercard">#63078</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2af8433bef"><code>2af8433bef</code></a>] - <strong>tools</strong>: bump js-yaml from 4.1.1 to 4.2.0 in /tools/lint-md (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63948" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63948/hovercard">#63948</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8ba5b8574b"><code>8ba5b8574b</code></a>] - <strong>tools</strong>: bump js-yaml from 4.1.1 to 4.2.0 in /tools/eslint (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63947" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63947/hovercard">#63947</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/325087be5b"><code>325087be5b</code></a>] - <strong>tools</strong>: enforce iterator result property order (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63526" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63526/hovercard">#63526</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/314f417db7"><code>314f417db7</code></a>] - <strong>tools</strong>: update the llhttp updater script (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63819" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63819/hovercard">#63819</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c6e4f5a4fe"><code>c6e4f5a4fe</code></a>] - <strong>tools</strong>: avoid test/fixtures/wpt/README.md conflicts (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63938" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63938/hovercard">#63938</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/363912acc3"><code>363912acc3</code></a>] - <strong>tools</strong>: align Bash snippets in GHA with <code>lint-sh</code> conventions (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63829" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63829/hovercard">#63829</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cfd16e973c"><code>cfd16e973c</code></a>] - <strong>tools</strong>: bump @node-core/doc-kit in /tools/doc in the doc group (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63760" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63760/hovercard">#63760</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1566872706"><code>1566872706</code></a>] - <strong>tools</strong>: bump the eslint group in /tools/eslint with 7 updates (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63730" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63730/hovercard">#63730</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/08437a3a5b"><code>08437a3a5b</code></a>] - <strong>tools</strong>: fix zlib updater script (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63707" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63707/hovercard">#63707</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e883366172"><code>e883366172</code></a>] - <strong>url</strong>: fix URLSearchParams(null) to prudce null= per spec (Marco) <a href="https://github.com/nodejs/node/pull/63782" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63782/hovercard">#63782</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/60e83d9bfd"><code>60e83d9bfd</code></a>] - <strong>util</strong>: fix scientific notation formatting (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63823" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63823/hovercard">#63823</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5f7f60ac36"><code>5f7f60ac36</code></a>] - <strong>util</strong>: fix -0 formatting when numericSeparator is enabled (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63815" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63815/hovercard">#63815</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/af1a11e0dd"><code>af1a11e0dd</code></a>] - <strong>util</strong>: remove style caches from styleText slow path (Guilherme Araújo) <a href="https://github.com/nodejs/node/pull/63706" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63706/hovercard">#63706</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b17817eb2b"><code>b17817eb2b</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>vfs</strong>: dispatch fs/promises to mounted VFS instances (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63537" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63537/hovercard">#63537</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7bc93a6ac5"><code>7bc93a6ac5</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>vfs</strong>: add minimal node:vfs subsystem (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63115" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63115/hovercard">#63115</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/584e7527c4"><code>584e7527c4</code></a>] - <strong>vm</strong>: fix property queries for proxy sandboxes (Brian Meek) <a href="https://github.com/nodejs/node/pull/63742" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63742/hovercard">#63742</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a926e72eaf"><code>a926e72eaf</code></a>] - <strong>watch</strong>: print name of changed file that triggers restart (Marco) <a href="https://github.com/nodejs/node/pull/63781" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63781/hovercard">#63781</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/32a2621ca4"><code>32a2621ca4</code></a>] - <strong>watch</strong>: cancel pending restart on shutdown (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63383" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63383/hovercard">#63383</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/692215d1b1"><code>692215d1b1</code></a>] - <strong>zlib</strong>: coerce -0 to +0 for crc32 seeds (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63556" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63556/hovercard">#63556</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Von Markdown zu PDF auf die harte Weise (noname_ev)]]></title>
<description><![CDATA[Ich mag Markdown zum Schreiben von Notizen oder längeren Texten, aber leider gefällt manchen Menschen das Anstarren von Textdateien nicht. In der Vergangenheit habe ich darum mit pandoc und latex meine Markdown Dokumente in PDFs verwandelt.

Kürzlich habe ich beschlossen, dass ich typst viel lieb...]]></description>
<link>https://tsecurity.de/de/3622571/it-security-video/von-markdown-zu-pdf-auf-die-harte-weise-nonameev/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622571/it-security-video/von-markdown-zu-pdf-auf-die-harte-weise-nonameev/</guid>
<pubDate>Wed, 24 Jun 2026 20:50:37 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Ich mag Markdown zum Schreiben von Notizen oder längeren Texten, aber leider gefällt manchen Menschen das Anstarren von Textdateien nicht. In der Vergangenheit habe ich darum mit pandoc und latex meine Markdown Dokumente in PDFs verwandelt.<br>
<br>
Kürzlich habe ich beschlossen, dass ich typst viel lieber mag als latex. Drum zeige ich euch heute, wie ich mittlerweile Dokumente von Markdown über pandoc und typst zu PDFs konvertiere.<br>
<br>
Spoiler: Es ist ein bisschen bash-Code involviert.<br></p>
<p>
Aufgrund eines Fehlers bei der Aufnahme und Durchführung ist der Bildschirminhalt samt Präsentation leider nicht sichtbar.
</p>

<p>
Links und Quellen:
</p><ul>
  <li><a href="https://www.noname-ev.de/chaotische_viertelstunde.html#c14h_670">Vortrag auf der Vereinsseite</a></li>
  <li><a href="https://gitlab.com/hartang/typst/md2pdf">Projekt 'md2pdf'</a></li>
  <li><a href="https://gitlab.com/hartang/c14h/2026-01-08_von-markdown-zu-pdf-auf-die-harte-weise">Repo &amp; Folien</a></li>
</ul>

about this event: https://www.noname-ev.de/chaotische_viertelstunde.html#c14h_670]]></content:encoded>
</item>
<item>
<title><![CDATA[Gemeinsam Wissens-Infrastruktur bauen: föderierte Wikibase für Video- und Podcasts (gpn24)]]></title>
<description><![CDATA[Das WissKomm Wiki hat Förderung, einen laufenden Prototypen und 100.000+ identifizierte Videos. Dieser Talk zeigt, was schon läuft: föderierte Wikibase, automatische Transkription per Whisper, SPARQL-Queries über Wissenschaftsmedien. 
Mit Arrrrrmin haben wir LanzMining von der GPN23 zu SpeakerMin...]]></description>
<link>https://tsecurity.de/de/3622493/it-security-video/gemeinsam-wissens-infrastruktur-bauen-foederierte-wikibase-fuer-video-und-podcasts-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622493/it-security-video/gemeinsam-wissens-infrastruktur-bauen-foederierte-wikibase-fuer-video-und-podcasts-gpn24/</guid>
<pubDate>Wed, 24 Jun 2026 20:48:55 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das WissKomm Wiki hat Förderung, einen laufenden Prototypen und 100.000+ identifizierte Videos. Dieser Talk zeigt, was schon läuft: föderierte Wikibase, automatische Transkription per Whisper, SPARQL-Queries über Wissenschaftsmedien. 
Mit Arrrrrmin haben wir LanzMining von der GPN23 zu SpeakerMining aufgebaut und ins WissKomm Wiki integriert - eine vollständige Pipeline, die aus ZDF-Archiv-PDFs einen verlinkten Wissensgraph erzeugt: 10.000+ Personenerwähnungen, 120.000+ Wikidata-Triples, OpenRefine-Kuration. Genau das skalieren wir im WissKomm Wiki auf Wissenschaftsvideos und -podcasts. Plus die offenen Probleme, an denen wir gemeinsam arbeiten möchten, am besten gleich im GPN24 Hackathon.

2021: Idee
GPN22: Präsentation im CCC.
GPN23: Prototyp, Antrag in der Schwebe, Arrrrrmin stellt LanzMining vor.
GPN24: Das Projekt läuft: Gefördert durch FDM-NDS dürfen wir jetzt zeigen, wie LanzMining, WissKomm Wiki und viele ähnliche Projekte zusammenpassen.

Ein Einblick: [GPN23, media.ccc.de](https://media.ccc.de/v/gpn23-299-ctrl-f-for-facts-mit-dem-wisskomm-wiki-filterblasen-erkennen-und-fakten-sichtbar-machen). 
Im Talk gehen wir endlich über Konzepte hinaus in die Anwendung!


Auf der GPN23 hat Arrrrrmin mit LanzMining gezeigt, was möglich ist, wenn man TV-Archivdaten strukturiert erschließt. Wir haben das weitergebaut zur vollständigen Pipeline Speaker Mining. Ausgangspunkt: ZDF-Archiv-PDFs des Markus-Lanz-Talks. 
Semantisch disambiguiert mit OpenRefine, dedupliziert auf Wikibase bereitgestellt und letztlich nachhaltig frei verfügbar.
Wer mag, kann live über SPARQL-Queries Fragen stellen: - wer war wie oft zu Gast? Mit welcher Rollenverteilung? 
Wir gehen noch tiefer in die Analyse: Visualisierung der Rollenverteilung, wie von LanzMining bereits vorgemacht: Indem wir Klassen wie Rollen und Instanzen wie Markus Lanz statistisch unter die Lupe nehmen, können wir mit Speaker Mining bildlich machen, was unsere Medienlandschaft ausmacht.


Die aktuelle WissKomm-Wiki-Infrastruktur besteht aus einer föderierten Wikibase via Wikibase.cloud (wie ein eigenes Wikidata), langfristig verknüpft mit einem Full Text Wiki für Transkripte. Via SPARQL kann nach Properties und Datenquellen gefiltert werden. 

Speaker Mining zeigt, wohin das führt: Wenn Sendungsarchiv-Metadaten maschinenlesbar in einer Wikibase liegen, kann man fragen: Wer war wann zu Gast, mit welcher Rolle, aus welcher Institution?

Whisper läuft noch lokal, transkribiert offline, und die Ergebnisse landen vorerst nicht im Wiki - bis wir im Projekt die Rechtsfragen geklärt haben. Ziel dafür: Ende Juni steht der Fragenkatalog, und im September haben wir unser Rechtsgutachten.
Experimentell haben wir so schon mal 230+ Folgen Lanz &amp; Precht transkribiert und analysiert - die ersten Ergebnisse sind ganz spannend. Der Blick auf die beiden *sozusagen*-Experten ist nur ein erster Einblick in das, was langfristig möglich sein soll. Der nächste Schritt geht gen Wissenschafts-Podcasts, wie dem jüngst mit dem ÖFG-Preis für Wissenschaftsjournalismus ausgezeichneten Podcast [Das Klima](https://dasklima.podigee.io/) von u.a. FuzzyLeapfrog, die von Beginn an bei Speaker Mining mitgewirkt hat.


Jetzt geht es darum, die Community aufzubauen: Der [Matrix-Channel](https://matrix.to/#/#wisskomm.wiki:matrix.org) ist aufgesetzt, das Community-Team steht bereit und arbeitet fleißig mit unserem gemeinnützigen Verein daran, die gewachsenen Strukturen der vergangenen fünf Jahre auf bleibende Strukturen zu stellen. Das Open Science Lab aus Hannover übernimmt die fundamentale Infrastruktur, und der Verein übernimmt experimentellere Interfaces wie Gamification oder Plugins.

* Föderierte Wiki-Architektur: Wikibase + Full Text Wiki, verbunden über interne Queries
* Module für Datenakquise, Zwischenspeicherung, Transkription (Whisper ASR, lokal)
* Interfaces: nicht nur für Forschende und Entwickler\*innen, sondern auch für Urheber\*innen und Plattformbetreibende
* Federation mit Wikidata, ORKG, TIB AV-Portal - ohne deren Infrastruktur zu überlasten

Wer mitmachen will: Wir vom WissKomm Wiki sind auf der GPN, sprecht uns an :) Zum Talk gibts hoffentlich noch den Workshop. 

**Links**

* [GPN23: CTRL+F for Facts (WissKomm Wiki)](https://media.ccc.de/v/gpn23-299-ctrl-f-for-facts-mit-dem-wisskomm-wiki-filterblasen-erkennen-und-fakten-sichtbar-machen)
* [GPN23: LanzMining (Arrrrrmin)]([https://media.ccc.de/v/gpn23](https://media.ccc.de/v/gpn23-213-lanzmining-wer-spricht-denn-da-))
* [Projekt](https://borgnetzwerk.org/wisskomm-wiki)
* SciCom Wiki: [Code](https://gitlab.com/wisskomm-wiki), [Paper](https://arxiv.org/abs/2511.09248),
* Speaker Mining: [Code](https://github.com/borgnetzwerk/speaker-mining), [Paper](
https://doi.org/10.48550/arXiv.2606.02905))

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/G9VCNN/]]></content:encoded>
</item>
<item>
<title><![CDATA[Gogs vs. GitLab: Leichtgewicht gegen DevOps-Plattform]]></title>
<description><![CDATA[Mit Gogs und GitLab stehen Ihnen zwei leistungsfähige Git-Server zur Auswahl. Doch während Gogs bewusst minimalistisch gehalten ist, deckt GitLab den gesamten Softwareentwicklungsprozess ab. Das wirkt sich nicht nur auf die Funktionen, sondern auch auf Ressourcenbedarf und Wartung aus. Unser Verg...]]></description>
<link>https://tsecurity.de/de/3621692/server/gogs-vs-gitlab-leichtgewicht-gegen-devops-plattform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621692/server/gogs-vs-gitlab-leichtgewicht-gegen-devops-plattform/</guid>
<pubDate>Wed, 24 Jun 2026 16:30:21 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/c-plus-plus-plus-plus-t.jpg" width="1200" height="630" alt=""><br>Mit Gogs und GitLab stehen Ihnen zwei leistungsfähige Git-Server zur Auswahl. Doch während Gogs bewusst minimalistisch gehalten ist, deckt GitLab den gesamten Softwareentwicklungsprozess ab. Das wirkt sich nicht nur auf die Funktionen, sondern auch auf Ressourcenbedarf und Wartung aus. Unser Vergleichsartikel zu Gogs vs. GitLab hilft Ihnen, die Unterschiede zu verstehen und die richtige Entscheidung für Ihr Projekt zu treffen.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab-Umfrage: KI-beschleunigtes Coding erzeugt Sicherheitsprobleme]]></title>
<description><![CDATA[Der GitLab AI Accountability Report zeigt: Der Einsatz von KI macht das Coding schneller, aber ohne Kontrolle entstehen neue Risiken und technische Schulden.]]></description>
<link>https://tsecurity.de/de/3621331/it-nachrichten/gitlab-umfrage-ki-beschleunigtes-coding-erzeugt-sicherheitsprobleme/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621331/it-nachrichten/gitlab-umfrage-ki-beschleunigtes-coding-erzeugt-sicherheitsprobleme/</guid>
<pubDate>Wed, 24 Jun 2026 14:33:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der GitLab AI Accountability Report zeigt: Der Einsatz von KI macht das Coding schneller, aber ohne Kontrolle entstehen neue Risiken und technische Schulden.]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-06-23 - Kernels, KDE Frameworks, KDE Gear, Xorg-Server]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected end of June, Mid of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you...]]></description>
<link>https://tsecurity.de/de/3617719/unix-server/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617719/unix-server/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/</guid>
<pubDate>Tue, 23 Jun 2026 11:16:30 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected end of June, Mid of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may found thus far.</p>
<h3><a name="p-862629-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-862629-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-862629-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-862629-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/188480/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/188480/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/188480/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/188480/1">(click for more details)</a>
<h2><a name="p-862629-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-862629-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>Kernels</strong> got updated
<ul>
<li>introducing <strong>linux72</strong> series</li>
</ul>
</li>
<li><strong>Systemd</strong> <a href="https://github.com/systemd/systemd/compare/v260.1...v260.2">260.2</a></li>
<li><strong>PipeWire</strong> <a href="https://gitlab.freedesktop.org/pipewire/pipewire/-/releases/1.6.6">1.6.6</a></li>
<li><strong>COSMIC</strong> Epoch <a href="https://github.com/pop-os/cosmic-epoch/releases/tag/epoch-1.0.16">1.0.16</a></li>
<li><strong>NVIDIA</strong> <a href="https://www.nvidia.com/en-us/drivers/details/271414/">610.43.02</a></li>
<li><strong>VLC</strong> <a href="https://images.videolan.org/vlc/releases/3.0.23.html">3.0.23_2</a></li>
<li><strong>Arkdep</strong> <a href="https://github.com/arkanelinux/arkdep/compare/2025.12.18...2026.06.10">20260610</a></li>
<li><strong>Xorg-Server</strong> <a href="https://lists.x.org/archives/xorg-announce/2026-June/003702.html">21.1.23</a></li>
<li><strong>KDE Gear</strong> <a href="https://kde.org/announcements/gear/26.04.2/">26.04.2</a></li>
<li><strong>KDE Frameworks</strong> <a href="https://kde.org/announcements/frameworks/6/6.27.0/">6.27.0</a></li>
<li><strong>LibreOffice</strong> <a href="https://blog.documentfoundation.org/blog/2026/06/05/tdf-releases-libreoffice-26-2-4/">26.2.4</a></li>
<li><strong>QEmu</strong> <a href="https://www.qemu.org/2026/04/22/qemu-11-0-0/">11.0.1</a></li>
</ul>
<h2><a name="p-862629-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-862629-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/188480/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/188480/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.176</li>
<li>linux66 6.6.143</li>
<li>linux612 6.12.94</li>
<li>linux618 6.18.36</li>
<li>linux70 7.0.13</li>
<li>linux71 7.1.1</li>
<li>linux72 7.2.0-rc0</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (Tue Jun 16 2026 12:41:23 GMT+0000)</p>
<ul>
<li>testing core x86_64:  28 new and 28 removed package(s)</li>
<li>testing extra x86_64:  3515 new and 3453 removed package(s)</li>
<li>testing multilib x86_64:  40 new and 40 removed package(s)</li>
</ul>
<p><strong>Overlay Changes</strong></p>
<ul>
<li>testing core x86_64:  16 new and 14 removed package(s)</li>
<li>testing extra x86_64:  170 new and 165 removed package(s)</li>
<li>testing multilib x86_64:  3 new and 3 removed package(s)</li>
</ul>
<p>A list of all package changes can be found <a href="https://gitlab.manjaro.org/-/snippets/1204/raw">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/188480/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-06-23-kernels-kde-frameworks-kde-gear-xorg-server/188480">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-05-29 - Systemd, COSMIC, NVIDIA, Firefox, Pipewire, VLC]]></title>
<description><![CDATA[Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected end of June, beginning of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issu...]]></description>
<link>https://tsecurity.de/de/3616080/unix-server/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616080/unix-server/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/</guid>
<pubDate>Mon, 22 Jun 2026 18:16:47 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello Manjaro user community, here we have another set of package updates. We are continuing our development of the upcoming release of ‘Bian-May’ which can be expected end of June, beginning of July. Development speed may be a little slower the upcoming weeks. However, still let us know any issues you may found thus far.</p>
<h3><a name="p-858952-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-858952-current-promotions-1" aria-label="Heading link"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-858952-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-858952-recent-news-2" aria-label="Heading link"></a>Recent News</h2>

New in Manjaro GNOME!
Or, if you prefer the command line: <a href="https://forum.manjaro.org/t/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/188000/1">(click for more details)</a>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/188000/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/188000/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-1-bian-may-preview-released/187389" class="inline-onebox">Manjaro 26.1 Bian-May - Preview released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
<li>As of Linux 6.19.14, the 6.19 series is now EOL (End Of Life). Please install 7.0, and/or 6.18 LTS (Long Term Support) and/or 6.12 LTS.</li>
</ul>

Previous News <a href="https://forum.manjaro.org/t/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/188000/1">(click for more details)</a>
<h2><a name="p-858952-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-858952-notable-package-updates-3" aria-label="Heading link"></a>Notable Package Updates</h2>
<ul>
<li><strong>Systemd</strong> <a href="https://github.com/systemd/systemd/compare/v260.1...v260.2">260.2</a></li>
<li><strong>PipeWire</strong> <a href="https://gitlab.freedesktop.org/pipewire/pipewire/-/releases/1.6.6">1.6.6</a></li>
<li><strong>COSMIC</strong> Epoch <a href="https://github.com/pop-os/cosmic-epoch/releases/tag/epoch-1.0.14">1.0.14</a></li>
<li><strong>NVIDIA</strong> <a href="https://www.nvidia.com/en-us/drivers/details/271414/">610.43.02</a></li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/firefox/151.0.2/releasenotes/">151.0.2</a></li>
<li><strong>VLC</strong> <a href="https://images.videolan.org/vlc/releases/3.0.23.html">3.0.23_2</a></li>
</ul>
<h2><a name="p-858952-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-858952-additional-info-4" aria-label="Heading link"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/188000/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/188000/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux61 6.1.174</li>
<li>linux66 6.6.141</li>
<li>linux612 6.12.91</li>
<li>linux618 6.18.33</li>
<li>linux70 7.0.10</li>
<li>linux71 7.1.0-rc5</li>
<li>linux61-rt 6.1.167_rt62</li>
<li>linux66-rt 6.6.135_rt74</li>
<li>linux612-rt 6.12.89_rt18</li>
</ul>
<p><strong>Package Changes</strong> (5/29/26 00:30 CEST)</p>
<ul>
<li>testing core x86_64:  7 new and 7 removed package(s)</li>
<li>testing extra x86_64:  645 new and 740 removed package(s)</li>
<li>testing multilib x86_64:  8 new and 8 removed package(s)</li>
</ul>
<p>A list of all package changes can be found <a href="https://pastebin.com/raw/SFTs3KdH">here</a>.</p>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/188000/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>20 posts - 13 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-05-29-systemd-cosmic-nvidia-firefox-pipewire-vlc/188000">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Schwere Sicherheitslücke in aktuellen Windows-Systemen: Microsoft verspricht, sie zu schließen]]></title>
<description><![CDATA[Vor einer Woche veröffentlichte der anonyme Sicherheitsforscher “Nightmare Eclipse” Informationen zu „Rogue Planet“, einer sogenannten „Zero-Day“-Sicherheitslücke in Microsofts Sicherheitsprogramm Defender (lesen Sie hier: Was ist Microsoft Defender und wie gut schützt er vor Viren und anderen Be...]]></description>
<link>https://tsecurity.de/de/3613249/it-nachrichten/schwere-sicherheitsluecke-in-aktuellen-windows-systemen-microsoft-verspricht-sie-zu-schliessen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613249/it-nachrichten/schwere-sicherheitsluecke-in-aktuellen-windows-systemen-microsoft-verspricht-sie-zu-schliessen/</guid>
<pubDate>Sun, 21 Jun 2026 09:32:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Vor einer Woche veröffentlichte der anonyme Sicherheitsforscher “Nightmare Eclipse” Informationen zu „<a href="https://blog.projectnightcrawler.dev/posts/2026-06-16-rogueplanet-another-quick-statement/">Rogue Planet“</a>, einer sogenannten „Zero-Day“-Sicherheitslücke in Microsofts Sicherheitsprogramm Defender (lesen Sie hier: <a href="https://www.pcwelt.de/article/2652374/was-ist-microsoft-defender-und-wie-gut-schutzt-es-vor-viren-und-anderen-bedrohungen.html" target="_blank" rel="noreferrer noopener">Was ist Microsoft Defender und wie gut schützt er vor Viren und anderen Bedrohungen?</a>). Die Schwachstelle, die die offizielle Bezeichnung <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656">CVE-2026-50656 </a>erhalten hat, kann von Hackern ausgenutzt werden, um vollständigen Zugriff auf unsere Computer zu erlangen.</p>



<p>Die von „Nightmare Eclipse“ veröffentlichte Schwachstelle steckt in vollständig gepatchten Windows 10- und Windows 11-Geräten und ermöglicht es Angreifern, über eine Race-Condition in Microsoft Defender Eingabeaufforderungen mit SYSTEM-Rechten zu erzeugen. Der Sicherheitsexperte veröffentlichte einen Proof-of-Concept-Exploit in einem selbst gehosteten Git-Repository und behauptete, Microsoft habe zuvor seine Repos, in denen Exploits auf GitHub und GitLab gehostet wurden, ins Visier genommen und entfernt.</p>



<p>Der Sicherheitsexperte schreibt: „Bei dem Exploit handelt es sich um eine Race Condition, daher ist der Erfolg ungewiss. Auf einigen Rechnern konnte ich eine Erfolgsquote von 100 % erzielen, während es auf anderen nur schwer funktionierte. Der PoC für RoguePlanet funktioniert unabhängig davon, ob der Echtzeitschutz aktiviert ist oder nicht.</p>



<p>In einer Stellungnahme gegenüber dem IT-Sicherheitsnachrichtenportal <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-working-on-defender-patch-for-rogueplanet-zero-day/" data-type="link" data-id="https://www.bleepingcomputer.com/news/microsoft/microsoft-working-on-defender-patch-for-rogueplanet-zero-day/">Bleeping Computer</a> erklärte ein Sprecher von Microsoft, dass das Unternehmen derzeit intensiv an der Entwicklung eines Sicherheitspatches für „Rogue Planet“ arbeite, der hoffentlich in Kürze für die Öffentlichkeit bereitgestellt werde. Microsoft sagt laut Bleepingcomputer:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Microsoft ist sich einer Berechtigungserweiterung in der Microsoft Malware Protection Engine von Microsoft Defender bewusst, die öffentlich als ‚RoguePlanet‘ bezeichnet wird: Wir arbeiten daran, ein hochwertiges Sicherheitsupdate bereitzustellen, das diese Sicherheitslücke behebt. Wir werden Informationen zu dieser CVE bereitstellen, sobald das Update verfügbar ist.</p>
</blockquote>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<p>In letzter Zeit hat derselbe Sicherheitsforscher Informationen über eine ganze Reihe von Sicherheitslücken in Windows veröffentlicht, darunter „<a href="https://www.pcwelt.de/article/3107858/ungepatchte-windows-luecke-ermoeglicht-uebernahme-von-pcs.html" target="_blank" rel="noreferrer noopener">Blue Hammer</a>“, „<a href="https://www.pcwelt.de/article/3116191/kuriose-sicherheitsluecke-in-windows-defender-gefaehrdet-millionen-nutzer.html" target="_blank" rel="noreferrer noopener">Red Sun</a>“, „Green Plasma“, „Mini Plasma“, „Yellow Key“ und „Undefend“.</p>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/2490003/windows-security-vs-microsoft-defender-wichtige-unterschiede-die-sie-kennen-sollten.html" target="_blank" rel="noreferrer noopener">Windows-Sicherheit vs. Microsoft Defender: Diese Unterschiede sollten Sie kennen</a></li>



<li><a href="https://www.pcwelt.de/article/2043389/windows-defender-einrichten-nutzen.html" target="_blank" rel="noreferrer noopener">Windows Defender optimal einrichten und nutzen</a></li>



<li><a href="https://www.pcwelt.de/article/2661230/windows-defender-alle-versionen-ueberblick.html" target="_blank" rel="noreferrer noopener">Windows Defender: Alle Versionen im Überblick</a></li>
</ul>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-6955 | GitLab Remote Development up to 16.5.5/16.6.3/16.7.1 access control (Issue 43218 / EUVD-2023-59151)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in GitLab Remote Development up to 16.5.5/16.6.3/16.7.1. Affected by this issue is some unknown functionality. The manipulation results in improper access controls.

This vulnerability is cataloged as CVE-2023-6955. The attack may be launched remot...]]></description>
<link>https://tsecurity.de/de/3612919/sicherheitsluecken/cve-2023-6955-gitlab-remote-development-up-to-165516631671-access-control-issue-43218-euvd-2023-59151/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3612919/sicherheitsluecken/cve-2023-6955-gitlab-remote-development-up-to-165516631671-access-control-issue-43218-euvd-2023-59151/</guid>
<pubDate>Sun, 21 Jun 2026 02:38:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/gitlab:remote_development">GitLab Remote Development up to 16.5.5/16.6.3/16.7.1</a>. Affected by this issue is some unknown functionality. The manipulation results in improper access controls.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2023-6955">CVE-2023-6955</a>. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ubuntu 26.04 LTS - say goodbye to snaps]]></title>
<description><![CDATA[Love Ubuntu but F*** SNAPS, GOODBYE!  You can strip snaps out of 26.04 LTS and continue humming along. Here's the steps, taken from a YouTube video I came across, but I've updated the steps as below.  NOTE - these MUST be executed in the order I have written here due to dependencies and related h...]]></description>
<link>https://tsecurity.de/de/3611464/linux-tipps/ubuntu-2604-lts-say-goodbye-to-snaps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611464/linux-tipps/ubuntu-2604-lts-say-goodbye-to-snaps/</guid>
<pubDate>Sat, 20 Jun 2026 02:08:39 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><strong>Love Ubuntu but F*** SNAPS, GOODBYE!</strong> </p> <p><strong>You can strip snaps out of 26.04 LTS</strong> and continue humming along. Here's the steps, taken from a YouTube video I came across, but I've updated the steps as below. </p> <p>NOTE - these MUST be executed in the order I have written here due to dependencies and related hierarchies. Be patient with the snap removal section as some commands take a few moments to process. </p> <p>Test with a VM first if you're worried, don't run on your live install unless you have a snapshot handy. Copy-paste this into a text file for better readability. </p> <p>Install Flatpak binary:<br> sudo apt install flatpak </p> <p>Gnome Software Center &amp; Flatpak Plugin install:<br> sudo apt install --no-install-recommends gnome-software </p> <p>Install Flatpak Plugin:<br> sudo apt install gnome-software-plugin-flatpak </p> <p>Then we add add Flathub Repo:<br> flatpak remote-add --if-not-exists flathub <a href="https://dl.flathub.org/repo/flathub.flatpakrepo">https://dl.flathub.org/repo/flathub.flatpakrepo</a> </p> <p>Reboot your system:<br> sudo reboot </p> <p>After reboot, install a browser e.g.<br> flatpak install flathub io.github.ungoogled_software.ungoogled_chromium </p> <p>Now we neeed to add PPAs, example applications:<br> KeepassXC:<br> sudo add-apt-repository ppa:phoerious/keepassxc </p> <p>Firefox ESR and Thunderbird stable builds:<br> sudo add-apt-repository ppa:mozillateam/ppa </p> <p>LibreOffice:<br> sudo add-apt-repository ppa:libreoffice/ppa </p> <p>VS Codium (I prefer this OSS version, no MS telemetry. If the code here stuffs up, goto the Debian/Ubuntu section on <a href="https://vscodium.com/">https://vscodium.com/</a> and copy from there)<br> wget -qO - <a href="https://gitlab.com/paulcarroty/vscodium-deb-rpm-repo/raw/master/pub.gpg">https://gitlab.com/paulcarroty/vscodium-deb-rpm-repo/raw/master/pub.gpg</a> \ </p> <p>| gpg --dearmor \ </p> <p>| sudo dd of=/usr/share/keyrings/vscodium-archive-keyring.gpg </p> <p>echo -e 'Types: deb\nURIs: <a href="https://download.vscodium.com/debsnSuites:">https://download.vscodium.com/debs\nSuites:</a> vscodium\nComponents: main\nArchitectures: amd64 arm64\nSigned-by: /usr/share/keyrings/vscodium-archive-keyring.gpg' \ </p> <p>| sudo tee /etc/apt/sources.list.d/vscodium.sources </p> <p>Firefox + Thunderbird preparations:<br> Preparation for Thunderbird:<br> sudo nano /etc/apt/preferences.d/mozillateam-ppa </p> <p>Add these 6 lines in the file:<br> Package: thunderbird*<br> Pin: release o=LP-PPA-mozillateam<br> Pin-Priority: 1001<br> Package: thunderbird*<br> Pin: release o=Ubuntu<br> Pin-Priority: -1 </p> <p>Now that we've prepared flatpak, we can do the snap uninstall:<br> snap list </p> <p>This will show columns in its output, the snaps are on the far left. </p> <p>Here is the standard list and snap remove you'll see in Ubuntu 26.04: </p> <p>sudo snap remove firefox<br> sudo snap remove gtk-common-themes<br> sudo snap remove gnome-46-2404<br> sudo snap remove snapd-desktop-integration<br> sudo snap remove snap-store<br> sudo snap remove firmware-updater<br> sudo snap remove gtk-common-themes<br> sudo snap remove bare<br> sudo snap remove thunderbird<br> sudo snap remove desktop-security-center<br> sudo snap remove mesa-2404<br> sudo snap remove prompting-client<br> sudo snap remove core24<br> sudo snap remove snapd </p> <p>Then check the list again with snap list, it should be empty. </p> <p>We need to deactivate deactivate snapd.socket:<br> sudo systemctl disable --now snapd.socket </p> <p>Then we stop snapd:<br> sudo systemctl stop snapd </p> <p>Now we disable snapd:<br> sudo systemctl disable snapd </p> <p>Then we mask snapd so the OS doesn't try to reuse it:<br> sudo systemctl mask snapd </p> <p>And we delete snapd:<br> sudo apt purge snapd -y </p> <p>We mark snap so the OS doesn't try to reuse it:<br> sudo apt-mark hold snapd </p> <p>Next we perform snap fs cleanup:<br> sudo rm -rf ~/snap<br> sudo rm -rf /snap<br> sudo rm -rf /var/snap<br> sudo rm -rf /var/lib/snapd </p> <p>We also need to prevent prevent snap reinstall:<br> sudo nano /etc/apt/preferences.d/nosnap.pref </p> <p>We add these 3 lines:<br> Package: snapd<br> Pin: release a=*<br> Pin-Priority: -10 </p> <p>Next we perform an apt refresh:<br> sudo apt update </p> <p>Install Firefox ESR &amp; Thunderbird:<br> sudo apt update &amp;&amp; sudo apt install firefox-esr thunderbird -y </p> <p>Install VSCodium:<br> sudo apt update &amp;&amp; sudo apt install codium </p> <p>And that's that, aside from other applications you want to add. Now you're snap-free on Ubuntu LTS 26.04 :)</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/The_Hubster"> /u/The_Hubster </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1uagk9a/ubuntu_2604_lts_say_goodbye_to_snaps/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uagk9a/ubuntu_2604_lts_say_goodbye_to_snaps/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[7,000 Langflow servers are under attack. LangGraph and LangChain have the same holes]]></title>
<description><![CDATA[Your AI agent did exactly what it was designed to do. The framework underneath it just handed an attacker a shell on the box that holds your OpenAI key, your database credentials, and your CRM tokens.That is not a hypothetical. In a few months, three of the most widely deployed AI agent framework...]]></description>
<link>https://tsecurity.de/de/3611334/it-nachrichten/7000-langflow-servers-are-under-attack-langgraph-and-langchain-have-the-same-holes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611334/it-nachrichten/7000-langflow-servers-are-under-attack-langgraph-and-langchain-have-the-same-holes/</guid>
<pubDate>Fri, 19 Jun 2026 23:31:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Your AI agent did exactly what it was designed to do. The framework underneath it just handed an attacker a shell on the box that holds your OpenAI key, your database credentials, and your CRM tokens.</p><p>That is not a hypothetical. In a few months, three of the most widely deployed AI agent frameworks each turned a known, ordinary bug class into a way through. <a href="https://research.checkpoint.com/2026/from-sqli-to-rce-exploiting-langgraphs-checkpointer/">Check Point Research</a> chained a SQL injection in LangGraph’s SQLite checkpointer to full remote code execution. Tenable and VulnCheck tracked a path traversal in Langflow’s file upload endpoint to active, in-the-wild RCE. <a href="https://www.cyera.com/research/langdrained-3-paths-to-your-data-through-the-worlds-most-popular-ai-framework">Cyera</a> documented a path traversal in LangChain-core’s prompt loader that reads your secrets off disk. Two paths to a shell, one to your keys. They are the same bug, wearing three frameworks.</p><p>These frameworks became production infrastructure faster than anyone secured them. They store agent state, take file uploads, load prompt configs, and hold the credentials to databases, CRMs, and internal APIs. The edge tools watch traffic. The endpoint tools watch processes. Neither was built to treat an imported framework as a boundary worth guarding, and that blind spot is exactly where all three chains live, widening every week as these frameworks ship to production.</p><h2><b>The LangGraph chain, SQL injection to a Python shell</b></h2><p>Start with the one most teams pulled into production this quarter. LangGraph gives AI agents memory through checkpointers, the persistence layer that stores execution state. It has cleared over 50 million downloads a month. Yarden Porat of Check Point Research took that layer apart and found three vulnerabilities. Two of them chain to RCE.</p><p><a href="https://advisories.gitlab.com/pypi/langgraph-checkpoint-sqlite/CVE-2025-67644/">CVE-2025-67644</a>, rated CVSS 7.3, is a SQL injection in the SQLite checkpointer. The function that builds the WHERE clause for checkpoint lookups drops user-controlled filter keys straight into the query with no parameterization and no escaping. This does not hit everyone, but where it hits, it is serious. A deployment is exposed when it self-hosts LangGraph on the SQLite or Redis checkpointer and lets untrusted input reach get_state_history() or a similar history endpoint. Meet those conditions, and an attacker who controls the filter writes a fabricated row straight into the checkpoint table. Run LangChain’s managed LangSmith platform on PostgreSQL, and the exposure is gone.</p><p>Then <a href="https://advisories.gitlab.com/pypi/langgraph/CVE-2026-28277/">CVE-2026-28277</a>, CVSS 6.8, finishes the job. LangGraph’s msgpack checkpoint decoder rebuilds Python objects from the stored data, which lets it import a module and call a named function with attacker-supplied arguments. That step needs write access to the checkpoint store; the SQL injection is what grants it remotely. LangGraph loads the forged row as a legitimate checkpoint, the decoder runs the specified function, including os.system, and code executes under the identity of the agent server. A third issue, CVE-2026-27022, CVSS 6.5, reaches the same place through the Redis checkpointer.</p><p>There has been no confirmed exploitation in the wild yet. A working proof-of-concept is public in Check Point’s disclosure. The fixes are version bumps: langgraph-checkpoint-sqlite to 3.0.1, langgraph to 1.0.10, and langgraph-checkpoint-redis to 1.0.2.</p><h2><b>The Langflow chain, one unauthenticated request to RCE</b></h2><p>Langflow is the one already under attack. CVE-2026-5027, CVSS 8.8, is a path traversal in the POST /api/v2/files endpoint, which takes the filename straight from the form data and writes it to disk unsanitized. An attacker packs that filename with traversal sequences and drops a file anywhere, such as a cron job in /etc/cron.d/. Because Langflow ships with auto-login enabled in its default configuration, an exposed instance needs no credentials at all. A single unauthenticated request reaches the endpoint, and the next cron run hands over a shell.</p><p>VulnCheck’s Caitlin Condon confirmed exploitation on June 9: “Our Canaries observed exploitation of CVE-2026-5027 that successfully leveraged the path traversal to write what appear to be test files on victim systems.” Censys put roughly 7,000 exposed instances on the internet, most in North America. This is the third Langflow flaw to draw active exploitation this year, after <a href="https://www.probablypwned.com/article/langflow-cve-2025-34291-muddywater-account-takeover-rce">CVE-2025-34291</a>, which the Iranian state-sponsored group MuddyWater weaponized and which CISA added to its <a href="https://thehackernews.com/2026/05/cisa-adds-exploited-langflow-and-trend.html">Known Exploited Vulnerabilities catalog</a> in May. CVE-2026-5027 itself was patched in version 1.9.0, released April 15.</p><p>The timeline is what sets the clock. The patch shipped April 15. Attacks started in June, and <a href="https://www.thestack.technology/langflow-instances-are-getting-exploited-again/">VulnCheck added CVE-2026-5027 to its exploited-vulnerabilities list June 8</a> once its sensors caught the first in-the-wild hits. Every instance left unpatched between those two dates has been sitting in the open for almost two months. The lesson for security teams is to start the patch clock at disclosure, not at a federal catalog entry.</p><h2><b>The LangChain-core gap, arbitrary file reads through the prompt loader</b></h2><p>LangChain-core, the foundation under both, disclosed <a href="https://thehackernews.com/2026/03/langchain-langgraph-flaws-expose-files.html">CVE-2026-34070</a>, CVSS 7.5, a path traversal in its legacy prompt-loading API. The load_prompt() functions read a file path out of a config dict with no check against traversal sequences or absolute paths, so an attacker who influences that path reads arbitrary files the process can reach, including the .env file holding OPENAI_API_KEY and ANTHROPIC_API_KEY. Cyera paired it with CVE-2025-68664, CVSS 9.3, a deserialization flaw that resolves environment secrets through a crafted object. The fix versions differ, which matters when you patch: CVE-2026-34070 lands in <a href="https://security.snyk.io/vuln/SNYK-PYTHON-LANGCHAINCORE-15809257">langchain-core 1.2.22 and 0.3.86</a>; CVE-2025-68664 lands earlier in <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68664">1.2.5 and 0.3.81</a>. Clear both, or the higher-severity flaw stays live behind a patched one.</p><p>Three frameworks, three classic AppSec bugs. Path traversal. SQL injection. Unsafe deserialization. Nothing exotic, nothing AI-specific, just old vulnerabilities living inside new infrastructure. None of this is a frontier-model problem. It is plumbing, sitting in the layer where AI meets the enterprise.</p><h2><b>Why the scanner cannot see it</b></h2><p>Merritt Baer, CSO at <a href="https://www.enkryptai.com/">Enkrypt AI</a> and former deputy CISO at AWS, has named what makes this kind of failure hard to see coming. It does not announce itself as an AI problem. "CISOs will experience MCP insecurity not in the abstract, but when an employee pastes sensitive data into a tool, or when an attacker finds an unauthenticated MCP server in your cloud," Baer told VentureBeat. "It won't feel like 'AI risk.' It will feel like your traditional security program failing." The framework chains here are the same shape. An exposed Langflow instance is an unauthenticated server in your cloud, and the alert, if one fires, reads like an ordinary incident.</p><p>That is the gap in one sentence. The exploit lives in the framework your code imports. The WAF never sees a msgpack decoder running three layers down. The EDR watches the agent server make the same process calls it makes a thousand times a day and waves it through. Both tools are doing their job. Nobody scoped the framework itself as the thing that could turn on you. </p><p>The root cause is older than AI, and Baer names it. “MCP is shipping with the same mistake we’ve seen in every major protocol rollout: insecure defaults,” she told VentureBeat. “If we don’t build authentication and least privilege in from day one, we’ll be cleaning up breaches for the next decade.” Langflow’s auto-login is that mistake shipped. LangChain-core’s unguarded prompt loader is that mistake shipped. The convenient default is the vulnerability. And the moment an agent connects to anything, that risk compounds. “You’re not just trusting your own security, you’re inheriting the hygiene of every tool, every credential, every developer in that chain,” Baer said. “That’s a supply chain risk in real time.”</p><p>There is a governance failure layered on top of the technical one, and it is the same miscategorization Assaf Keren, chief security officer at Qualtrics and former CISO at PayPal, has flagged in adjacent tooling. “Most security teams still classify experience management platforms as ‘survey tools,’ which sit in the same risk tier as a project management app,” Keren told VentureBeat. “This is a massive miscategorization.” Swap in AI agent frameworks, and it still holds. Teams file LangGraph, Langflow, and LangChain under developer convenience, then wire them into databases, CRMs, and provider keys. “Security has to be an enabler,” Keren said, “or teams route around it.” These frameworks are what routing around it looks like.</p><p>Follow the money and it points at the same layer. On its <a href="https://www.fool.com/earnings/call-transcripts/2026/06/03/crowdstrike-crwd-q1-2027-earnings-transcript/">Q1 fiscal 2027 earnings call</a>, CrowdStrike reported its AI detection and response line up more than 250% sequentially, and on June 17 it <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-advances-ai-and-cloud-security-operations-on-aws/">extended that runtime coverage</a> to agent, LLM, and MCP traffic on AWS. George Kurtz, the company’s co-founder and CEO, named the reason in plain terms: “Agents run on the endpoint. They make tool calls, access files, invoke APIs, and move data at the process level.” That is the exact plumbing these chains abuse, and real money is now moving to the layer your AppSec scan skips.</p><h2><b>What to put in front of the board</b></h2><p>The board does not need the CVE numbers. It needs the consequence, and Keren draws the line the board cares about. Most teams have mapped the technical blast radius. “But not the business blast radius,” Keren told VentureBeat. “When an AI engine triggers a compensation adjustment based on poisoned data, the damage is not a security incident. It is a wrong business decision executed at machine speed.” A framework RCE is the same problem one layer earlier. The agent does not just leak a credential; it acts on production systems with it, and the business sees an outcome no one can explain.</p><p>So frame it the way a board frames it: we run AI agent frameworks in production that can be turned into remote shells through bugs our scanners are not built to find, all three are patched, one is under active attack, and here is the date every instance is verified and closed. None of this required custom malware or a zero-day.</p><h2><b>The six-question checklist</b></h2><p>Six trust boundaries, one per row, each with the question, the proof point, the command, the fix, and the board line. Run it tonight.</p><table><tbody><tr><td><p><b>Trust-Boundary Question</b></p></td><td><p><b>Proof Point</b></p></td><td><p><b>What Broke</b></p></td><td><p><b>Verify Before You Install</b></p></td><td><p><b>The Fix</b></p></td><td><p><b>Board Language</b></p></td></tr><tr><td><p><b>1. Can the agent's state store be poisoned with code?</b></p></td><td><p>LangGraph SQLi-to-RCE chain. CVE-2025-67644 (CVSS 7.3) chains into CVE-2026-28277 (CVSS 6.8). PoC public, no in-the-wild use yet.</p></td><td><p>Filter keys interpolated into SQL with an f-string. Forged checkpoint row hits the msgpack decoder, which imports and runs an attacker-named callable.</p></td><td><p>pip show langgraph-checkpoint-sqlite. Below 3.0.1 = vulnerable. Confirm get_state_history() is not exposed to network input.</p></td><td><p>Upgrade langgraph-checkpoint-sqlite to 3.0.1, langgraph to 1.0.10, langgraph-checkpoint-redis to 1.0.2.</p></td><td><p>“Our agent memory layer can be tricked into running attacker code. Vendor has patched it. We are upgrading and confirming the endpoint is not exposed.”</p></td></tr><tr><td><p><b>2. Can an unauthenticated request write a file to our agent server?</b></p></td><td><p>Langflow CVE-2026-5027 (CVSS 8.8). On VulnCheck KEV (June 8). Active exploitation confirmed June 9. ~7,000 exposed instances (Censys).</p></td><td><p>Path traversal in POST /api/v2/files. Filename unsanitized. Auto-login on by default. Two HTTP calls drop a cron job and earn a shell.</p></td><td><p>Query Censys or Shodan for your Langflow, Flowise, n8n, and Dify instances on the perimeter. Check whether auto-login is enabled.</p></td><td><p>Upgrade Langflow to 1.9.0+. Disable auto-login. Pull AI dev tools behind VPN or zero-trust. Isolate port 7860.</p></td><td><p>“Our AI dev tools are reachable from the internet with login off. This exact flaw is under active attack now. We are pulling them behind access controls today.”</p></td></tr><tr><td><p><b>3. Can our prompt loader read files it should never touch?</b></p></td><td><p>LangChain-core CVE-2026-34070 (CVSS 7.5), path traversal in the prompt-loading API. Paired with deserialization CVE-2025-68664 (CVSS 9.3).</p></td><td><p>load_prompt() reads a config-supplied path with no traversal check, returning files such as the .env holding OPENAI_API_KEY and ANTHROPIC_API_KEY.</p></td><td><p>pip show langchain-core. Below 1.2.22 (1.x) or 0.3.86 (0.x) = vulnerable. Audit any code passing user-influenced paths to load_prompt().</p></td><td><p>Upgrade langchain-core past both fixes: 1.2.22 / 0.3.86 (CVE-2026-34070) and 1.2.5 / 0.3.81 (CVE-2025-68664). Replace load_prompt() with an allowlisted directory. Run as non-root.</p></td><td><p>“Our prompt system could be steered to read our API keys off disk. We are patching and removing the legacy loader.”</p></td></tr><tr><td><p><b>4. Does a compromised framework hand over every credential at once?</b></p></td><td><p>These frameworks are often deployed with provider keys, database credentials, and integration tokens available to the process environment. Cyera documents the credential-exfiltration path.</p></td><td><p>One RCE on the agent server exposes every secret the process can read. Blast radius is the full credential set, not one app.</p></td><td><p>Inventory which secrets each framework process can reach. Confirm keys come from a secrets manager, not static .env files.</p></td><td><p>Move provider keys to ephemeral injection. Rotate any key a vulnerable instance could have read. Scope each key to least privilege.</p></td><td><p>“A single break in one AI framework exposes the keys to every model and data store it touches. We are rotating and scoping them now.”</p></td></tr><tr><td><p><b>5. Are these frameworks running outside security governance?</b></p></td><td><p>A prior Langflow flaw, CVE-2025-34291, was weaponized by Iranian-linked MuddyWater and added to CISA KEV in May. Shadow AI is the new shadow IT.</p></td><td><p>Teams stand frameworks up for speed, give them credentials, and never bring them under review. The security team cannot see what it does not know exists.</p></td><td><p>Run a discovery sweep for AI frameworks outside change management. Map each to an owner and an approval record.</p></td><td><p>Assign every framework a documented owner and a place in the approval process. Offer a sanctioned alternative so teams do not route around you.</p></td><td><p>“We have AI frameworks in production that no one formally approved. We are bringing them under governance, not banning them.”</p></td></tr><tr><td><p><b>6. Can our scanners even see inside the framework at runtime?</b></p></td><td><p>Runtime detection is forming around this layer: CrowdStrike Falcon AIDR expanded to AWS June 17 (Bedrock, Kiro, Strands); its <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-expands-project-quiltworks-with-aws-hardening-the-cloud-attack-surface-against-frontier-ai-risk/">QuiltWorks coalition</a> now covers cloud workloads.</p></td><td><p>WAF reads HTTP at the edge. EDR watches the endpoint. By default, neither reliably models a msgpack decoder or a prompt loader three layers down in an imported framework as a separate trust boundary.</p></td><td><p>Test whether your AppSec scan covers third-party framework internals. Track CVEs by dependency, not just by what your edge tools can parse.</p></td><td><p>Add framework dependencies to vuln management. Treat agent output and stored state as untrusted. Patch on disclosure, not on KEV listing.</p></td><td><p>“Our scanners check our code, not the frameworks our code imports. We are closing that blind spot and patching on disclosure, not waiting for the federal catalog.”</p></td></tr></tbody></table><p><i>How to read this table: each row is one trust boundary, left to right, from the question to ask to the line to read your board.</i></p><h2><b>Give the board the deadline, not the technology</b></h2><p>The fixes are not a re-architecture. They are version bumps and config changes you can land this week. The exposure is the gap between the day the patch shipped and the day your team runs the checks, and right now that gap is measured in months. The frameworks did exactly what they were built to do. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab 19.1: Admins erhalten Hoheit über GitLab-Duo-Aktivierung]]></title>
<description><![CDATA[Admins beziehungsweise Besitzer können GitLab Duo für eine Instanz oder Top-Level-Gruppe zentral aktivieren. Die Secrets-Erkennung erhält KI-Unterstützung.]]></description>
<link>https://tsecurity.de/de/3609798/it-nachrichten/gitlab-191-admins-erhalten-hoheit-ueber-gitlab-duo-aktivierung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609798/it-nachrichten/gitlab-191-admins-erhalten-hoheit-ueber-gitlab-duo-aktivierung/</guid>
<pubDate>Fri, 19 Jun 2026 11:03:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Admins beziehungsweise Besitzer können GitLab Duo für eine Instanz oder Top-Level-Gruppe zentral aktivieren. Die Secrets-Erkennung erhält KI-Unterstützung.]]></content:encoded>
</item>
<item>
<title><![CDATA[Schwere Sicherheitslücke in aktuellen Windows-Systemen: Microsoft verspricht, sie zu schließen]]></title>
<description><![CDATA[Vor einer Woche veröffentlichte der anonyme Sicherheitsforscher “Nightmare Eclipse” Informationen zu „Rogue Planet“, einer sogenannten „Zero-Day“-Sicherheitslücke in Microsofts Sicherheitsprogramm Defender (lesen Sie hier: Was ist Microsoft Defender und wie gut schützt er vor Viren und anderen Be...]]></description>
<link>https://tsecurity.de/de/3609551/it-nachrichten/schwere-sicherheitsluecke-in-aktuellen-windows-systemen-microsoft-verspricht-sie-zu-schliessen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609551/it-nachrichten/schwere-sicherheitsluecke-in-aktuellen-windows-systemen-microsoft-verspricht-sie-zu-schliessen/</guid>
<pubDate>Fri, 19 Jun 2026 08:47:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Vor einer Woche veröffentlichte der anonyme Sicherheitsforscher “Nightmare Eclipse” Informationen zu „<a href="https://blog.projectnightcrawler.dev/posts/2026-06-16-rogueplanet-another-quick-statement/">Rogue Planet“</a>, einer sogenannten „Zero-Day“-Sicherheitslücke in Microsofts Sicherheitsprogramm Defender (lesen Sie hier: <a href="https://www.pcwelt.de/article/2652374/was-ist-microsoft-defender-und-wie-gut-schutzt-es-vor-viren-und-anderen-bedrohungen.html" target="_blank" rel="noreferrer noopener">Was ist Microsoft Defender und wie gut schützt er vor Viren und anderen Bedrohungen?</a>). Die Schwachstelle, die die offizielle Bezeichnung CVE-2026-50656 erhalten hat, kann von Hackern ausgenutzt werden, um vollständigen Zugriff auf unsere Computer zu erlangen.</p>



<p>Die von „Nightmare Eclipse“ veröffentlichte Schwachstelle steckt in vollständig gepatchten Windows 10- und Windows 11-Geräten und ermöglicht es Angreifern, über eine Race-Condition in Microsoft Defender Eingabeaufforderungen mit SYSTEM-Rechten zu erzeugen. Der Sicherheitsexperte veröffentlichte einen Proof-of-Concept-Exploit in einem selbst gehosteten Git-Repository und behauptete, Microsoft habe zuvor seine Repos, in denen Exploits auf GitHub und GitLab gehostet wurden, ins Visier genommen und entfernt.</p>



<p>Der Sicherheitsexperte schreibt: „Bei dem Exploit handelt es sich um eine Race Condition, daher ist der Erfolg ungewiss. Auf einigen Rechnern konnte ich eine Erfolgsquote von 100 % erzielen, während es auf anderen nur schwer funktionierte. Der PoC für RoguePlanet funktioniert unabhängig davon, ob der Echtzeitschutz aktiviert ist oder nicht.</p>



<p>In einer Stellungnahme gegenüber dem IT-Sicherheitsnachrichtenportal <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-working-on-defender-patch-for-rogueplanet-zero-day/" data-type="link" data-id="https://www.bleepingcomputer.com/news/microsoft/microsoft-working-on-defender-patch-for-rogueplanet-zero-day/">Bleeping Computer</a> erklärte ein Sprecher von Microsoft, dass das Unternehmen derzeit intensiv an der Entwicklung eines Sicherheitspatches für „Rogue Planet“ arbeite, der hoffentlich in Kürze für die Öffentlichkeit bereitgestellt werde. Microsoft sagt laut Bleepingcomputer:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Microsoft ist sich einer Berechtigungserweiterung in der Microsoft Malware Protection Engine von Microsoft Defender (<a href="https://www.pcwelt.de/article/2661230/windows-defender-alle-versionen-ueberblick.html" target="_blank" rel="noreferrer noopener">Windows Defender: Alle Versionen im Überblick</a>) bewusst, die öffentlich als ‚RoguePlanet‘ bezeichnet wird: Wir arbeiten daran, ein hochwertiges Sicherheitsupdate bereitzustellen, das diese Sicherheitslücke behebt. Wir werden Informationen zu dieser CVE bereitstellen, sobald das Update verfügbar ist.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>
</blockquote>



<p>In letzter Zeit hat derselbe Sicherheitsforscher Informationen über eine ganze Reihe von Sicherheitslücken in Windows veröffentlicht, darunter „Blue Hammer“, „Red Sun“, „Green Plasma“, „Mini Plasma“, „Yellow Key“ und „Undefend“.</p>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/2490003/windows-security-vs-microsoft-defender-wichtige-unterschiede-die-sie-kennen-sollten.html" target="_blank" rel="noreferrer noopener">Windows-Sicherheit vs. Microsoft Defender: Diese Unterschiede sollten Sie kennen</a></li>



<li><a href="https://www.pcwelt.de/article/2043389/windows-defender-einrichten-nutzen.html" target="_blank" rel="noreferrer noopener">Windows Defender optimal einrichten und nutzen</a></li>
</ul>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab erweitert Kooperation mit Google]]></title>
<description><![CDATA[Die Anforderungen an moderne Softwareentwicklung steigen kontinuierlich. Unternehmen müssen nicht nur Anwendungen schneller bereitstellen, sondern gleichzeitig Sicherheitsvorgaben, Compliance-Anforderungen und den Einsatz künstlicher Intelligenz unter einen Hut bringen. 

Tags: #GitLab | #Google]]></description>
<link>https://tsecurity.de/de/3608254/it-security-nachrichten/gitlab-erweitert-kooperation-mit-google/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608254/it-security-nachrichten/gitlab-erweitert-kooperation-mit-google/</guid>
<pubDate>Thu, 18 Jun 2026 17:26:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2025/08/Google-Quelle-BobNoah-Shutterstock-2497569717-1920.jpg" class="attachment-full size-full wp-post-image" alt="Google" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2025/08/Google-Quelle-BobNoah-Shutterstock-2497569717-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2025/08/Google-Quelle-BobNoah-Shutterstock-2497569717-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2025/08/Google-Quelle-BobNoah-Shutterstock-2497569717-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2025/08/Google-Quelle-BobNoah-Shutterstock-2497569717-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2025/08/Google-Quelle-BobNoah-Shutterstock-2497569717-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="GitLab erweitert Kooperation mit Google 1"></p>
    Die Anforderungen an moderne Softwareentwicklung steigen kontinuierlich. Unternehmen müssen nicht nur Anwendungen schneller bereitstellen, sondern gleichzeitig Sicherheitsvorgaben, Compliance-Anforderungen und den Einsatz künstlicher Intelligenz unter einen Hut bringen. 

<p>Tags: <a href="https://www.it-daily.net/thema/gitlab">#GitLab</a> | <a href="https://www.it-daily.net/thema/google">#Google</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers abuse Google Ads, GitLab, and Claude to deliver malware]]></title>
<description><![CDATA[Threat actors are abusing trusted platforms, including Google Ads, GitLab pages, and Claude’s shared chat feature, to trick users into executing malicious commands on their systems.



Disguised as popular AI developer tools, the threat actors used ClickFix social engineering attacks, where victi...]]></description>
<link>https://tsecurity.de/de/3607819/it-security-nachrichten/attackers-abuse-google-ads-gitlab-and-claude-to-deliver-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607819/it-security-nachrichten/attackers-abuse-google-ads-gitlab-and-claude-to-deliver-malware/</guid>
<pubDate>Thu, 18 Jun 2026 14:54:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Threat actors are abusing trusted platforms, including Google Ads, GitLab pages, and Claude’s shared chat feature, to trick users into executing malicious commands on their systems.</p>



<p>Disguised as popular AI developer tools, the threat actors used ClickFix social engineering attacks, where victims were tricked into manually executing malicious commands. Typically, this involved copying and pasting PowerShell or terminal commands, <a href="https://www.trendmicro.com/en/research/26/f/claudeai-shared-chat-abused-in-malvertising.html" target="_blank" rel="noreferrer noopener">noted</a> researchers at TrendAI.</p>



<p>The campaign funnelled more than 2,000 victims from sponsored Google search results for popular AI developer tools to malicious download pages before leveraging the claude.ai shared-chat feature as another stage in the attack chain.</p>



<p>The campaign demonstrates how threat actors are exploiting trust in widely used AI platforms to make social-engineering attacks more convincing and harder to detect.</p>



<h2 class="wp-block-heading">Inside the six-wave campaign</h2>



<p>Unlike traditional malware campaigns that rely on suspicious domains or fake download websites, this attack chain was built almost entirely on legitimate services. The threat actors used 92 unique malicious hostnames across GitLab pages, impersonated legitimate brand names including ChatGPT Codex, Perplexity, <a href="https://www.csoonline.com/article/4164250/critical-cursor-bug-could-turn-routine-git-into-rce.html?utm=hybrid_search">Cursor IDE</a>, JetBrains, Claude AI, and <a href="https://www.csoonline.com/article/4168867/claude-in-chrome-is-taking-orders-from-the-wrong-extensions.html?utm=hybrid_search">claude.ai</a>, and simultaneously ran Mac utility scam lures.</p>



<p>The campaign was spread across seven weeks, where weekly campaigns introduced new pages and keywords.</p>



<p>The first wave of the campaign launched between April 8-13, with claude-code-app.gitlab[.]io as the primary lure, supported by claudeapp.gitlab[.]io. Simultaneously, Mac utility-themed lures (mac-clean-storage.gitlab[.]io, mac-guide-tool.gitlab[.]io) were also found to have been deployed. During this wave, a single Google Ads campaign ID (23736589328) resulted in driving the majority of the traffic.</p>



<p>During the next wave spanning April 14-21, the campaign was diversified with the new Claude-themed variants, including gitlab.io domain (claude-tool-app, claud-desktop-app, claudesktop, claude-desktop-apps) alongside expanded Mac utility lures (macsupp-group, macsupp-usb, jetbrains-apps-group).</p>



<p>The brand impersonation was expanded during the third wave with the introduction of perplexity-platform.gitlab.io and chatgpt-codex.gitlab[.]io, while also creating claude-desktop-lm.gitlab[.]io  and cladesktop.gitlab[.]io.</p>



<p>During the fourth wave between April 29 and May 5, the operators pivoted significantly toward ChatGPT and <a href="https://www.csoonline.com/article/4142354/openai-says-codex-security-found-11000-high-impact-bugs-in-a-month.html?utm=hybrid_search">Codex</a> branding with codexgpt.gitlab[.]io , chatgpt-codex-app.gitlab[.]io, and chatgpt-codex-lm.gitlab[.]io, while the Claude-themed attacks continued.</p>



<p>In the fifth wave, spanning May 6-14, the threat actors moved their campaign from self-hosted GitLab Pages to abusing claude.ai’s legitimate shared chat feature. For this, claude.ai’s “share” feature was leveraged to create persistent, publicly accessible URLs on a fully trusted domain and then used Google Ads to direct victims to these weaponized pages, claimed the research. </p>



<p>During the sixth wave, between May 21 and June 14, the threat actors had completely shifted to claude.ai’s shared chat feature.</p>



<p>The campaign appears to have been designed primarily to target developers and technical users, say experts.</p>



<p>“An interaction with a Claude can be perceived as reliable because the users have become accustomed to considering AI tools as sources of productivity tips and technical advice. In this scenario, when users are provided with harmful instructions via an AI platform, there is a good chance that they will comply with them automatically,” explained Devroop Dhar, co-founder and India CEO at Primus Partners.</p>



<h2 class="wp-block-heading">Reputation-based defenses fell short</h2>



<p>Security experts say the campaign’s success stemmed from its ability to leverage trusted platforms at every stage of the attack chain, making malicious activity appear like normal user behavior.</p>



<p>“What makes this attack chain particularly effective is that it does not ask the victim to trust something obviously suspicious. Instead, it borrows trust from familiar brands, legitimate ad infrastructure, reputable hosting, and an AI platform that many developers already use in their daily workflow. This reduced the psychological friction that normally makes users pause before clicking or executing something,” said Amit Jaju, senior managing director at Ankura Consulting.</p>



<p>This is also a strong example of trust stacking. Each layer looks individually legitimate, so the full chain appears safer than it really is, added Jaju.</p>



<p>By leveraging platforms that organizations routinely allow and trust, the attackers were able to blend malicious activity into normal user workflows, making detection significantly more difficult.</p>



<p>Dhar added that in most cases, access to applications such as Google, GitLab, and AI applications is not blocked, as this could hinder operations within an organization. The reputation-based security systems cannot work efficiently here since the domain in question is seen as a reputable one, meaning security personnel will have to dig deeper into behaviour and user actions.</p>



<h2 class="wp-block-heading">Breaking the attack chain</h2>



<p>If a developer falls victim, the blast radius can be much larger than a normal user compromise. Jaju warned that a developer machine often contains browser session cookies, SSO tokens, SSH keys, Git credentials, source code, cloud CLI tokens, package manager credentials, secrets stored in local files, and access to internal documentation or collaboration platforms. </p>



<p>From there, attackers can move into code repositories, <a href="https://www.csoonline.com/article/4165420/sap-npm-package-attack-highlights-risks-in-developer-tools-and-ci-cd-pipelines.html?utm=hybrid_search">CI/CD pipelines</a>, cloud environments, container registries, ticketing systems, and enterprise messaging platforms. In some cases, they may not need to steal passwords at all because session tokens or authenticated browser sessions are enough to bypass part of the security stack.</p>



<p>While the campaign relied heavily on trusted platforms, organizations can still disrupt attacks at multiple points.</p>



<p>Dhar noted the first thing to understand here is that not all cyberattacks necessarily require malicious software. Nowadays, more and more attackers try to persuade victims into performing actions by themselves. Hence, one solution might be limiting unnecessary administrative privileges, monitoring shell and PowerShell executions, and detecting any suspicious behaviour. Additionally, developer PCs might need to be monitored because of the high level of access they have.</p>



<p>From a control standpoint, enterprises should restrict local admin rights and enforce least privilege on developer endpoints. They should also segment developer environments and separate high-risk browsing from privileged engineering workflows, where feasible, added Jaju.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dropping Elephant Hackers Use China-Themed Loader Chain to Deploy In-Memory RAT]]></title>
<description><![CDATA[A sophisticated malvertising and social-engineering campaign that pivoted from weaponized GitLab Pages to abusing claude.ai’s shared chat feature, enabling operators to deliver an in-memory remote-access trojan (RAT) via a China-themed loader chain. Across seven weeks (April 8–June 14, 2026) inve...]]></description>
<link>https://tsecurity.de/de/3607655/it-security-nachrichten/dropping-elephant-hackers-use-china-themed-loader-chain-to-deploy-in-memory-rat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607655/it-security-nachrichten/dropping-elephant-hackers-use-china-themed-loader-chain-to-deploy-in-memory-rat/</guid>
<pubDate>Thu, 18 Jun 2026 14:09:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A sophisticated malvertising and social-engineering campaign that pivoted from weaponized GitLab Pages to abusing claude.ai’s shared chat feature, enabling operators to deliver an in-memory remote-access trojan (RAT) via a China-themed loader chain. Across seven weeks (April 8–June 14, 2026) investigators tracked 106 unique malicious hostnames across six attack waves, revealing rapid infrastructure rotation, targeted geographic […]</p>
<p>The post <a href="https://gbhackers.com/china-themed-loader-chain/">Dropping Elephant Hackers Use China-Themed Loader Chain to Deploy In-Memory RAT</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dropping Elephant Hackers Use China-Themed Loader Chain to Deploy In-Memory RAT]]></title>
<description><![CDATA[A sophisticated malvertising and social-engineering campaign that pivoted from weaponized GitLab Pages to abusing claude.ai’s shared chat feature, enabling operators to deliver an in-memory remote-access trojan (RAT) via a China-themed loader chain. Across seven weeks (April 8–June 14, 2026) inve...]]></description>
<link>https://tsecurity.de/de/3607648/it-security-nachrichten/dropping-elephant-hackers-use-china-themed-loader-chain-to-deploy-in-memory-rat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607648/it-security-nachrichten/dropping-elephant-hackers-use-china-themed-loader-chain-to-deploy-in-memory-rat/</guid>
<pubDate>Thu, 18 Jun 2026 14:09:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A sophisticated malvertising and social-engineering campaign that pivoted from weaponized GitLab Pages to abusing claude.ai’s shared chat feature, enabling operators to deliver an in-memory remote-access trojan (RAT) via a China-themed loader chain. Across seven weeks (April 8–June 14, 2026) investigators…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/dropping-elephant-hackers-use-china-themed-loader-chain-to-deploy-in-memory-rat/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/dropping-elephant-hackers-use-china-themed-loader-chain-to-deploy-in-memory-rat/">Dropping Elephant Hackers Use China-Themed Loader Chain to Deploy In-Memory RAT</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New CISO appointments 2026]]></title>
<description><![CDATA[The upper ranks of corporate security are seeing a high rate of change as companies try to adapt to the evolving threat landscape. Many companies are hiring a chief security officer (CSO) or chief information security officer (CISO) for the first time to support a deeper commitment to information...]]></description>
<link>https://tsecurity.de/de/3607427/it-security-nachrichten/new-ciso-appointments-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607427/it-security-nachrichten/new-ciso-appointments-2026/</guid>
<pubDate>Thu, 18 Jun 2026 12:54:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The upper ranks of corporate security are seeing a high rate of change as companies try to adapt to the evolving threat landscape. Many companies are hiring a chief security officer (CSO) or <a href="https://www.csoonline.com/article/566757/what-is-a-ciso-responsibilities-and-requirements-for-this-vital-leadership-role.html">chief information security officer</a> (CISO) for the first time to support a deeper commitment to information security.</p>



<p>Follow this column to keep up with new appointments to senior-level security roles and perhaps gain a little insight into hiring trends. If you have an announcement of your own that you would like us to include here, contact Peter Sayer, executive editor of news, at <a href="mailto:peter_sayer@foundryco.com?subject=New%20CISO%20appointment">peter_sayer@foundryco.com</a>.</p>



<h2 class="wp-block-heading">New CISO appointments in June 2026</h2>



<h3 class="wp-block-heading">SolarWinds appoints Justin Henkel as CISO</h3>



<p>IT management software vendor SolarWinds has named Justin Henkel its new CISO. Henkel was previously deputy CISO at OneTrust, and before that spent 25 years as an intelligence officer in the US Air Force. </p>



<h2 class="wp-block-heading">New CISO appointments in March 2026</h2>



<h3 class="wp-block-heading">Kathy Wang joints micro1 as CISO</h3>



<p>Frontier AI model training company micro1 has hired Kathy Wang as CISO. She was most recently CISO at hospitality software developer Otelier, and has previously held top cybersecurity roles at Discord and GitLab.</p>



<h3 class="wp-block-heading">Green Impact Exchange names John Visneski CISO</h3>



<p>John Visneski has joined stock exchange operator Green Impact Exchange as CISO. He was previously CISO at MGM Studios, and following that company’s acquisition by Amazon became head fo security for mergers and acquisitions. His cybersecurity career began with the US Air Force, where he served as cyber advisor to the Secretary and Chief of Staff of teh Air Force.</p>



<h2 class="wp-block-heading">New CISO appointments in January 2026</h2>



<h3 class="wp-block-heading">Julien Mousqueton joins Cohesity as field CISO for Europe</h3>



<p>Data security firm Cohesity has hired Julien Mousqueton as field CISO for Europe. His previous role was as CTO at IT service provider Computacenter. He is a reservist advisor for OFAC, the French national police force’s anti-cybercrime division, and created the real-time ransomware activity-tracking platform <a href="https://ransomware.live/" target="_blank" rel="noreferrer noopener">ransomware.live</a>.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS targets software release bottlenecks with DevOps Agent update]]></title>
<description><![CDATA[The problem with software development today may no longer be writing code. With AI coding assistants generating code faster than ever, the bigger challenge is reviewing, testing, and safely releasing it.



AWS is betting that software teams need help with that part of the process, adding release...]]></description>
<link>https://tsecurity.de/de/3605222/ai-nachrichten/aws-targets-software-release-bottlenecks-with-devops-agent-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605222/ai-nachrichten/aws-targets-software-release-bottlenecks-with-devops-agent-update/</guid>
<pubDate>Wed, 17 Jun 2026 17:05:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The problem with software development today may no longer be writing code. With AI coding assistants generating code faster than ever, the bigger challenge is reviewing, testing, and safely releasing it.</p>



<p>AWS is betting that software teams need help with that part of the process, adding release management features to its DevOps Agent.</p>



<p>The new features, currently in preview, automatically assess code changes against organizational standards, identify potential release risks, and generate tests tailored to individual changes before they reach production.</p>



<p>The release readiness feature, in particular, runs the code in an AWS-managed isolated environment, executing lightweight user journey tests to verify the software builds, runs, and passes basic functional checks before the change enters the pipeline, the company wrote in a blog post.</p>



<p>The findings of these tests can be viewed through the DevOps Agent console, as comments on pull requests in GitHub or GitLab, or can be invoked directly through IDEs via <a href="https://www.infoworld.com/article/4135310/aws-adds-design-first-and-bugfix-workflows-to-kiro.html">Kiro</a> or the <a href="https://www.infoworld.com/article/4116598/anthropic-expands-claude-code-beyond-developer-tasks-with-cowork.html">Claude Code</a> plugin, it added.</p>



<h2 class="wp-block-heading">Targeting AI-era software delivery bottlenecks</h2>



<p>Running code in isolated environments and delivering the results directly through developer tools helps address two longstanding challenges in software delivery, said <a href="https://pareekh.com/about/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, principal analyst at Pareekh Consulting.</p>



<p>It enables teams to validate how code changes behave before deployment, catching issues that static analysis may overlook, while reducing context switching by embedding findings into existing workflows, in turn accelerating fixes, Jain said.</p>



<p>The analyst pointed out that the release readiness capability addresses a key bottleneck in AI-driven software development: “While AI coding agents can generate code quickly, reviews, compliance checks, dependency validation, and release approvals still slow deployment.”</p>



<p>“By automatically checking code changes against internal standards, security policies, and dependency impacts, AWS helps developers, <a href="https://www.infoworld.com/article/2255028/what-is-devops-bringing-dev-and-ops-together-for-better-software.html">DevOps</a> teams, and <a href="https://www.infoworld.com/article/2257232/what-is-an-sre-the-vital-role-of-the-site-reliability-engineer.html">SREs</a> identify issues earlier, reduce manual review effort, and improve release confidence,” Jain added.</p>



<p>These gains in productivity for developers could also translate into tangible business benefits for CIOs, according to Jain.</p>



<p>“Release readiness as a feature could help enterprises capture more value from AI-generated code while reducing operational overhead by eliminating the need for additional QA and DevOps resources. This means that they can accelerate software delivery without sacrificing reliability,” the analyst noted.</p>



<h2 class="wp-block-heading">Autonomous testing before merging code</h2>



<p>While release readiness reviews focus on assessing whether a code change is safe to move through the delivery pipeline, AWS is also adding a separate feature aimed at validating how those changes behave in production-like environments.</p>



<p>Named autonomous release testing, the new capability generates and runs change-specific test plans for web and API-based applications in customer-provisioned, production-like environments before the change actually merges, the company wrote in the blog post.</p>



<p>For Jain, autonomous release testing is “even more” important for developers and SREs as it “automates one of the most time-consuming parts of software delivery.”</p>



<p>“Developers spend less time creating and maintaining tests, while SREs benefit from fewer rollbacks and improved system reliability,” Jain said.</p>



<p>These benefits stem from the feature’s ability to automatically generate tests tailored to individual code changes, covering functional correctness, behavioral regressions, and integration scenarios that might otherwise require significant manual effort, Jain added.</p>



<p>However, AWS is not alone in trying to bring AI deeper into the software delivery lifecycle.</p>



<p>Microsoft-owned GitHub has been expanding Copilot’s code review capabilities, allowing the service to automatically <a href="https://docs.github.com/en/copilot/concepts/agents/code-review" target="_blank" rel="noreferrer noopener">review pull requests</a>, suggest fixes, and provide feedback directly within developer workflows.</p>



<p>Google, meanwhile, has been steadily broadening the scope of <a href="https://docs.cloud.google.com/gemini/docs/code-review/review-repo-code" target="_blank" rel="noreferrer noopener">Gemini Code Assist</a> beyond code generation to support software development tasks such as code review and developer assistance.</p>



<p>AWS’s differentiation, though, according to Jain, lies in tying those capabilities to release management and operational workflows that span development and production environments.</p>



<h2 class="wp-block-heading">Availability and pricing</h2>



<p>For development teams interested in evaluating DevOps Agent’s new capabilities, AWS said both features are available in preview at no additional cost in the US East (N. Virginia) region.</p>



<p>AWS DevOps Agent, billed per agent-second, is included in the AWS Free Tier for new customers.</p>



<p>Additionally, new AWS DevOps Agent customers receive a 2-month free trial starting with their first operational task after general availability.</p>



<p>Each trial month includes up to 10 agent spaces, 20 hours of investigations (incident response), 15 hours of evaluations (incident prevention), and 20 hours of on-demand SRE tasks (chat), the company said.</p>



<p>Once those limits are exhausted, customers are charged based on consumption, with investigations, evaluations, and on-demand SRE tasks each priced at $0.0083 per agent-second, AWS added.</p>



<p>A prerequisite for using the new release management features includes connecting at least one GitHub or GitLab repository to an AWS DevOps Agent Space.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wine/Wayland: support for fractional scaling protocol merged]]></title>
<description><![CDATA[https://gitlab.winehq.org/wine/wine/-/merge_requests/11101 Wine upstream has merged support for the fractional_scale_v1 Wayland protocol. From the MR:  "This enables users to have different fractional scales per display under wine without causing blur. This matches the behavior under XWayland and...]]></description>
<link>https://tsecurity.de/de/3601927/linux-tipps/winewayland-support-for-fractional-scaling-protocol-merged/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601927/linux-tipps/winewayland-support-for-fractional-scaling-protocol-merged/</guid>
<pubDate>Tue, 16 Jun 2026 15:11:16 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><a href="https://gitlab.winehq.org/wine/wine/-/merge_requests/11101">https://gitlab.winehq.org/wine/wine/-/merge_requests/11101</a></p> <p>Wine upstream has merged support for the <code>fractional_scale_v1</code> Wayland protocol. From the MR:</p> <blockquote> <p>"This enables users to have different fractional scales per display under wine without causing blur. This matches the behavior under XWayland and is actually better than the XWayland behavior when using multiple displays with different fractional scales."</p> </blockquote> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/eszlari"> /u/eszlari </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1u7c1bw/winewayland_support_for_fractional_scaling/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1u7c1bw/winewayland_support_for_fractional_scaling/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[v15.13.3]]></title>
<description><![CDATA[@oh-my-pi/pi-agent-core
Added

Added the interruptible tool field: when set, the agent loop may abort the tool mid-execution to deliver a queued steering message (honored only in immediate interrupt mode).
Added support for gemini and gemma as valid owned tool syntax values in environment configu...]]></description>
<link>https://tsecurity.de/de/3598860/tools/v15133/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598860/tools/v15133/</guid>
<pubDate>Mon, 15 Jun 2026 13:09:42 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-agent-core</h2>
<h3>Added</h3>
<ul>
<li>Added the <code>interruptible</code> tool field: when set, the agent loop may abort the tool mid-execution to deliver a queued steering message (honored only in <code>immediate</code> interrupt mode).</li>
<li>Added support for <code>gemini</code> and <code>gemma</code> as valid owned tool syntax values in environment configuration</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>pruneToolOutputs</code> blanking tiny tool results during overflow pruning: results below <code>50</code> tokens (<code>MIN_PRUNE_TOKENS</code>) are no longer replaced with the <code>[Output truncated - N tokens]</code> placeholder, which cost more tokens than the result itself and churned the prompt cache for zero savings.</li>
</ul>
<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Added the <code>gemini</code> in-band tool-call syntax with Python-style <code>tool_code</code> blocks and <code>default_api</code> invocations</li>
<li>Added the <code>gemma</code> token-delimited in-band tool-call syntax using <code>&lt;|tool_call&gt;</code> and <code>&lt;|tool_response&gt;</code> blocks</li>
<li>Added <code>gemini</code> and <code>gemma</code> to owned stream tool-result token detection so their tool responses are recognized</li>
<li>Fixed truncated Gemini and Gemma tool blocks from being emitted as plain text during streaming</li>
<li>Added the Azure OpenAI provider definition (<code>azure</code>) to the registry; <code>AZURE_OPENAI_API_KEY</code> resolves as its env-var API key via the catalog provider table.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Gemini tool-call examples now render without the <code>default_api.</code> namespace prefix, keeping <code>&lt;example&gt;</code> blocks concise. The live wire format still uses <code>default_api.</code> per the Gemini grammar.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed duplicate tool call projections by deduplicating provider-native <code>toolCall</code> events against in-band <code>tool_code</code> calls and keeping only the first real channel</li>
<li>Dropped nameless native <code>toolCall</code> events so they no longer appear as surfaced tool calls in owned-mode streams</li>
<li>Fixed Gemini/Gemma in-band tool-call parsing around Python comments, raw/unicode string literals, and Gemma close-token text inside string values.</li>
</ul>
<h2>@oh-my-pi/pi-catalog</h2>
<h3>Added</h3>
<ul>
<li>Added Azure OpenAI as a catalog provider (<code>azure</code>, default model <code>gpt-5.5</code>, env var <code>AZURE_OPENAI_API_KEY</code>), bundling the OpenAI-family models Azure serves over the Responses API (GPT-4/4.1/4o, GPT-5 family, o-series, Codex). Like Amazon Bedrock it is catalog-only — models ship in the bundle and become selectable once the env key is set, with the deployment base URL resolved at runtime from <code>AZURE_OPENAI_BASE_URL</code>/<code>AZURE_OPENAI_RESOURCE_NAME</code>.</li>
<li>Added models.dev-backed bundled catalogs for providers that previously shipped no offline models: Hugging Face, Kilo, Moonshot, NanoGPT, Synthetic, Venice, Ollama Cloud, and the Xiaomi Token Plan regions (ams/cn/sgp). They still discover live when credentialed; the bundle is now a non-empty baseline.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Updated stale provider default models to their latest bundled versions: OpenAI-family providers (<code>azure</code>, <code>github-copilot</code>, <code>aimlapi</code>) → GPT-5.5; Gemini providers (<code>google</code>, <code>google-gemini-cli</code>, <code>google-vertex</code>) → <code>gemini-3.1-pro-preview</code>; GLM providers (<code>zai</code>, <code>zhipu-coding-plan</code>) → <code>glm-5.2</code>, <code>cerebras</code> → <code>zai-glm-4.7</code>; Kimi providers (<code>fireworks</code>, <code>opencode-go</code>, <code>moonshot</code>) → <code>kimi-k2.7-code</code>, <code>kimi-code</code> → <code>kimi-for-coding</code>, <code>together</code> → <code>moonshotai/Kimi-K2.7-Code</code>; <code>alibaba-coding-plan</code> → <code>qwen3.7-plus</code>; and Claude-Sonnet defaults (<code>cloudflare-ai-gateway</code>, <code>cursor</code>, <code>gitlab-duo</code>, <code>kilo</code>, <code>opencode-zen</code>, <code>vercel-ai-gateway</code>) → Claude Opus 4.x.</li>
<li>Restricted models.dev Azure discovery to OpenAI-family IDs (<code>gpt-</code>, <code>o1</code>, <code>o3</code>, <code>o4</code>, <code>codex</code>, <code>chatgpt</code>), excluding Foundry-hosted third parties (Claude/DeepSeek/Llama/Mistral/Phi) that Azure serves through non-Responses APIs.</li>
<li>Detected the Azure OpenAI Responses compat surface (developer role, strict tool mode, strict tool-result pairing) by provider id as well as base URL, so bundled <code>azure</code> models whose deployment host is only known at runtime still get the right wire behavior.</li>
<li>Renamed the <code>Qwen3-ASR-Flash</code> model label to <code>Qwen3 ASR Flash</code></li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed tool syntax selection for Gemini-family and Gemma model IDs by routing them to dedicated <code>gemini</code> and <code>gemma</code> formats instead of generic XML</li>
<li>Fixed <code>zhipu-coding-plan</code> and <code>together</code> shipping no bundled models: their descriptors referenced non-existent models.dev keys (<code>zhipu-coding-plan</code>, <code>together</code>); pointed them at the real keys (<code>zhipuai-coding-plan</code>, <code>togetherai</code>) so they bundle their GLM and full catalogs respectively.</li>
<li>Folded the <code>azure-openai-responses</code> API into the OpenAI Responses thinking-inference branches so Azure reasoning models (o-series, GPT-5, Codex) resolve the discrete effort vocabulary (including <code>xhigh</code>) and effort-control mode instead of falling through to generic defaults.</li>
<li>Fixed <code>ollama-cloud</code> discovery inheriting an unsafe cross-provider <code>contextWindow</code>/<code>maxTokens</code> when <code>/api/show</code> returns no size metadata; it now falls back to the safe 128K context / 8K output caps.</li>
<li>Dropped internal Fireworks control-plane resource ids (<code>accounts/fireworks/{models,routers}/…</code>) from the bundle; only the public request ids ship.</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Added</h3>
<ul>
<li>Unexpected stop detection: optional tiny/smol classifier that continues the turn when the assistant says it will act but emits no tool calls.</li>
<li>Settings <code>features.unexpectedStopDetection</code> and <code>providers.unexpectedStopModel</code>.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed the <code>job</code> poll to return early when a steering message is queued, draining the steer immediately instead of waiting out the poll window.</li>
<li>Capped unexpected-stop auto-continuation to three retry attempts before giving up on repeated stops</li>
<li>Updated the <code>edit</code> tool's hashline prompt, grammar, and docs to recommend the <code>.=</code> inclusive range separator (<code>SWAP 1.=3:</code>); the legacy <code>..</code> form still parses.</li>
<li>Normalized all internal worker argv selectors under the <code>__omp_worker_</code> prefix, skipping the async worker dispatch check during normal CLI startup.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Filtered out whitespace-only and dot-only (<code>.</code> or <code>…</code>) assistant blocks so they are treated as empty and no longer appear as visible content in message rendering, streaming reveal counts, or session export output</li>
<li>Filtered placeholder-only thinking content from ACP notifications and message visibility checks so dot-only <code>reasoning_content</code> no longer triggers turn completion or read/run updates</li>
<li>Fixed ModelRegistry tests making outbound network calls by automatically stubbing fetch during test execution.</li>
<li>Fixed <code>eval</code> JS cells (and browser-tab worker startup) always stalling for the full init timeout — typically the cell's whole 30s budget — before silently falling back to the slower inline worker. The self-dispatching CLI host imports the worker module dynamically from its argv dispatch, so the worker's own <code>parentPort.on("message")</code> attached only after Bun flushed the messages the parent posted before spawn; the synchronously-posted <code>init</code> handshake was dropped and never answered with <code>ready</code>. The host now installs a buffering <code>parentPort</code> inbox synchronously in the entry's sync prefix (before importing the worker module) and the worker binds it on load, replaying the buffered handshake. <code>omp --smoke-test</code> now also spawns the JS eval worker through the host entry and asserts it handshakes on a real worker thread.</li>
<li>Fixed pre-prompt context-full compaction on OpenAI Responses sessions to use provider-anchored context usage when available, so large encrypted reasoning signatures no longer trigger automatic maintenance while the visible context percentage remains below threshold (<a href="https://github.com/can1357/oh-my-pi/issues/2628" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2628/hovercard">#2628</a>).</li>
</ul>
<h2>@oh-my-pi/collab-web</h2>
<h3>Fixed</h3>
<ul>
<li>Wrapped composer button labels to display icon-only on mobile devices for a more compact and readable layout</li>
<li>Made the connect screen, ended session card, and notification toasts fully responsive for smaller device viewports</li>
<li>Fixed mobile layout issues where the entire chat flow would overflow horizontally and text was rendered too large on iOS Safari (by setting <code>text-size-adjust: 100%</code>)</li>
<li>Made transcript rows stack vertically on small screens to optimize reading space, and prevented grid track expansion</li>
<li>Hid non-essential metadata (such as the model name, thinking level, and working directory path) and context gauge tracks on mobile headers to prevent overflow</li>
</ul>
<h2>@oh-my-pi/hashline</h2>
<h3>Changed</h3>
<ul>
<li>Changed the recommended hashline range separator from <code>..</code> to <code>.=</code> (e.g. <code>SWAP 1.=3:</code>, <code>DEL 4.=5</code>) so the inclusive <code>&lt;=</code>-style end is self-evident. <code>HL_RANGE_SEP</code> is now <code>.=</code>; the prompt, grammar, error messages, and emitted headers all use it. The lenient parser still accepts the legacy <code>..</code> (and <code>-</code>/<code>…</code>/space) forms.</li>
</ul>
<h2>@oh-my-pi/omp-stats</h2>
<h3>Changed</h3>
<ul>
<li>Renamed <code>__omp_stats_sync_worker</code> to <code>__omp_worker_stats_sync</code>.</li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Added</h3>
<ul>
<li>Added <code>installWorkerInbox(port)</code> / <code>consumeWorkerInbox()</code> to <code>@oh-my-pi/pi-utils/worker-host</code>. A self-dispatching CLI host that imports a Bun worker module dynamically attaches the worker's real <code>message</code> listener after Bun flushes the messages the parent posted before spawn, dropping a synchronously-posted <code>init</code>. The host installs this buffering inbox synchronously in the entry's sync prefix so a listener exists at flush time; the worker module consumes it and binds the real handler, replaying anything buffered.</li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v15.13.2...v15.13.3"><tt>v15.13.2...v15.13.3</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[5 runtime signals for catching a compromised AI agent]]></title>
<description><![CDATA[In June 2025, Simon Willison, the engineer who coined the term “prompt injection,” published a warning that circulated widely through the security community. He called it the lethal trifecta — three capabilities that, when combined in a single AI agent, create a near-guaranteed path to exploitati...]]></description>
<link>https://tsecurity.de/de/3598566/it-security-nachrichten/5-runtime-signals-for-catching-a-compromised-ai-agent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598566/it-security-nachrichten/5-runtime-signals-for-catching-a-compromised-ai-agent/</guid>
<pubDate>Mon, 15 Jun 2026 11:08:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In June 2025, Simon Willison, the engineer who coined the term “prompt injection,” <a href="https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/">published a warning</a> that circulated widely through the security community. He called it the lethal trifecta — three capabilities that, when combined in a single AI agent, create a near-guaranteed path to exploitation through indirect prompt injection: access to private data; exposure to untrusted content; the ability to communicate externally.</p>



<p>The framing was sharp and useful. If your agent reads your email, ingests arbitrary web content, and can make outbound requests, an attacker who embeds malicious instructions anywhere in that content pipeline can direct the agent to exfiltrate your data without you ever knowing. Willison illustrated the point with a long list of real production exploits: Microsoft 365 Copilot, GitHub’s MCP server, GitLab Duo, Slack AI, Google Bard, Amazon Q. The same class of attack, over and over.</p>



<p>The trifecta worked as a signal because, at the time, agents were mostly narrowly scoped. An agent capable of performing only one or two of the lethal trifecta activities could be assessed as lower risk. Avoiding the combination felt like a viable design strategy.</p>



<p>That window has closed given what practitioners deploy today: A customer-facing support agent reads ticket histories and customer records, ingests user messages and attached files, and calls CRMs, refund APIs, or ticketing systems. An email AI reads your inbox and calendar, processes inbound messages from strangers, and sends replies on your behalf.</p>



<p>Rather than being edge cases or poorly designed deployments, these are the agents enterprises and individuals actually want, and they’re the ones vendors are building toward.</p>



<h2 class="wp-block-heading">Lethal trifecta as default configuration</h2>



<p>Ross McKerchar, CISO at Sophos, <a href="https://www.sophos.com/en-us/blog/inside-the-lethal-trifecta-blast-radius-reduction-in-ai-agent-deployments">put it plainly</a> in a piece published this May: “the capabilities practitioners actually want (read my data, understand external context, take action) push firmly into dangerous territory. This isn’t a misconfiguration; it’s the architectural cost of usefulness.” He’s right. An agent without private data access is useless, one that can’t process external content is isolated, and the one that can’t communicate externally is inert. Strip any leg of the trifecta and you have something closer to a search box than an agent.</p>



<p>If every legitimate agent architecture exhibits all three trifecta properties, the trifecta is no longer a meaningful indicator of elevated risk. It’s the default configuration. Treating it as a red flag is like treating DNS resolution as a signal of network compromise. Technically <a href="https://www.csoonline.com/article/574989/4-strategies-to-help-reduce-the-risk-of-dns-tunneling.html">true in some threat models</a>, but universally present in every real deployment.</p>



<p>McKerchar’s piece frames the response as “blast radius reduction”: a reasonable operational philosophy, but one that accepts the trifecta as a given condition rather than a preventable one. That’s a reasonable call. The question is what comes after the acceptance.</p>



<p>Meta’s security team arrived at the same conclusion from the other direction. In October 2025, they published the “<a href="https://ai.meta.com/blog/practical-ai-agent-security/">Rule of Two</a>,” a framework that recommends agents satisfy no more than two of the three trifecta properties in a single session, with human-in-the-loop approval required if all three are necessary. Willison <a href="https://simonwillison.net/2025/Nov/2/new-prompt-injection-papers/">himself endorsed the framework</a> as “the best practical advice for building secure LLM-powered agent systems today.”</p>



<p>Meta’s limitations section, however, concedes that many sought-after use cases won’t fit the framework cleanly, and that “designs that satisfy the Agents Rule of Two can still be prone to failure.” That’s not a criticism of the framework but confirmation that the problem has outgrown the architecture-level solution.</p>



<p>The scale of exposure is no longer theoretical. <a href="https://blog.google/security/prompt-injections-web/">Google’s April 2026 sweep</a> of the Common Crawl repository found prompt injection attempts across public web pages, ranging from pranks to data exfiltration payloads, with malicious attempts up 32% between November 2025 and February 2026. Google noted sophistication remains low for now but flagged the trend as a signal of maturing attacker interest.</p>



<p>The environment the trifecta warned about has arrived.</p>



<h2 class="wp-block-heading">How to sleuth out a compromised agent</h2>



<p>If the trifecta describes nearly every deployed agent, practitioners need signals that distinguish compromised behavior from normal operation within a trifecta-exhibiting system. That means shifting from architecture-level assessments to <a href="https://www.csoonline.com/article/4145127/runtime-the-new-frontier-of-ai-agent-security.html">runtime behavioral detection</a>.</p>



<p>The production evidence arrived in a cluster. From Jan. 7 to Jan. 15, 2026, <a href="https://breached.company/the-lethal-trifecta-strikes-four-major-ai-agent-vulnerabilities-in-five-days/">researchers disclosed exploits</a> against four separate AI productivity tools in eight days: IBM Bob, Superhuman AI, Notion AI, and Anthropic’s Claude Cowork. Each used indirect prompt injection to exfiltrate data via a channel the agent had legitimate access to. In the Cowork case, a hidden prompt embedded in an uploaded document directed the agent to exfiltrate files via Anthropic’s own allowlisted API domain, invisible to any perimeter control and indistinguishable from normal agent behavior until the data was already gone. In all of these cases, the trifecta wasn’t a risk factor but the operating condition.</p>



<p>Here’s what’s worth watching to detect an agent has been compromised.</p>



<p><strong>Instruction-following anomalies.</strong> A compromised agent doesn’t usually do something structurally different from a healthy one. Following instructions is its normal function. The difference is whose instructions it’s following. Look for agent actions that have no plausible correspondence to a user-initiated task. An agent that was asked to summarize a quarterly report but then attempts an outbound DNS request to an unfamiliar domain didn’t spontaneously decide to do that. Something in the content it ingested told it to.</p>



<p><strong>Tool call sequences that break expected topology.</strong> In a well-designed agent system, the graph of tool calls for any given task should be relatively predictable. A coding agent invoked to fix a bug should touch files, run tests, perhaps check documentation. It shouldn’t be reaching for email or calendar APIs. Tool call sequences that cross expected workflow boundaries are worth flagging even when each individual call looks legitimate on its own.</p>



<p><strong>Exfiltration via low-bandwidth channels.</strong> The classic prompt injection exfiltration attack routes stolen data through a mechanism the agent has legitimate access to: a rendered image URL with encoded query parameters, an API call with data embedded in a parameter, a link in a generated document. These don’t look like data theft in isolation; they look like normal agent output. Detection requires correlating what data the agent had access to against what it embedded in its output. That requires end-to-end visibility into the agent’s actions, not just the final response.</p>



<p><strong>Credential and secret access outside task scope.</strong> If an agent with legitimate access to a secrets store or key vault touches credentials that have no relationship to the current task, that’s a signal. An agent fixing a React rendering bug should likely not be reading AWS credentials. Least-privilege scoping is the architectural defense here, but monitoring for out-of-scope credential access is the detection layer that catches failures in that scoping.</p>



<p><strong>Memory-write anomalies.</strong> Agents with persistent memory are a growing attack surface. A poisoned memory entry that looks like legitimate user context but contains dormant trigger instructions can persist across sessions and fire long after the initial injection. Monitoring for memory-writes containing instruction-like content, or writes made during sessions that ingested untrusted content, is worth adding to any agent observability pipeline.</p>



<h2 class="wp-block-heading">Runtime alone can address the agent redirection threat</h2>



<p>For practitioners operating production agent infrastructure, the lethal trifecta tells you what you know: Your agents are exposed. The question is what to do about it.</p>



<p>The answers are at the runtime layer, not the architecture layer. That’s where <a href="https://www.csoonline.com/article/653052/how-to-pick-the-best-endpoint-detection-and-response-solution.html">EDR</a> and <a href="https://www.csoonline.com/article/566677/12-top-siem-tools-rated-and-compared.html">SIEM</a> live for traditional infrastructure — agents need the same instrumentation, and most deployments don’t have it yet. Full execution traces on every agent invocation. Tool call <a href="https://www.csoonline.com/article/3822459/what-is-anomaly-detection-behavior-based-analysis-for-cyber-threats.html">anomaly detection</a>. Input screening at ingest. Credential access monitoring scoped to task context. Memory-write auditing. Not a human attacker logging in. An agent that’s been quietly redirected.</p>



<p>Willison’s trifecta was the right alarm for its moment, which was last year. Almost every production agent now fits the profile. Because of that, only runtime anomaly detection can potentially provide adequate defense. The above signals are a good place to start.<a></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-9204 | GitLab Community Edition/Enterprise Edition up to 18.10.7/18.11.4/19.0.1 server-side request forgery]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in GitLab Community Edition and Enterprise Edition up to 18.10.7/18.11.4/19.0.1. This affects an unknown part. Executing a manipulation can lead to server-side request forgery.

This vulnerability is tracked as CVE-2026-9204. The attack...]]></description>
<link>https://tsecurity.de/de/3598440/sicherheitsluecken/cve-2026-9204-gitlab-community-editionenterprise-edition-up-to-18107181141901-server-side-request-forgery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598440/sicherheitsluecken/cve-2026-9204-gitlab-community-editionenterprise-edition-up-to-18107181141901-server-side-request-forgery/</guid>
<pubDate>Mon, 15 Jun 2026 10:10:38 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 18.10.7/18.11.4/19.0.1</a>. This affects an unknown part. Executing a manipulation can lead to server-side request forgery.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-9204">CVE-2026-9204</a>. The attack can be launched remotely. No exploit exists.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-8589 | GitLab Enterprise Edition up to 18.10.7/18.11.4/19.0.1 Setting cross site scripting]]></title>
<description><![CDATA[A vulnerability was found in GitLab Enterprise Edition up to 18.10.7/18.11.4/19.0.1. It has been declared as problematic. The affected element is an unknown function of the component Setting Handler. Such manipulation leads to cross site scripting.

This vulnerability is documented as CVE-2026-85...]]></description>
<link>https://tsecurity.de/de/3598437/sicherheitsluecken/cve-2026-8589-gitlab-enterprise-edition-up-to-18107181141901-setting-cross-site-scripting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598437/sicherheitsluecken/cve-2026-8589-gitlab-enterprise-edition-up-to-18107181141901-setting-cross-site-scripting/</guid>
<pubDate>Mon, 15 Jun 2026 10:10:34 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gitlab:enterprise_edition">GitLab Enterprise Edition up to 18.10.7/18.11.4/19.0.1</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. The affected element is an unknown function of the component <em>Setting Handler</em>. Such manipulation leads to cross site scripting.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-8589">CVE-2026-8589</a>. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-9694 | GitLab Community Edition/Enterprise Edition up to 18.10.7/18.11.4/19.0.1 Service Desk Email Reply substitution character]]></title>
<description><![CDATA[A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.10.7/18.11.4/19.0.1. It has been rated as problematic. The impacted element is an unknown function of the component Service Desk Email Reply Handler. Performing a manipulation results in improper neutralization ...]]></description>
<link>https://tsecurity.de/de/3598436/sicherheitsluecken/cve-2026-9694-gitlab-community-editionenterprise-edition-up-to-18107181141901-service-desk-email-reply-substitution-character/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598436/sicherheitsluecken/cve-2026-9694-gitlab-community-editionenterprise-edition-up-to-18107181141901-service-desk-email-reply-substitution-character/</guid>
<pubDate>Mon, 15 Jun 2026 10:10:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 18.10.7/18.11.4/19.0.1</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. The impacted element is an unknown function of the component <em>Service Desk Email Reply Handler</em>. Performing a manipulation results in improper neutralization of substitution characters.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-9694">CVE-2026-9694</a>. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[Open-source CI/CD abuse detector guards against stolen credential attacks]]></title>
<description><![CDATA[CI/CD Abuse Detector is an open-source project that uses a large language model to flag suspicious changes to continuous integration and continuous deployment pipelines, workflows, and automation configurations. The repository contains drop-in templates for GitHub Actions, GitLab CI, and Azure…
R...]]></description>
<link>https://tsecurity.de/de/3598212/it-security-nachrichten/open-source-cicd-abuse-detector-guards-against-stolen-credential-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598212/it-security-nachrichten/open-source-cicd-abuse-detector-guards-against-stolen-credential-attacks/</guid>
<pubDate>Mon, 15 Jun 2026 08:23:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CI/CD Abuse Detector is an open-source project that uses a large language model to flag suspicious changes to continuous integration and continuous deployment pipelines, workflows, and automation configurations. The repository contains drop-in templates for GitHub Actions, GitLab CI, and Azure…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/open-source-ci-cd-abuse-detector-guards-against-stolen-credential-attacks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/open-source-ci-cd-abuse-detector-guards-against-stolen-credential-attacks/">Open-source CI/CD abuse detector guards against stolen credential attacks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Open-source CI/CD abuse detector guards against stolen credential attacks]]></title>
<description><![CDATA[CI/CD Abuse Detector is an open-source project that uses a large language model to flag suspicious changes to continuous integration and continuous deployment pipelines, workflows, and automation configurations. The repository contains drop-in templates for GitHub Actions, GitLab CI, and Azure De...]]></description>
<link>https://tsecurity.de/de/3598139/it-security-nachrichten/open-source-cicd-abuse-detector-guards-against-stolen-credential-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598139/it-security-nachrichten/open-source-cicd-abuse-detector-guards-against-stolen-credential-attacks/</guid>
<pubDate>Mon, 15 Jun 2026 07:52:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CI/CD Abuse Detector is an open-source project that uses a large language model to flag suspicious changes to continuous integration and continuous deployment pipelines, workflows, and automation configurations. The repository contains drop-in templates for GitHub Actions, GitLab CI, and Azure DevOps. The project targets a common attack chain in software supply chain compromises. Stolen developer credentials are used to push modifications to workflow files, which then harvest secrets stored in the CI environment. The detector … <a href="https://www.helpnetsecurity.com/2026/06/15/ci-cd-abuse-detector-open-source/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/15/ci-cd-abuse-detector-open-source/">Open-source CI/CD abuse detector guards against stolen credential attacks</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wine Staging 11.11 has been released. The number of patches carried atop the upstream codebase is now sitting at 289]]></title>
<description><![CDATA[From the article  Following Friday's exciting release of Wine 11.11 with Wayland driver improvements, Wine-Staging 11.11 is now available for this experimental/testing derivative that continues carrying nearly 300 patches atop the upstream codebase.   The release of Wine-Staging 11.11 clocks in t...]]></description>
<link>https://tsecurity.de/de/3596591/linux-tipps/wine-staging-1111-has-been-released-the-number-of-patches-carried-atop-the-upstream-codebase-is-now-sitting-at-289/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596591/linux-tipps/wine-staging-1111-has-been-released-the-number-of-patches-carried-atop-the-upstream-codebase-is-now-sitting-at-289/</guid>
<pubDate>Sun, 14 Jun 2026 08:08:16 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><strong>From the article</strong></p> <blockquote> <p>Following Friday's exciting release of <a href="https://www.phoronix.com/news/Wine-11.11-Released">Wine 11.11 with Wayland driver improvements</a>, Wine-Staging 11.11 is now available for this experimental/testing derivative that continues carrying nearly 300 patches atop the upstream codebase. </p> </blockquote> <p>The release of Wine-Staging 11.11 clocks in tonight at 289 patches atop the "vanilla" upstream Wine 11.11 codebase. </p> <p>Over the past two weeks there have not been any new patches added to staging but the VKD3D Git code was updated for newer Direct3D 12 on Vulkan support. Additionally, the DCompositionCreateDevice2 patches carried by Wine-Staging were also updated to their latest state. </p> <p>Wine-Staging 11.11 downloads and more details can be found via the <a href="https://gitlab.winehq.org/wine/wine-staging">WineHQ.org GitLab</a>.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/somerandomxander"> /u/somerandomxander </a> <br> <span><a href="https://www.phoronix.com/news/Wine-Staging-11.11">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1u5aw3u/wine_staging_1111_has_been_released_the_number_of/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building My Malware Lab From Scratch 3]]></title>
<description><![CDATA[Today we look at building a single button deploy using the power of Gitlab CI!    submitted by    /u/superdog793   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3596295/malware-trojaner-viren/building-my-malware-lab-from-scratch-3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596295/malware-trojaner-viren/building-my-malware-lab-from-scratch-3/</guid>
<pubDate>Sun, 14 Jun 2026 01:03:05 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/ExploitDev/comments/1u3v9bi/building_my_malware_lab_from_scratch_3/"> <img src="https://external-preview.redd.it/6IgaE_pYMeISCTNh9woIbMmBokGZLp6z4n1dt4CyuOE.jpeg?width=320&amp;crop=smart&amp;auto=webp&amp;s=ee8b243d8db6832319abc4e931e3c4527c92d32d" alt="Building My Malware Lab From Scratch 3" title="Building My Malware Lab From Scratch 3"> </a> </td><td> <!-- SC_OFF --><div class="md"><p>Today we look at building a single button deploy using the power of Gitlab CI!</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/superdog793"> /u/superdog793 </a> <br> <span><a href="https://youtu.be/vnsZGscnMuA">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1u3v9bi/building_my_malware_lab_from_scratch_3/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[v15.12.4]]></title>
<description><![CDATA[@oh-my-pi/pi-agent-core
Fixed

Fixed remote compaction input trimming to use unlimited context when model.contextWindow is unset

@oh-my-pi/pi-ai
Added

Added GITLAB_CLIENT_ID and GITLAB_REDIRECT_URI env-var overrides for the GitLab Duo OAuth login flow so users running with their own GitLab OAut...]]></description>
<link>https://tsecurity.de/de/3595882/tools/v15124/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595882/tools/v15124/</guid>
<pubDate>Sat, 13 Jun 2026 18:24:20 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-agent-core</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed remote compaction input trimming to use unlimited context when <code>model.contextWindow</code> is unset</li>
</ul>
<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Added <code>GITLAB_CLIENT_ID</code> and <code>GITLAB_REDIRECT_URI</code> env-var overrides for the GitLab Duo OAuth login flow so users running with their own GitLab OAuth application can replace the bundled credentials when GitLab rejects the bundled <code>client_id</code>'s redirect URI. Setting <code>GITLAB_REDIRECT_URI</code> also disables the random-port fallback (strict OAuth providers reject mismatched URIs anyway). (<a href="https://github.com/can1357/oh-my-pi/issues/2424" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2424/hovercard">#2424</a>)</li>
<li>Added <code>AuthStorage.listStoredCredentials()</code> and <code>AuthStorage.removeCredential()</code> for per-account credential management.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Replaced the OpenAI SDK client usage in <code>openai-completions</code>, <code>openai-responses</code>, <code>azure-openai-responses</code>, and <code>openai-codex-responses</code> with the new internal <code>postOpenAIStream</code> OpenAI-wire JSON/SSE transport</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed streaming providers to cancel upstream model requests when the client closes the response body, so interrupted SSE sessions stop instead of continuing in the background</li>
<li>Fixed: provider request builders treat unknown <code>model.maxTokens</code> (<code>null</code>) as "no model cap" instead of coercing to <code>0</code> via <code>Math.min</code>; Anthropic falls back to the 64k Claude-Code cap for its required <code>max_tokens</code>.</li>
<li>Fixed transient stream failures on OpenAI-compatible providers by retrying HTTP 408/429/5xx responses and transient network errors with Retry-After/quota-hint aware backoff</li>
<li>Fixed SSE stream handling for OpenAI-compatible responses by parsing wire-level JSON frames directly and honoring <code>[DONE]</code> termination</li>
<li>Fixed stream error handling for OpenAI-compatible providers by preserving structured HTTP status/headers and response body details from failed requests for retry and strict-tool fallback logic</li>
<li>Fixed OpenAI-compat streams ending with a bare <code>finish_reason: "error"</code> (gateways like OpenRouter reporting upstream failures, e.g. Gemini <code>MALFORMED_FUNCTION_CALL</code>) surfacing as a non-retryable <code>Provider finish_reason: error</code>. The reason is now mapped to <code>Provider returned error finish_reason</code>, which the session retry classifier recognizes as transient, so the turn auto-retries instead of stopping with a pinned error banner.</li>
<li>Fixed <code>SqliteAuthCredentialStore.open()</code> crashing with <code>SQLITE_BUSY_RECOVERY</code> (errno 261) when several <code>omp --session</code> panes restore concurrently after an unclean shutdown: <code>PRAGMA busy_timeout = 5000</code> now runs as a standalone statement BEFORE <code>PRAGMA journal_mode=WAL</code> (the first lock-taking statement during WAL recovery), and <code>open()</code> retries the BUSY family — <code>SQLITE_BUSY</code>, <code>SQLITE_BUSY_RECOVERY</code>, <code>SQLITE_BUSY_SNAPSHOT</code>, <code>SQLITE_BUSY_TIMEOUT</code> — with bounded exponential backoff. The exhausted-retry error message includes the DB path. Exported <code>isSqliteBusyError(err)</code> for callers that need the same classifier (<a href="https://github.com/can1357/oh-my-pi/issues/2421" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2421/hovercard">#2421</a>).</li>
<li>Fixed MiniMax-M3 OpenAI-compatible streams rendering reasoning twice when the same chunk carried both <code>&lt;think&gt;…&lt;/think&gt;</code> content and structured <code>reasoning_content</code>; structured reasoning now wins and cumulative MiniMax reasoning snapshots are collapsed to deltas. (<a href="https://github.com/can1357/oh-my-pi/issues/2433" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2433/hovercard">#2433</a>)</li>
<li>Fixed Gemini turns silently halting the agent when the model returned <code>finishReason: STOP</code> with only an empty (or whitespace-only) text part and no tool call — the well-known "empty response" failure. All Google surfaces (public Generative Language <code>streamGoogle</code>, Vertex <code>streamGoogleVertex</code>, and Cloud Code Assist <code>google-gemini-cli</code>/<code>google-antigravity</code>) now classify such a turn as empty via the shared <code>hasMeaningfulGoogleContent</code> check and retry it up to <code>MAX_EMPTY_STREAM_RETRIES</code> times before surfacing an error. The Cloud Code Assist path previously had an empty-stream retry that never fired for this case (its <code>hasContent</code> flag counted an empty-string text part as content), and the public/Vertex path had no retry at all; the retry now emits a single <code>start</code> event so no duplicate partial message leaks downstream.</li>
</ul>
<h2>@oh-my-pi/pi-catalog</h2>
<h3>Added</h3>
<ul>
<li>Added bundled Fireworks models <code>deepseek-v4-flash</code>, <code>kimi-k2.7-code</code>, <code>minimax-m2.5</code>, <code>minimax-m3</code>, <code>nemotron-3-ultra-nvfp4</code>, <code>qwen3.6-plus</code>, and <code>qwen3.7-plus</code></li>
<li>Changed</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Model <code>contextWindow</code>/<code>maxTokens</code> are now <code>number | null</code>; discovery emits <code>null</code> when a provider reports no limit, replacing the <code>222222</code>/<code>8888</code> (<code>UNK_CONTEXT_WINDOW</code>/<code>UNK_MAX_TOKENS</code>) sentinels (now removed). Bundled <code>models.json</code> unknown limits are <code>null</code>.</li>
<li>Changed the <code>github-copilot</code> model context window to <code>524288</code> tokens</li>
<li>Changed Fireworks model discovery to source the control-plane <code>List Models</code> API (<code>GET /v1/accounts/fireworks/models?filter=supports_serverless=true</code>) instead of the OpenAI-compatible <code>/v1/models</code> inference listing. The inference endpoint returns a sparse, account-specific subset that omits on-demand serverless models (e.g. <code>kimi-k2.7-code</code>), so newly published serverless models stayed invisible in the picker until hand-added to the bundled catalog. The control-plane catalog enumerates every serverless model with capability metadata (<code>supportsServerless</code>/<code>supportsTools</code>/<code>supportsImageInput</code>/<code>contextLength</code>/<code>displayName</code>), paginated and filtered to tool-capable <code>READY</code> entries, then merged with bundled/models.dev references — the Kimi K2 max-output clamp and DeepSeek V4 thinking-toggle strip are preserved, and unbundled models default to reasoning so <code>buildModel</code> derives the Fireworks effort map. New serverless releases now surface automatically with no catalog edits.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Filled missing <code>contextWindow</code> and <code>maxTokens</code> in generated <code>models.json</code> for proxy/reseller variants by inheriting limits from canonical-family and segment-reference models</li>
<li>Ignored zero-cost <code>x-ai</code> subscription entries as reference sources when backfilling limits so inflated values are not propagated</li>
<li>Fixed the model cache opening with <code>PRAGMA journal_mode=WAL</code> before <code>PRAGMA busy_timeout</code>, so concurrent omp startups could crash inside <code>getDb()</code> on <code>SQLITE_BUSY</code> during WAL recovery instead of waiting through the transient lock. The busy handler is now installed before the first lock-taking statement (<a href="https://github.com/can1357/oh-my-pi/issues/2421" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2421/hovercard">#2421</a>).</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Removed the top-level <code>--list-models</code> flag path and migrated model listing to the new <code>omp models</code> command</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added <code>omp models</code> command to list and manage models with <code>ls</code>, <code>find</code>, <code>canonical</code>, and <code>refresh</code> actions</li>
<li>Added <code>--json</code> output plus <code>-e/--extension</code>, <code>--no-extensions</code>, and <code>--config</code> controls to <code>omp models</code> listings</li>
<li>Added <code>skills.enableAgentsUser</code> and <code>skills.enableAgentsProject</code> settings (default on) so the canonical OMP-native <code>~/.agent[s]/skills</code> and project-walkup <code>.agent[s]/skills</code> are configurable independently from the third-party Claude/Codex/Pi toggles.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Model registry merge and <code>omp models</code> / model picker handle unknown context/output limits (<code>null</code>) — unknown limits render as <code>-</code> instead of a fake <code>222K</code>/<code>8.9K</code>.</li>
<li>Changed <code>omp models</code> to use cached provider data by default and require <code>omp models refresh</code> for a forced online re-fetch</li>
<li>Updated model-resolution errors to point to <code>omp models</code> when a provider or model is not found</li>
<li>Upgraded workspace catalog packages to their latest versions as of 3 days ago, and refactored the ACP agent implementation to be compatible with <code>@agentclientprotocol/sdk</code> version <code>0.25.0</code>.</li>
<li>Made the <code>zod</code> version requirement in the workspace catalog more tolerant (<code>^4.0.0</code> instead of <code>4.4.3</code>), and aligned type definitions in coding-agent extensibility modules.</li>
<li>Changed <code>/logout</code> to pick a stored account after the provider, so multi-account OAuth providers can remove one credential without logging out every account.</li>
<li>Changed the status-line context% to report the provider's real prompt-token count — anchored on the last assistant response, matching the <code>/context</code> panel and the collab host broadcast — instead of an independent cl100k estimate of the whole conversation. The estimate could read several points high and climb past 100% on subscription/Codex models (whose advertised window, e.g. <code>272K</code>, is already the input budget after reserving max output) while the request was still well within the real limit. Right after compaction the segment now shows <code>?</code> until the next response re-establishes the true count, and the redundant per-message estimate cache was dropped in favor of memoizing <code>getContextUsage()</code>.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed ACP thinking-delta mapping to tolerate live chunks that only carry delta text.</li>
<li>Fixed image input to Ollama (local <code>ollama</code>, <code>ollama-cloud</code>, and any <code>ollama-chat</code> model) failing with an opaque HTTP 400 when an attached image was encoded as WebP. Ollama decodes images through llama.cpp / <code>stb_image</code>, which is built without WebP support, so the resize pipeline now auto-excludes WebP for those models — the automatic equivalent of <code>OMP_NO_WEBP=1</code>, applied across every image path (<code>@file</code> mentions and prompt/paste/CLI attachments, the <code>read</code>/<code>inspect_image</code> tools, <code>eval</code> display images, <code>fetch</code>ed images, and browser screenshots). Other providers are unaffected and still honor <code>OMP_NO_WEBP</code>.</li>
<li>Fixed queued steering/follow-up display to derive from the agent-core queue, so queued chips clear when the core dequeues them and no longer strand after empty-Enter aborts.</li>
<li>Fixed model auth gateway probing to avoid skipping candidates with unknown <code>maxTokens</code> limits (<code>null</code>)</li>
<li>Fixed model listings so providers registered via extensions are now included from <code>-e</code> and configured <code>extensions</code> sources</li>
<li>Fixed <code>/mcp reauth</code>, <code>/mcp test</code>, and <code>/mcp unauth</code> to find and operate on MCP servers reported by <code>/mcp list</code> even when they are only runtime-discovered and not stored in writable config, including namespaced plugin servers like <code>cloudflare:cloudflare-api</code></li>
<li>Fixed MCP server name validation so colon-namespaced server IDs are accepted when persisting reauth overrides so namespaced OAuth MCP servers can be stored in user config as <code>server:subserver</code> entries</li>
<li>Retried assistant turns that stop with reasoning/thinking only and no final text or tool call, so Gemini/Antigravity thought-only <code>STOP</code> responses continue instead of silently ending the session.</li>
<li>Fixed <code>~/.agent[s]/skills</code> not appearing as <code>/skill:&lt;name&gt;</code> commands when every named source toggle (<code>skills.enableCodexUser</code>, <code>skills.enableClaudeUser</code>, <code>skills.enableClaudeProject</code>, <code>skills.enablePiUser</code>, <code>skills.enablePiProject</code>) was off: <code>loadSkills</code> gated the <code>agents</code> provider on <code>anyBuiltInSkillSourceEnabled</code>, so a user who turned off the Claude/Codex/Pi sources to clean noise also lost their own canonical OMP-native skills. The <code>agents</code> provider now reads the dedicated <code>enableAgentsUser</code>/<code>enableAgentsProject</code> toggles, decoupled from the third-party fall-through (<a href="https://github.com/can1357/oh-my-pi/issues/2401" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2401/hovercard">#2401</a>).</li>
<li>Fixed Windows PowerShell image paste so Ctrl+V can fall back to the PowerShell clipboard bridge when the native clipboard reader reports no image (<a href="https://github.com/can1357/oh-my-pi/issues/2429" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2429/hovercard">#2429</a>).</li>
<li>Fixed misaligned box borders in Mermaid ASCII rendering for CJK (Korean/Japanese/Chinese) and emoji labels — affects both fenced <code>mermaid</code> code blocks in assistant messages and the <code>render_mermaid</code> tool. <code>beautiful-mermaid@1.1.3</code> measures label width in UTF-16 code units while terminals render East Asian characters 2 columns wide; a <code>patchedDependencies</code> entry rebuilds its ASCII renderer to measure terminal display columns (grapheme-cluster aware, wcwidth-style policy). The patch mirrors the upstream PR (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654741745" data-permission-text="Title is private" data-url="https://github.com/lukilabs/beautiful-mermaid/issues/128" data-hovercard-type="pull_request" data-hovercard-url="/lukilabs/beautiful-mermaid/pull/128/hovercard" href="https://github.com/lukilabs/beautiful-mermaid/pull/128">lukilabs/beautiful-mermaid#128</a>) and should be dropped once it ships in a release.</li>
<li>Fixed interrupt loader state getting stuck after queued-message aborts by removing the session-layer flush/latch path; empty Enter now aborts the active turn and lets the existing post-unwind queue drain resume normally.</li>
<li>Fixed <code>/goal &lt;objective&gt;</code> and <code>/goal set &lt;objective&gt;</code> during streaming so goal context is steered immediately but objective submission waits for the active turn to finish instead of spamming <code>AgentBusyError</code> (<a href="https://github.com/can1357/oh-my-pi/issues/2454" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2454/hovercard">#2454</a>).</li>
<li>Fixed concurrent <code>omp --session</code> startups (e.g. cmux pane restore after an unclean shutdown) crashing with <code>SQLITE_BUSY_RECOVERY</code> while the agent SQLite databases were still under WAL recovery. The auth credential store and <code>AgentStorage.open()</code> retry the <code>SQLITE_BUSY</code> family with bounded backoff, and every shared SQLite open path (<code>AgentStorage</code>, history, autoresearch, memories, github cache, auto-QA grievances, catalog model cache, stats) now installs the busy handler before the first lock-taking statement so transient WAL recovery contention waits instead of crashing (<a href="https://github.com/can1357/oh-my-pi/issues/2421" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2421/hovercard">#2421</a>).</li>
<li>Mnemopi <code>per-project</code> / <code>per-project-tagged</code> bank derivation is now stable for one cwd, ignoring the surrounding git layout. Previously the bank id was hashed from <code>git.repo.resolveSync(cwd)?.repoRoot ?? path.resolve(cwd)</code>, so adding or removing a <code>.git</code> anywhere above the working directory silently repointed the same conversation to a new bank and stranded its memories (e.g. <code>/home/x/projects/repo</code> flipping between <code>projects-…</code> and <code>repo-…</code>). The derivation in <code>packages/coding-agent/src/mnemopi/config.ts</code> now hashes <code>path.resolve(cwd)</code> directly, and session startup widens the recall set with any sibling bank under <code>&lt;dbDir&gt;/banks/</code> whose <code>working_memory</code> rows already carry the active cwd in <code>metadata_json.$.cwd</code>, so memories stranded by the old, less-stable derivation become visible again on the next session without manual migration (<a href="https://github.com/can1357/oh-my-pi/issues/2412" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2412/hovercard">#2412</a>).</li>
<li>Fixed model switching (Ctrl+P role cycling and the alt+p / <code>/switch</code> / <code>/models</code> selector) intermittently freezing the UI for several seconds. <code>AgentSession.setModel</code>/<code>setModelTemporary</code> ran an eager <code>await modelRegistry.getApiKey(model)</code> purely as an existence pre-flight and discarded the value — but <code>getApiKey</code> does real work: it synchronously executes command-backed key programs (<code>apiKey: "!cmd"</code>, <code>execSync</code> with a 10s timeout, blocking the event loop) and refreshes OAuth tokens over the network when one crosses the expiry window (the "fine for a few switches, then a multi-second stall" symptom). Switching now uses the synchronous, side-effect-free <code>ModelRegistry.hasConfiguredAuth</code> check; the concrete key (command execution + OAuth refresh) is still resolved lazily per request via the existing resolver, so an unconfigured provider still fails fast with <code>No API key</code> while a healthy switch never touches the network or spawns a subprocess. <code>hasConfiguredAuth</code> no longer runs the command program or refreshes tokens either, matching its documented "probe without resolving an API key" contract.</li>
<li>Fixed session resume (<code>pi -c</code> / <code>--continue</code> / <code>--session</code>) hanging for ~10s at startup — surfaced by the watchdog as <code>Still starting … phase: createAgentSession &gt; restoreSessionModel</code> — when an OAuth token needed refreshing or the auth broker (<code>OMP_AUTH_BROKER_URL</code>) was unreachable. Picking which saved model to restore is a pure <em>selection</em> that only needs to know whether auth is configured, but <code>restoreSessionModel</code> probed each candidate with the async <code>getApiKey</code>, which refreshes OAuth tokens over the network, executes command-backed key programs, and issues auth-broker requests — so a slow or unreachable endpoint stalled resume for the full refresh timeout per candidate. Startup model selection now uses the synchronous, side-effect-free <code>ModelRegistry.hasConfiguredAuth</code> probe (the same fix already applied to interactive model switching); the concrete key is still resolved lazily on the first request via the resolver.</li>
</ul>
<h2>@oh-my-pi/collab-web</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed context usage percentage calculations to return null when context window is missing or non-positive, preventing invalid or Infinity/NaN usage display</li>
</ul>
<h2>@oh-my-pi/pi-mnemopi</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>consolidateToEpisodic</code> (the function backing <code>sleep</code> / <code>sleepAllSessions</code>) never populating the episodic graph: the <code>gists</code> and <code>graph_edges</code> tables stayed at 0 rows across every bank even after multiple consolidation cycles, so Polyphonic Recall's <code>graph</code> voice (BFS over <code>findGistsByParticipant</code> / <code>findRelatedMemories</code>) always returned nothing. Consolidation now best-effort ingests the new episodic memory into <code>EpisodicGraph</code> so the gist row, gist→memory <code>ctx</code> edge, fact edges, and cross-memory similarity/entity/temporal edges land alongside the episodic row. Independent of the existing <code>MNEMOPI_PROACTIVE_LINKING</code> flag, which still gates the same enrichment on the <code>remember()</code> write path. (<a href="https://github.com/can1357/oh-my-pi/issues/2435" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2435/hovercard">#2435</a>)</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed native shell execution rejecting quoted heredocs whose closing delimiter is the final line without a trailing newline, matching bash paste-run snippets.</li>
</ul>
<h2>@oh-my-pi/omp-stats</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed the stats dashboard's SQLite init never setting <code>PRAGMA busy_timeout</code>, so a concurrent <code>omp</code> startup hitting WAL recovery could crash <code>initDb()</code> with <code>SQLITE_BUSY</code> instead of waiting through it. The busy handler is now installed before <code>PRAGMA journal_mode=WAL</code> (<a href="https://github.com/can1357/oh-my-pi/issues/2421" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2421/hovercard">#2421</a>).</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Added</h3>
<ul>
<li><code>PI_FORCE_HYPERLINKS=1</code> / <code>PI_NO_HYPERLINKS=1</code> env overrides for the OSC 8 hyperlink capability, mirroring the <code>PI_FORCE_SYNC_OUTPUT</code>/<code>PI_NO_SYNC_OUTPUT</code> shape (opt-out beats force-on).</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Auto-enable OSC 8 hyperlinks inside tmux when tmux self-reports &gt;= 3.4 via <code>TERM_PROGRAM_VERSION</code>; tmux 3.4 stores OSC 8 as a cell attribute and forwards it to outer terminals whose <code>terminal-features</code> include <code>hyperlinks</code>. Older tmux, GNU screen, and tmux without a reported version still default off. Resolution is factored into <code>hyperlinksUserOverride()</code> and <code>shouldEnableHyperlinksByDefault()</code> mirroring the sync-output helpers (<a href="https://github.com/can1357/oh-my-pi/issues/2403" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2403/hovercard">#2403</a>).</li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed abortable stream wrappers to cancel the source stream on abort, so timeout watchdogs release upstream HTTP bodies instead of only stopping the local reader.</li>
</ul>
<h2>@oh-my-pi/pi-wire</h2>
<h3>Changed</h3>
<ul>
<li>Changed <code>WireModel.contextWindow</code> and <code>ContextUsage.contextWindow</code> to <code>number | null</code> to allow representing unavailable context-window values</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(tui): respect OSC 8 hyperlinks under tmux &gt;= 3.4 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4650944240" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2404" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2404/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2404">#2404</a></li>
<li>fix(skills): load ~/.agents/skills even when third-party source toggles are off by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651011756" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2405" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2405/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2405">#2405</a></li>
<li>fix(coding-agent): stabilize mnemopi per-project bank derivation (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651832873" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2412" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2412/hovercard" href="https://github.com/can1357/oh-my-pi/issues/2412">#2412</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651944937" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2414" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2414/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2414">#2414</a></li>
<li>fix(auth): retried SQLITE_BUSY family and hoisted busy_timeout by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4652322896" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2423" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2423/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2423">#2423</a></li>
<li>fix(ai): added GITLAB_CLIENT_ID and GITLAB_REDIRECT_URI overrides for gitlab-duo OAuth by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4652454808" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2425" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2425/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2425">#2425</a></li>
<li>fix(coding-agent): restore Windows image paste fallback by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4652851725" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2430" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2430/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2430">#2430</a></li>
<li>fix(ai): deduplicate MiniMax reasoning stream by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654022523" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2434" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2434/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2434">#2434</a></li>
<li>fix(mnemopi): populated gists and graph_edges during consolidation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654648195" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2439" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2439/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2439">#2439</a></li>
<li>fix: align Mermaid ASCII box borders for CJK/emoji labels by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chan1103/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chan1103">@chan1103</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4654744037" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2442" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2442/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2442">#2442</a></li>
<li>docs: document project settings and disabledProviders by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655013563" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2448" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2448/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2448">#2448</a></li>
<li>fix(cli): defer goal objectives while streaming by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4655927611" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2455" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2455/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2455">#2455</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v15.12.3...v15.12.4"><tt>v15.12.3...v15.12.4</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Developer-Häppchen fürs Wochenende – kleinere News der Woche]]></title>
<description><![CDATA[Kleine, aber interessante Meldungshäppchen vom News-Buffet zu VS Code, Grafana Tempo, Zig, Stack Overflow, Testwell, Apache Pulsar, GitLab und Qt.]]></description>
<link>https://tsecurity.de/de/3595171/it-nachrichten/developer-haeppchen-fuers-wochenende-kleinere-news-der-woche/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595171/it-nachrichten/developer-haeppchen-fuers-wochenende-kleinere-news-der-woche/</guid>
<pubDate>Sat, 13 Jun 2026 09:32:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kleine, aber interessante Meldungshäppchen vom News-Buffet zu VS Code, Grafana Tempo, Zig, Stack Overflow, Testwell, Apache Pulsar, GitLab und Qt.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-39904 | GitLab Community Edition/Enterprise Edition 13.1 Merge Request access control (Issue 29529)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in GitLab Community Edition and Enterprise Edition 13.1. Affected by this vulnerability is an unknown functionality of the component Merge Request Handler. Performing a manipulation results in improper access controls.

This vulnerability is r...]]></description>
<link>https://tsecurity.de/de/3594379/sicherheitsluecken/cve-2021-39904-gitlab-community-editionenterprise-edition-131-merge-request-access-control-issue-29529/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594379/sicherheitsluecken/cve-2021-39904-gitlab-community-editionenterprise-edition-131-merge-request-access-control-issue-29529/</guid>
<pubDate>Fri, 12 Jun 2026 21:08:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition 13.1</a>. Affected by this vulnerability is an unknown functionality of the component <em>Merge Request Handler</em>. Performing a manipulation results in improper access controls.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2021-39904">CVE-2021-39904</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-39911 | GitLab Community Edition/Enterprise Edition 13.9 Merge Request information disclosure (Issue 29747)]]></title>
<description><![CDATA[A vulnerability was found in GitLab Community Edition and Enterprise Edition 13.9. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component Merge Request Handler. This manipulation causes information disclosure.

The identification of this vuln...]]></description>
<link>https://tsecurity.de/de/3594377/sicherheitsluecken/cve-2021-39911-gitlab-community-editionenterprise-edition-139-merge-request-information-disclosure-issue-29747/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594377/sicherheitsluecken/cve-2021-39911-gitlab-community-editionenterprise-edition-139-merge-request-information-disclosure-issue-29747/</guid>
<pubDate>Fri, 12 Jun 2026 21:08:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition 13.9</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is an unknown functionality of the component <em>Merge Request Handler</em>. This manipulation causes information disclosure.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2021-39911">CVE-2021-39911</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-39913 | GitLab Community Edition/Enterprise Edition Migration Log log file (Issue 28074)]]></title>
<description><![CDATA[A vulnerability was found in GitLab Community Edition and Enterprise Edition. It has been declared as problematic. The impacted element is an unknown function of the component Migration Log. Executing a manipulation can lead to sensitive information in log files.

The identification of this vulne...]]></description>
<link>https://tsecurity.de/de/3594376/sicherheitsluecken/cve-2021-39913-gitlab-community-editionenterprise-edition-migration-log-log-file-issue-28074/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594376/sicherheitsluecken/cve-2021-39913-gitlab-community-editionenterprise-edition-migration-log-log-file-issue-28074/</guid>
<pubDate>Fri, 12 Jun 2026 21:07:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. The impacted element is an unknown function of the component <em>Migration Log</em>. Executing a manipulation can lead to sensitive information in log files.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2021-39913">CVE-2021-39913</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Android App Penetration Testing: From APK Decompilation to Runtime Exploitation [Tools and Labs]]]></title>
<description><![CDATA[Hello, everyone. I hope you are well.بِسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيمِIn this article, I’ll cover the basics of Android penetration testing, including the required tools and how to use them. I’m not an expert Android penetration tester, but I hope you find this article useful.Before I star...]]></description>
<link>https://tsecurity.de/de/3591576/hacking/android-app-penetration-testing-from-apk-decompilation-to-runtime-exploitation-tools-and-labs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591576/hacking/android-app-penetration-testing-from-apk-decompilation-to-runtime-exploitation-tools-and-labs/</guid>
<pubDate>Thu, 11 Jun 2026 20:39:31 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><strong>Hello, everyone. I hope you are well.</strong></p><p><strong>بِسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيمِ</strong></p><p>In this article, I’ll cover the <strong>basics of Android penetration testing</strong>, including the <strong>required tools and how to use them</strong>. I’m not an expert Android penetration tester, but I hope you find this article useful.</p><p>Before I start talking about Android penetration testing tools, we need to start with an <strong>Android virtual device</strong>, OR a <strong>physical device</strong>, to work.</p><p><strong>Android Studio</strong> is the official <strong>Integrated Development Environment (IDE)</strong> for Android app development, developed by <strong>Google</strong>. It provides all the tools developers need to create, test, and debug Android apps, and it supports running apps on <strong>physical devices</strong> and <strong>emulators</strong>.</p><p>I’m using Android Studio to create an AVD (Android Virtual Device), but there <strong>are other Android emulators you can use, such as </strong><a href="https://www.genymotion.com/"><strong>Genymotion</strong></a><strong>, which is also good and easy to use.</strong></p><p><strong>In Android Studio</strong>,<strong> create an AVD </strong>to work with. I’m using Android 13 with the x86_64 CPU architecture (ABI). After you create the AVD — regardless of which emulator you choose — we’ll move on to the tools and discuss each one in detail.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Uw_7c2__3zQ2ORnlsb_tQw.png"></figure><h3>— — Some Idioms and Important Things: — —</h3><p><strong>Firstly</strong>, we need to cover some basic concepts.</p><blockquote><strong>AndroidManifest.xml: </strong>Think of it as the app’s identity card and configuration file for the Android operating system. Before the system can run any of your app’s code, it must read the manifest to understand what the app is, what components it has, and what permissions it needs.</blockquote><h3>Insecure storage: SharedPreferences, DBs, files, external storage:</h3><p>It means <strong>sensitive data</strong> (auth tokens, passwords, API keys, PII, JWTs, encryption keys, etc.) is stored on-device in a way an attacker or another app can read or modify.</p><p>Common<strong> Android storage</strong> places:</p><ul><li><strong>SharedPreferences:</strong> key/value XML files usually used for settings, Ex, /data/data/&lt;package_name&gt;/shared_prefs/</li><li><strong>SQLite databases:</strong> structured app data Ex: /data/data/&lt;package_name&gt;/databases/</li><li><strong>Cache directory:</strong>/data/data/&lt;package_name&gt;/cache/</li><li><strong>External storage:</strong> /storage/emulated/0/</li><li><strong>Logs</strong>: not strictly storage, but sensitive info in <strong>logs</strong>.</li></ul><h3>Activities:</h3><p><strong>Represents</strong> UI screens that users interact with; each <strong>activity</strong> can be started via an <strong>intent</strong> by the same app or another app.</p><ul><li><strong>Potential Security Issue: Exported</strong> activities can be accessed by <strong>other</strong> <strong>apps</strong> if not restricted. An attacker can invoke internal(sensitive) activities to make them public.</li><li><strong>Example: </strong>Suppose an app that has</li></ul><pre>&lt;activity android:name=".AdminActivity"<br>          android:exported="true"&gt;<br>&lt;/activity&gt;</pre><p>If this activity allows <strong>admin-</strong>only functions like Create, Update, and delete users, and it doesn’t check <strong>authentication</strong> <strong>internally</strong>. An attacker can create a malicious app and <strong>send</strong> an <strong>intent</strong> to it because the exported activity is <strong>true</strong>, like</p><pre>Intent i = new Intent();<br>i.setClassName("com.victim.app", "com.victim.app.AdminActivity");<br>startActivity(i);</pre><h3>Services:</h3><p>Perform background operations like playing music or downloading data; they can <strong>run</strong> even if <strong>no activity is visible</strong>.</p><ul><li><strong>Potential Security Issue: Exported</strong> services can be started or bound by <strong>other apps</strong> <strong>&amp; </strong>attacker can perform actions like <strong>sending</strong> <strong>data</strong> <strong>indirectly</strong>.</li><li><strong>Example: </strong>Suppose we have an UploadService that uploads a user file to the server without any other internal checks.</li></ul><pre>&lt;service android:name=".UploadService"<br>         android:exported="true" /&gt;</pre><p>The <strong>attacker's</strong> malicious app can send any file to upload, like the following</p><pre>Intent intent = new Intent();<br>intent.setClassName("com.victim.app", "com.victim.app.UploadService");<br>intent.putExtra("file", "/data/data/com.victim.app/userinfo.db");<br>startService(intent);</pre><h3>Broadcast Receivers:</h3><p><strong>Respond</strong> to system-wide or app messages like <strong>battery low</strong> or SMS_Received.</p><ul><li><strong>Potential Security Issue: Unprotected receivers</strong> can be triggered by <strong>malicious broadcasts</strong>. If they perform sensitive actions like deleting files or sending data.</li><li><strong>Example: If </strong>we have a <strong>Receiver</strong>, it <strong>resets</strong> the app data</li></ul><pre>&lt;receiver android:name=".ResetReceiver"<br>          android:exported="true"&gt;<br>    &lt;intent-filter&gt;<br>        &lt;action android:name="com.victim.RESET_APP"/&gt;<br>    &lt;/intent-filter&gt;<br>&lt;/receiver&gt;</pre><p>An <strong>attacker's malicious app </strong>can send things like the following to reset it.</p><pre>Intent i = new Intent("com.victim.RESET_APP");<br>sendBroadcast(i</pre><h3>Content providers:</h3><p><strong>Managed</strong> structured data like <strong>databases</strong> or files, and allowed <strong>sharing</strong> data between <strong>apps</strong> using the URI content://&lt;authority&gt;/&lt;path&gt;/&lt;id&gt;</p><ul><li><strong>Potential Security Issue:</strong> Can lead to<strong> SQL injection </strong>vulnerabilities via<strong> </strong>unchecked <strong>URI</strong> <strong>parameters</strong> OR <strong>Path traversal</strong> in file-based providers.</li><li><strong>Example: Suppose</strong> that we have a content provider that <strong>returns</strong> user data via an <strong>ID</strong> that exists in the <strong>URI</strong>.</li></ul><pre>&lt;provider android:name=".UserDataProvider"<br>          android:authorities="com.victim.app.provider"<br>          android:exported="true" /&gt;</pre><pre>Cursor c = db.rawQuery("SELECT * FROM users WHERE id=" + uri.getLastPathSegment(), null);</pre><p>An <strong>attacker</strong> can get <strong>SQL</strong> injection to <strong>get</strong> <strong>all</strong> <strong>user</strong> <strong>data</strong> by querying</p><pre>content://com.victim.app.provider/users/1 OR 1=1--</pre><h3>Web Views:</h3><p>It is an Android component that allows you to display <strong>web content</strong> directly <strong>within your app</strong>, and it can lead to different vulnerabilities. If you look for the following <strong>Java code</strong>, you will notice that you can execute JavaScript(<strong>XSS</strong>) and access internal files(<strong>LFI</strong>) because you enabled JavaScript and file access to true.</p><pre>// Vulnerable (Java)<br>WebView webView = findViewById(R.id.webview);<br>WebSettings s = webView.getSettings();<br><br>// Dangerous combination: JS + file access<br>s.setJavaScriptEnabled(true);<br>s.setAllowFileAccess(true);<br>s.setAllowFileAccessFromFileURLs(true);<br>s.setAllowUniversalAccessFromFileURLs(true);<br><br>// Loads a user-editable local file (attacker could place/modify this file)<br>webView.loadUrl("file:///sdcard/app_data/user_note.html");</pre><h3>Root Detection:</h3><p><strong>Root</strong> refers to the system-level (<strong>superuser</strong>) account. It’s equivalent to the <strong>Administrator</strong> account in Windows or the <strong>root</strong> account in Linux. <strong>Root detection</strong> is an expected security mechanism in Android apps that secures the device’s integrity. <strong>Rooting[Root detection bypass] </strong>a device gives users administrative privileges, allowing them to bypass certain security features, giving them <em>power</em> over the device, allowing them to read/modify app memory and files, intercept/alter network traffic, remove protections, and persist privileged malware.</p><h3>SSL Pinning:</h3><p><strong>SSL/TLS (HTTPS)</strong> normally trusts any certificate chain that the device’s trusted CA store accepts.<strong>SSL pinning</strong> is when an app says, “I will only <strong>trust</strong> <em>this</em> certificate (or public key/intermediate), regardless of what the <strong>OS</strong> <strong>trusts</strong>. <strong>Attackers</strong> attempt to bypass pinning to <strong>read sensitive data in transit</strong> — capture tokens, passwords, and PII. <strong>Modify requests/responses.</strong></p><h3>=============Tools And Labs ==============</h3><h3>ADB:</h3><p><strong>Android Debug Bridge</strong> is a command-line tool that lets you communicate with a device. The The adb command facilitates a variety of device actions, such as installing and debugging apps. adb provides access to a Unix shell that you can use to run a variety of commands on a device. It is a client-server program</p><p>You can use ADB after installing the Android SDK Command-line Tools, which include ADB. You can also use it with your physical device. For more details, refer to the official documentation: <a href="https://developer.android.com/tools/adb"><strong>https://developer.android.com/tools/adb</strong></a></p><p>I’m going to talk about the important commands used with the <strong>adb</strong>.</p><ul><li><strong>lists</strong> all connected <strong>devices</strong> adb devices</li><li><strong>Install APK</strong> files directly to your device using ADB adb install &lt;path_to_apk&gt;</li><li><strong>Starts a remote shell</strong> connection to your Android device adb shell <strong>&amp;&amp; Reboot</strong> the device adb reboot</li><li><strong>Copies</strong> a file from your computer to the Android device adb push &lt;local_file_path&gt; &lt;device_file_path&gt;<strong>&amp;&amp; Copies</strong> a file from your device to the computer adb pull &lt;device_file_path&gt; &lt;local_file_path&gt;</li><li><strong>Getting</strong> all the <strong>logs</strong> of your Android using adb logcat</li><li><strong>Lists</strong> the <strong>package names</strong> of all installed apps adb shell pm list packages</li><li><strong>Launches</strong> a specific activity in an app adb shell am start -n &lt;package_name&gt;/&lt;activity_name&gt;<strong>EX:</strong> adb shell am start -n com.android.settings/.Settings</li><li><strong>Other</strong> important commands -&gt; <a href="https://developer.android.com/tools/adb"><strong><em>https://developer.android.com/tools/adb</em></strong></a></li></ul><h3>APKtool:</h3><p>It is an essential tool for anyone who needs to <strong>reverse engineer</strong>, analyze, or <strong>modify</strong> Android applications (<strong>APK files</strong>). It <strong>decompiles</strong> an APK file back to <em>almost</em> its <strong>original</strong> form, and <strong>Recompiles</strong> an APK file: After you have made changes to the decoded files, Apktool can <strong>rebuild</strong> them into a <strong>new APK</strong> file. You can install it from the following: <a href="https://apktool.org/docs/install/"><strong><em>https://apktool.org/docs/install/</em></strong></a></p><p>I will walk you through a real example from the <a href="https://github.com/satishpatnayak/AndroGoat"><strong>Androgoat</strong></a> lab to show how to use the <strong>apktool command </strong>with another <strong>GUI</strong> tool like <a href="https://github.com/skylot/jadx">JadxGUI</a>. First, let’s install the lab using: adb install AndroGoat.apk</p><p><strong>Decompile the APK file using jadx GUI</strong>, add the <strong>APK file</strong> to the <strong>jadxGUI</strong> tool, and the output will look like the following</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Bp8duix32MYgTsCg-I7POQ.png"></figure><p>As you can see, it’s easy to search for different things inside the decompiled APK. For example, we findpromocode = "NEW2019"<strong>It is a security issue</strong>. If we open the <strong>AndroGoat app </strong>and go to the <strong>Hardcode Issue section</strong>, we see that the <strong>price</strong> is <strong>2000</strong>, but after we use the promo code we found, we’ll get a <strong>discounted</strong> <strong>price</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/482/1*5lUWQKFdJRxL-ivvSYp2Ow.png"></figure><p><strong>Now</strong>, let’s use the <strong>apktool</strong></p><pre>apktool d AndroGoat.apk -o AndroGoat_output # d for decompile the app # -o the output directory</pre><p>In the output directory, you’ll see structures similar to what we saw in <strong>JadxGUI</strong>.</p><p>In our lab, if we explore the files, we’ll find the<strong> Binary Patching section</strong>, which contains an <strong>Administration button</strong> that we can’t access. But think about this: what if we could modify the <strong>decompiled</strong> code behind that button and then <strong>recompile</strong> the app?</p><blockquote><strong>Binary Patching: </strong>Modifying the app’s binary code to alter its behavior, such as disabling security features or enabling hidden functionalities.</blockquote><p>After some search using <strong>JadxGUI</strong> or <strong>apktool</strong>, I found</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*EMujz-TDwqc7AWrbH-RP-Q.png"></figure><p>The file res/layout/activity_binary_patching.xmlcontains the following button, which has enabled="false"</p><pre>&lt;Button<br>        android:enabled="false"<br>        android:id="@+id/adminButton"<br>        android:layout_width="match_parent"<br>        android:layout_height="wrap_content"<br>        android:layout_marginLeft="15dp"<br>        android:layout_marginTop="5dp"<br>        android:layout_marginRight="15dp"<br>        android:text="Administration"/&gt;</pre><p>Now we know where the file is located and what we need to change, so let’s go to our <strong>APKTool </strong>output<strong>, </strong><strong>AndroGoat_output/res/layout/activity_binary_patching.xml </strong>then modify the <strong>false</strong> to <strong>true. </strong>Then <strong>recompile</strong> it using the following steps.</p><ul><li><strong>Firstly, </strong>we will create an <strong>unsigned APK file</strong> that Android won’t install because Android <strong>requires</strong> apps to <strong>be signed </strong>to verify integrity and developer identity..</li></ul><pre>apktool b AndroGoat_output -o New_Target_APK_Name.apk # b recombile and -o for the Name of the new APK file</pre><ul><li><strong>Secondly,</strong> <strong>generate a signing key</strong>. It will ask you some questions (name, organization, etc.) and a <strong>password</strong> for the keystore and alias. You can leave them by default.</li></ul><pre>keytool -genkey -v -keystore Any_KeyStore_Name -keyalg RSA -keysize 2048 -validity 1000 -alias Any_Alias_Name<br># -genkey → generate a new key pair.<br># -keystore Any_KeyStore_Name → file where your private key is stored.<br># -keyalg RSA -keysize 2048 → algorithm &amp; key strength (standard).<br># -validity 1000 → number of days the key is valid (e.g., ~3 years).<br># -alias Any_Alias_Name → nickname for your key (you’ll use this later when signing).<br># Also you can use &lt;zipalign&gt; instead of keytool</pre><ul><li><strong>Thirdly,</strong> now use <strong>apksigner</strong> (part of Android SDK build-tools) to sign the APK:</li></ul><pre>apksigner sign --ks Any_KeyStore_Name --ks-key-alias Any_Alias_Name New_AndroGoat.apk<br># --ks → keystore file you created.<br># --ks-key-alias → alias name of your key inside the keystore.<br># New_AndroGoat.apk → unsigned APK to sign.</pre><ul><li><strong>Fourthly,</strong> <strong>verify</strong> the <strong>signature</strong> and <strong>install</strong></li></ul><pre>apksigner verify New_AndroGoat.apk # If it outputs nothing, the signature is valid<br>adb install ./New_AndroGoat.apk # Install the new Android app</pre><p>After we return to the same screen and recheck the <strong>Administration button</strong>, we can now access it <strong>successfully</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6fR5KD9msIOzSM1rFqkSag.png"></figure><h4>Root Access:</h4><p>If we tried to access the <strong>adb shell as root</strong>, we would get</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/555/1*sY6CTQ4RJ5jgQZKxS2TNyA.png"></figure><pre>git clone https://gitlab.com/newbit/rootAVD.git<br>cd rootAVD<br>bash rootAVD.sh ListAllAVDs # To list avds<br># Based on your avd we will use on of the result of rootAVD like the following I use<br>bash rootAVD.sh system-images/android-36/google_apis_playstore/x86_64/ramdisk.img</pre><p>You’ll see that Magisk has been installed, and your <strong>AVD</strong> will <strong>reboot</strong> <strong>automatically</strong>. Then, open the <strong>Magisk app</strong> and execute it within the <strong>Superuser</strong>. After that, you’ll be able to use the ADB shell with root access easily.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/392/1*D78wbjAas8CH1SZD-qQ2Xg.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*7Ax8T2n2KYudUGK4E6jj8g.png"></figure><p>Now that we have <strong>root access </strong>on our device, we run into a new problem: some applications detect that the device is rooted and<strong> block access</strong>. To bypass this, we need a root detection bypass. Instead of unrooting our emulator (which we still need for testing), we can simply use <strong>Frida to hook</strong> the <strong>isRooted</strong> function and force it to always return <strong>false</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/787/1*92Vyn2xlDGm2kkNQhhBImA.png"></figure><p>Understand how root detection works in the target app. In the AndroidManifest.xml file, you’ll find an activity called RootDetectionActivity.If you analyze its code, you’ll see a method named isRooted() that checks for signs of a rooted device, such as the presence of binaries like su or known root-related packages like Superuser.</p><ul><li>If isRooted() returns trueThe app displays: <strong>“Device is Rooted”</strong>.</li><li>If isRooted() returns falseThe app displays: <strong>“Device is Not Rooted”</strong>.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Zj5jio4-ZBaIaV4fASmeuQ.png"></figure><p>Let’s now use the following <strong>script</strong> to bypass it</p><pre>Java.perform(function () {<br><br>    console.log("[*] Root bypass loaded");<br><br>    var RootDetectionActivity = Java.use(<br>        "owasp.sat.agoat.RootDetectionActivity"<br>    );<br><br>    // Bypass isRooted()<br>    RootDetectionActivity.isRooted.implementation = function () {<br>        console.log("[+] isRooted() bypassed");<br>        return false;<br>    };<br><br>    // Bypass isRooted1()<br>    RootDetectionActivity.isRooted1.implementation = function () {<br>        console.log("[+] isRooted1() bypassed");<br>        return false;<br>    };<br><br>});</pre><pre>frida -U -f owasp.sat.agoat -l bypass.js<br># Below, I will explain how to use the Frida tool.</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*41kmcGFd3gElcF9flYVfVQ.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/737/1*HXD7JZRy4lHBja_squVSzA.png"></figure><h4>Insecure Data Storage: SharedPreferences, DBs, files, external storage:</h4><p>We’ve already explained the concept, but now we’ll look at how it appears in the<strong> AndroGoat lab</strong> under the Insecure Storage section.</p><p><strong>Firstly</strong>, we need to know the <strong>package</strong> of our lab using <strong>adb shell pm list packages | grep "goat"-&gt; Result</strong> -&gt; <strong>package:owasp.sat.agoat</strong>If we go to the following <strong>/data/data/owasp.sat.agoat/</strong>We will see different folders like <strong>cache</strong>, <strong>code_cache</strong>, <strong>databases</strong>, and <strong>shared_prefs. </strong>Suppose username and password are (<strong>admin</strong>: <strong>admin</strong>).</p><p>Firstly, we need to identify the package name of our lab using: <strong>adb shell pm list packages | grep "goat"-&gt; Result</strong> -&gt; <strong>package:owasp.sat.agoat</strong>Next, navigate to: <strong>/data/data/owasp.sat.agoat/</strong>Here, you’ll see different folders like <strong>cache</strong>, <strong>code_cache</strong>, <strong>databases</strong>, and <strong>shared_prefs</strong>.</p><ul><li><strong>shared_prefs, </strong>we will see the <strong>users.xml files</strong>, which contain the <strong>credentials</strong> in XML format. Also, we can edit the file as we want, like the <strong>score.xml </strong>file.</li><li><strong>databases: </strong>pull the <strong>aGoat file, then </strong>use the <strong>SQLite3 command or DB Browser GUI </strong>for better data extraction, as you’ll see.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*7ejDNIgvnMBfThAql20uoQ.png"></figure><ul><li><strong>Inside the Side Channel Data Leakage section</strong>, if we go to I<strong>nsecure Logging</strong> and enter a<strong>dminlog:adminlog</strong>, then run the following</li></ul><pre>adb logcat - pid=$(adb shell pidof -s owasp.sat.agoat)<br># we will see everything realted to our target APP</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*k5VWQ1EcmmQsCBmECeWf-Q.png"></figure><h3>Drozer:</h3><p>An <strong>Android</strong> application security testing <strong>framework</strong> that helps testers find vulnerabilities. <strong>Drozer has different modules,</strong> each with its own operation. <strong>EX:</strong> Static analysis of an application — Performing enumeration on various packages — Creating Exploits for activities and content providers — Automating SQL injection.</p><p>You can <a href="https://github.com/ReversecLabs/drozer"><strong>install</strong></a> it using <strong>Docker</strong> or <strong>pip</strong> → <strong>pip install drozer</strong> You also need the <a href="https://github.com/ReversecLabs/drozer-agent/releases"><strong>Drozer Agent</strong></a><strong> </strong>installed on your Android device. <strong>Start</strong> the <strong>drozer agent</strong>, then <strong>adb forward tcp:31415 tcp:31415Finally</strong>, <strong>start</strong> the <strong>drozer</strong> <strong>console</strong> by running the <strong>drozer console connect</strong>.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*lB02ixqE3Jgtd-PneT2QsQ.png"></figure><p>I’ll walk through the <strong>different</strong> <strong>modules</strong> available in <strong>Drozer and ADB</strong>.</p><ul><li>For <strong>Packages</strong><strong>run app.package.list</strong> — list installed packages. <strong>&amp;&amp;</strong> <strong>run app.package.list -f &lt;Name&gt;</strong> — search for a package by name substring. <strong>&amp;&amp;</strong> <strong>run app.package.info -a &lt;package.name&gt;</strong> — <strong>basic info</strong>: permissions, version about our target package.</li><li>For <strong>Activities</strong><strong>run app.activity.info -a &lt;package.name&gt;</strong> —<strong> list activities</strong> that are <strong>exported</strong>. <strong>&amp;&amp;</strong> <strong>run app.activity.start --component &lt;pkg&gt; &lt;ActivityName&gt;</strong> — attempt to <strong>start</strong> an <strong>exported activity</strong>.</li><li>For <strong>Services</strong> <strong>run app.service.info -a &lt;package.name&gt;</strong> — list services and permissions required. <strong>&amp;&amp; </strong><strong>run app.service.start</strong> / <strong>run app.service.stop</strong> — <strong>start</strong> or stop services. <strong>&amp;&amp; </strong><strong>run app.service.send &lt;pkg&gt; &lt;ServiceName&gt; --msg &lt;args&gt; --extra &lt;key&gt; &lt;value&gt;</strong> — interact with started service (send intents/bundles).</li><li>For<strong> Content providers </strong><strong>run app.provider.info -a &lt;package.name&gt;</strong> — <strong>list</strong> providers and permissions. <strong>&amp;&amp; </strong><strong>run scanner.provider.finduris -a &lt;package.name&gt;</strong> — <strong>Enumerate</strong> likely content <strong>URIs</strong> (common attack vector). <strong>&amp;&amp; </strong><strong>run app.provider.query content://... --vertical</strong> — query an accessible content provider URI. &amp; <strong>run app.provider.read content://.../path </strong>— attempt to read local files.</li><li>For <strong>Broadcast receivers </strong><strong>run app.broadcast.info -a &lt;package.name&gt;</strong> — list broadcast receivers and export status. <strong>&amp;&amp;</strong><strong>run app.broadcast.send --action &lt;pkg&gt;.&lt;ReceiverAction&gt; --extra "k=v"</strong> — send crafted intents to receivers.</li></ul><p>There are additional modules and features in Drozer. You can see more details by using the <strong>list</strong> command inside the tool. <a href="https://labs.withsecure.com/tools/drozer">https://labs.withsecure.com/tools/drozer</a> <strong>and</strong> <a href="https://angelica.gitbook.io/hacktricks/mobile-pentesting/android-app-pentesting/drozer-tutorial">https://angelica.gitbook.io/hacktricks/mobile-pentesting/android-app-pentesting/drozer-tutorial</a>.</p><h4>Unprotected Android Components:</h4><p>We need to verify the PIN to be able to log in, but what if we bypass the activity that <strong>handles</strong> this <strong>verification</strong>? If we use <strong>Drozer</strong> to interact with the app’s activities, we can attempt to start the protected activity directly and <strong>bypass the PIN check</strong>. Ex<strong>run app.activity.info -a owasp.sat.agoat</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1007/1*M-nQ6ExzCq7xlwhftPpvJg.png"></figure><ul><li><strong>Start</strong> the exported activity using it, <strong>run app.activity.start --component owasp.sat.agoat owasp.sat.agoat.AccessControl1ViewActivity</strong>and we will <strong>bypass</strong> it <strong>successfully</strong>.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*98gDeRw--mK-a2kY5-6GdQ.png"></figure><h4>Input Validations:</h4><p>Insecure or missing user input validation can introduce serious security vulnerabilities in Android apps, such as <strong>XSS</strong> or <strong>SQLI</strong>, or <strong>LFI</strong>.</p><ul><li><strong>XSS:</strong> If we enter any <strong>value</strong> into the <strong>Name</strong> field, we notice that this value is <strong>reflected</strong> in the page body. Let’s dig deeper by inspecting the <strong>XSSActivity</strong> with <strong>Jadx</strong>. You’ll see that it uses a <strong>WebView</strong>, and, importantly, that <strong>JavaScript is enabled</strong> for this WebView. This setup allows for XSS injection, as user-supplied input is passed directly into the web content without proper sanitization.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*AlGib0C1c0aW9GnwqgTGgA.png"></figure><p>Let’s <strong>inject</strong> an <strong>XSS payload</strong> like <strong>&lt;script&gt;alert("Hacked")&lt;/script&gt;</strong> Then you will see a <strong>JavaScript</strong> alert box.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vAy3v097SRKGpz0xJ-Pv7g.png"></figure><ul><li><strong>SQL Injection (SQLI): </strong>When user input is directly included in an SQL statement without proper validation or sanitization, as exists in the <strong>SQLInjectionActivity</strong>, it creates an SQL Injection vulnerability. For example, if we enter: <strong>admin'</strong> This will typically cause an <strong>SQL error</strong> because of the unmatched single quote. To exploit this, we can inject a payload such as: <strong>admin'OR 1=1;--</strong>This statement <strong>alters the original SQL logic</strong> and <strong>returns all users</strong> from the <strong>database</strong>, clearly demonstrating a successful SQL injection attack.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*0YR2DtWQAKiT1NFu5pXryw.png"></figure><ul><li><strong>WebView(Local file access): </strong>an attacker can a<strong>ccess local files </strong>if the allow file access is set to true, as exists in the following</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/520/1*fSAs4dQYW4Mgex8FXoJKvA.png"></figure><blockquote><strong>While</strong> <strong>JavaScript</strong> itself is generally <strong>safe</strong>, enabling the following settings can expose your application to <strong>various vulnerabilities</strong>.</blockquote><pre>WebSettings settings = webView.getSettings();<br>settings.setJavaScriptEnabled(true); <br>settings.setAllowFileAccess(true); <br>settings.setAllowContentAccess(true);<br>settings.setAllowFileAccessFromFileURLs(true);<br>settings.setAllowUniversalAccessFromFileURLs(true);</pre><h4>SSL Pinning bypass:</h4><p>There are different ways to <strong>bypass</strong> the SSL pinning.</p><ul><li><strong>For Static review</strong>, <strong>inspect</strong> the application code for pinning libraries — Custom trust managers — <strong>Hardcoded certs </strong>— and <strong>Public keys </strong>in the source or resources.<strong> EX:</strong><strong>network_security_config.xml analysis</strong> — Many apps explicitly configure cleartext traffic permissions and cert pinning here. This file is in res/xml/ and is often the first thing to check after decompiling. Misconfigured entries &lt;base-config cleartextTrafficPermitted="true"/&gt; are instant findings.</li><li><strong>For Dynamic:</strong> we will use different tools like <strong>Objection</strong>, <strong>Frida</strong>, and <strong>Burp</strong> for request interception.</li></ul><h3>Burp Suite:</h3><p>a <strong>web application security testing platform</strong> used to <strong>intercept</strong>, inspect, and manipulate HTTP(S) traffic. created by <a href="https://portswigger.net/burp">https://portswigger.net/burp</a>.</p><p><strong>— Steps to intercept requests using Burp </strong>in Android:</p><ul><li><strong>Run Burp</strong>, then go to the <strong>Add proxy listener</strong> → choose the IP address 192 with port 8080. Then, in the Android emulator, navigate to <a href="http://192/">http://192</a> in <strong>Chrome</strong> and download the <strong>.cert </strong>file. Then, go to <strong>settings</strong>, then more <strong>security and privacy</strong> → <strong>Encryption &amp; credentials </strong>→ install a certificate → choose the certificate downloaded.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/678/1*sMX5opySfqiNXPVFTu-raw.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/971/1*wtCWxW3shNzBAKqtlCmyoA.png"></figure><ul><li>Go to the <strong>Mobile Network Security</strong> → <strong>Internet</strong> → choose the AndroidWifi →Edit it → change the IP to 192 IP → You can intercept Requests easily.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/440/1*DDYpcwCKLEL59uDyjfxBbw.png"></figure><ul><li><strong>Network Intercepting: If you navigate to the HTTP section inside it, you can intercept requests via the Burp Suite proxy.</strong></li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*A21fR1MvVu-nK8YSmOdNtQ.png"></figure><p>However, when we press the <strong>HTTPS</strong> button, an error message appears stating <strong>“please intercept using proxy,”</strong> and no requests are captured in Burp Suite. This indicates that <strong>SSL pinning</strong> is <strong>enabled</strong> in the application, so we need to bypass this protection to intercept HTTPS traffic. To bypass SSL pinning, <strong>several tools</strong> are commonly used: <strong>Frida or Objection.</strong></p><h3>Frida:</h3><p>It is a <strong>free</strong> and open-source dynamic instrumentation toolkit that lets you <strong>inject snippets of JavaScript</strong> into running processes to <strong><em>hook functions</em></strong><em>, inspect/modify memory, intercept APIs, and implement custom runtime behavior</em></p><p>— <strong>How to install it:</strong></p><ol><li>Make sure you have <a href="https://github.com/frida/frida"><strong>Frida</strong></a><strong> installed</strong> on your workstation (laptop/PC): <strong>pip3 install frida-tools</strong></li><li><strong>Identify</strong> Device <strong>Architecture</strong>: Determine the<strong> CPU architecture</strong> for your Android device/emulator. <strong>Run</strong> this <strong>ADB command</strong> to check your device’s architecture <strong>adb shell getprop ro.product.cpu.abi </strong>You will get in response something like<strong> x86_64 </strong>.</li><li><strong>Download</strong> the Corresponding Frida Server: Go to the <a href="https://github.com/frida/frida/releases">official Frida releases page</a> and scroll to assets. <strong>Download</strong> the <strong>frida-server</strong> file that matches your device’s architecture (e.g., <strong>frida-server-&lt;version&gt;-android-x86_64.xz</strong> for x86_64).</li><li><strong>Extract</strong> it with <strong>xz -d frida-server.xz</strong></li><li><strong>Push</strong> and <strong>Run</strong> Frida Server on Your Device: <strong>a]</strong> <strong>Transfer</strong> the server binary to your device <strong>db push frida-server /data/local/tmp/</strong> [<strong>b] Set</strong> executable <strong>permission</strong>: <strong>db shell "chmod 755 /data/local/tmp/frida-server"</strong>[<strong>c]</strong> <strong>Start</strong> Frida server<strong>adb shell "/data/local/tmp/frida-server &amp;"</strong>.</li><li><strong>Run</strong> <strong>frida-ps -Ua</strong>To <strong>confirm</strong> that <strong>Frida</strong> is <strong>running</strong> on your device and to <strong>list</strong> the currently <strong>running</strong> apps.</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*a3OMS3uRmr2lilOS8feqiQ.png"></figure><p><strong>— How to use:</strong></p><pre>// hook_android_login.js<br>/*<br>The script hooks the authenticate(String user, String pass) method<br>1. Prints the original username and password sent by the app.<br>2. Replaces them with attacker-controlled values.<br>3. Calls the original authenticate method but using the new credentials.<br>4. Prints the result returned by the original method.<br>5. Returns that result back to the app.<br>*/<br>Java.perform(function () {<br>  var LoginManager = Java.use("com.example.app.LoginManager");<br>  LoginManager.authenticate.overload("java.lang.String","java.lang.String").implementation = function (user, pass) {<br>    console.log("[+] authenticate called. user:", user, "pass:", pass);<br>    // change credentials<br>    var newUser = "attacker";<br>    var newPass = "p@ssw0rd";<br>    console.log("[+] replacing creds with", newUser, newPass);<br>    var result = this.authenticate(newUser, newPass);<br>    console.log("[+] original result:", result);<br>    return result;<br>  };<br>});<br></pre><pre>frida -U -f com.example.app -l hook_android_login.js<br># -U Stands for USB device.Tells Frida to connect to the device.<br># -f Launches the target app (package name) from the beginning before injecting the script.<br># -l Loads your Frida script at startup.</pre><h4>SSL Pinning bypass using frida:</h4><p>You can create your own script to bypass SSL pinning or utilize existing scripts available at <a href="https://codeshare.frida.re/"><strong>https://codeshare.frida.re/</strong></a></p><pre>frida -U --codeshare akabe1/frida-multiple-unpinning -f Package_Name<br># This is an example for ssl pinning bypass</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-_Hl4Wkj56_ZpenjnZtWMw.png"></figure><blockquote>If you <strong>encounter</strong> any <strong>errors</strong> or <strong>problems</strong>, you can use the following repo to automate most of the process with the included scripts. <a href="https://github.com/httptoolkit/frida-interception-and-unpinning"><strong>https://github.com/httptoolkit/frida-interception-and-unpinning</strong></a></blockquote><p><strong>In the end</strong>, you will be able to <strong>bypass</strong> it.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*KJC7g8A324oHujNytGkZYg.png"></figure><h3><strong>Other Important Topics</strong>:</h3><ul><li><strong>Deep link / App Link hijacking </strong>is one of the most important Android IPC/client-side attack vectors. allow apps to open specific screens directly from <strong>browsers</strong> — <strong>emails</strong> — <strong>QR codes EX: mybank://transfer?id OR </strong><a href="https://bank.example.com/"><strong>https://bank.example.com</strong></a></li></ul><pre>&lt;!-- Example vulnerable manifest --&gt;<br>&lt;intent-filter&gt;<br>    &lt;action android:name="android.intent.action.VIEW"/&gt;<br>    &lt;category android:name="android.intent.category.DEFAULT"/&gt;<br>    &lt;category android:name="android.intent.category.BROWSABLE"/&gt;<br><br>    &lt;data<br>        android:scheme="mybank"<br>        android:host="transfer"/&gt;<br>&lt;/intent-filter&gt;<br></pre><p><strong>Also</strong>, it can lead to accessing<strong> local files</strong>, like the following attack</p><pre>adb shell am start -a android.intent.action.VIEW -d 'insecureshop://com.insecureshop/web?url=file:///etc/hosts’ </pre><ul><li><strong>Firebase/backend misconfiguration</strong> — Insecure Firebase Realtime Database and Storage rules are found in real apps. Check by looking in the resource files, specifically res/values/strings.xml or by locating the google-services.json config file that is sometimes packaged with the app from the APK, and testing unauthenticated read/write access:</li></ul><pre># Example which contain (.firebaseio.com) but you need to add .json at the end<br>curl "https://your-app.firebaseio.com/.json"<br># If it returns data, unauthenticated read is enabled</pre><ul><li><a href="https://github.com/dwisiswant0/apkleaks"><strong>apkleaks</strong></a><strong> for automated secret scanning</strong> — Running apkleaks -f target.apk -o leaks.jsonautomatically greps for API keys, tokens, and credentials across decompiled output. Faster than manual grep in jadx.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/680/1*gg1vTjeqoDeyt6_TrfVtCg.png"></figure><h3>References:</h3><p><strong>Here</strong> are many references that you can read.</p><ul><li><a href="https://github.com/imran-parray/Mind-Maps/tree/master"><strong>GitHub — imran-parray/Mind-Maps: Mind-Maps of Several Things</strong></a></li><li><a href="https://github.com/DevHackz/Android-Pentesting"><strong>https://github.com/DevHackz/Android-Pentesting</strong></a></li><li><a href="https://github.com/dn0m1n8tor/AndroidPentest101"><strong>https://github.com/dn0m1n8tor/AndroidPentest101</strong></a></li><li><a href="https://github.com/tanprathan/MobileApp-Pentest-Cheatsheet"><strong>https://github.com/tanprathan/MobileApp-Pentest-Cheatsheet</strong></a></li><li><a href="https://github.com/Hrishikesh7665/Android-Pentesting-Checklist"><strong>https://github.com/Hrishikesh7665/Android-Pentesting-Checklist</strong></a></li><li><a href="https://github.com/B3nac/Android-Reports-and-Resources"><strong>https://github.com/B3nac/Android-Reports-and-Resources</strong></a></li><li><a href="https://xmind.app/m/GkgaYH/#"><strong>https://xmind.app/m/GkgaYH/#</strong></a></li></ul><p><strong>Follow me</strong> on <a href="https://x.com/khaledyasse1882"><strong>X</strong></a> and <a href="https://www.linkedin.com/in/khaled-yassen-40a826206/"><strong>LinkedIn</strong></a></p><a href="https://medium.com/media/016ac8bc0f8343255720d2264a0c0370/href">https://medium.com/media/016ac8bc0f8343255720d2264a0c0370/href</a><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=5fc2fc68fc5d" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/android-app-penetration-testing-from-apk-decompilation-to-runtime-exploitation-tools-and-labs-5fc2fc68fc5d">Android App Penetration Testing: From APK Decompilation to Runtime Exploitation [Tools and Labs]</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-1500 | GitLab Community Edition/Enterprise Edition up to 18.10.7/18.11.4/19.0.1 File allocation of resources (EUVD-2026-36233)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in GitLab Community Edition and Enterprise Edition up to 18.10.7/18.11.4/19.0.1. The affected element is an unknown function of the component File Handler. Performing a manipulation results in allocation of resources.

This vulnerability...]]></description>
<link>https://tsecurity.de/de/3591085/sicherheitsluecken/cve-2026-1500-gitlab-community-editionenterprise-edition-up-to-18107181141901-file-allocation-of-resources-euvd-2026-36233/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591085/sicherheitsluecken/cve-2026-1500-gitlab-community-editionenterprise-edition-up-to-18107181141901-file-allocation-of-resources-euvd-2026-36233/</guid>
<pubDate>Thu, 11 Jun 2026 17:36:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 18.10.7/18.11.4/19.0.1</a>. The affected element is an unknown function of the component <em>File Handler</em>. Performing a manipulation results in allocation of resources.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-1500">CVE-2026-1500</a>. Remote exploitation of the attack is possible. No exploit is available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [hoch] GitLab: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, serverseitige Request-Forgery- und Cross-Site-Scripting-Angriffe durchzuführen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.]]></description>
<link>https://tsecurity.de/de/3590337/it-security-nachrichten/neu-hoch-gitlab-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590337/it-security-nachrichten/neu-hoch-gitlab-mehrere-schwachstellen/</guid>
<pubDate>Thu, 11 Jun 2026 13:23:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, serverseitige Request-Forgery- und Cross-Site-Scripting-Angriffe durchzuführen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab schließt zwölf Lücken – zwei ermöglichen Kontoübernahmen - All About Security]]></title>
<description><![CDATA[All About Security Das Online-Magazin zu Cybersecurity (Cybersicherheit). Ransomware, Phishing · Home · News · Newsletter · Management · Netzwerke.]]></description>
<link>https://tsecurity.de/de/3589749/it-security-nachrichten/gitlab-schliesst-zwoelf-luecken-zwei-ermoeglichen-kontouebernahmen-all-about-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589749/it-security-nachrichten/gitlab-schliesst-zwoelf-luecken-zwei-ermoeglichen-kontouebernahmen-all-about-security/</guid>
<pubDate>Thu, 11 Jun 2026 09:29:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[All About <b>Security</b> Das Online-Magazin zu Cybersecurity (Cybersicherheit). Ransomware, Phishing · Home · News · Newsletter · Management · Netzwerke.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab Patches Multiple Flaws Enabling Account Takeover Attacks]]></title>
<description><![CDATA[GitLab released security updates on June 10, 2026, patching 12 vulnerabilities across GitLab CE/EE and EE, including high-severity flaws that could enable full account takeover, arbitrary client-side code execution, and unauthenticated denial-of-service. All self-managed administrators are strong...]]></description>
<link>https://tsecurity.de/de/3589711/it-security-nachrichten/gitlab-patches-multiple-flaws-enabling-account-takeover-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589711/it-security-nachrichten/gitlab-patches-multiple-flaws-enabling-account-takeover-attacks/</guid>
<pubDate>Thu, 11 Jun 2026 09:09:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GitLab released security updates on June 10, 2026, patching 12 vulnerabilities across GitLab CE/EE and EE, including high-severity flaws that could enable full account takeover, arbitrary client-side code execution, and unauthenticated denial-of-service. All self-managed administrators are strongly urged to upgrade to GitLab 19.0.2, 18.11.5, or 18.10.8 immediately. The most alarming vulnerability in this release is CVE-2026-6552 (CVSS 8.7), an […]</p>
<p>The post <a href="https://cyberpress.org/gitlab-patches-multiple-flaws/">GitLab Patches Multiple Flaws Enabling Account Takeover Attacks</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-06-11 09h : 4 posts]]></title>
<description><![CDATA[4 posts were published in the last hour 6:34 : China-Linked JDY Botnet Hijacks 1,500+ IoT Devices for Rapid Exploits 6:34 : GitLab Patches Multiple Vulnerabilities Allowing Account Takeover 6:34 : Hackers Exploit AWS CloudTrail and Google Cloud Logging to…
Read more →
The post IT Security News Ho...]]></description>
<link>https://tsecurity.de/de/3589710/it-security-nachrichten/it-security-news-hourly-summary-2026-06-11-09h-4-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589710/it-security-nachrichten/it-security-news-hourly-summary-2026-06-11-09h-4-posts/</guid>
<pubDate>Thu, 11 Jun 2026 09:09:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>4 posts were published in the last hour 6:34 : China-Linked JDY Botnet Hijacks 1,500+ IoT Devices for Rapid Exploits 6:34 : GitLab Patches Multiple Vulnerabilities Allowing Account Takeover 6:34 : Hackers Exploit AWS CloudTrail and Google Cloud Logging to…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-11-09h-4-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-11-09h-4-posts/">IT Security News Hourly Summary 2026-06-11 09h : 4 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab Patches Multiple Vulnerabilities Allowing Account Takeover]]></title>
<description><![CDATA[GitLab has released security updates for GitLab CE/EE and EE that patch multiple vulnerabilities, including several high‑impact flaws that could lead to account takeover, data exposure, and denial of service if left unpatched. Administrators are strongly advised to upgrade to…
Read more →
The pos...]]></description>
<link>https://tsecurity.de/de/3589662/it-security-nachrichten/gitlab-patches-multiple-vulnerabilities-allowing-account-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589662/it-security-nachrichten/gitlab-patches-multiple-vulnerabilities-allowing-account-takeover/</guid>
<pubDate>Thu, 11 Jun 2026 08:37:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GitLab has released security updates for GitLab CE/EE and EE that patch multiple vulnerabilities, including several high‑impact flaws that could lead to account takeover, data exposure, and denial of service if left unpatched. Administrators are strongly advised to upgrade to…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/gitlab-patches-multiple-vulnerabilities-allowing-account-takeover/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/gitlab-patches-multiple-vulnerabilities-allowing-account-takeover/">GitLab Patches Multiple Vulnerabilities Allowing Account Takeover</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab Patches Multiple Vulnerabilities Allowing Account Takeover]]></title>
<description><![CDATA[GitLab has released security updates for GitLab CE/EE and EE that patch multiple vulnerabilities, including several high‑impact flaws that could lead to account takeover, data exposure, and denial of service if left unpatched. Administrators are strongly advised to upgrade to GitLab 19.0.2, 18.11...]]></description>
<link>https://tsecurity.de/de/3589612/it-security-nachrichten/gitlab-patches-multiple-vulnerabilities-allowing-account-takeover/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589612/it-security-nachrichten/gitlab-patches-multiple-vulnerabilities-allowing-account-takeover/</guid>
<pubDate>Thu, 11 Jun 2026 08:12:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GitLab has released security updates for GitLab CE/EE and EE that patch multiple vulnerabilities, including several high‑impact flaws that could lead to account takeover, data exposure, and denial of service if left unpatched. Administrators are strongly advised to upgrade to GitLab 19.0.2, 18.11.5, or 18.10.8, as applicable, to fully mitigate these issues. GitLab Patches Multiple […]</p>
<p>The post <a href="https://gbhackers.com/gitlab-patches-multiple-vulnerabilities-4/">GitLab Patches Multiple Vulnerabilities Allowing Account Takeover</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Defender 'RoguePlanet' Zero-Day Grants SYSTEM Privileges]]></title>
<description><![CDATA[A researcher using the name Nightmare Eclipse has released a new Microsoft Defender zero-day exploit called "RoguePlanet," which reportedly works on fully patched Windows 10 and 11 systems and can spawn a command prompt with SYSTEM privileges through a Defender race condition. The release came ju...]]></description>
<link>https://tsecurity.de/de/3589141/it-security-nachrichten/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589141/it-security-nachrichten/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/</guid>
<pubDate>Thu, 11 Jun 2026 01:07:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A researcher using the name Nightmare Eclipse has released a new Microsoft Defender zero-day exploit called "RoguePlanet," which reportedly works on fully patched Windows 10 and 11 systems and can spawn a command prompt with SYSTEM privileges through a Defender race condition. The release came just hours after Microsoft fixed two previously disclosed flaws during its latest monthly Patch Tuesday drop -- its largest Patch Tuesday release ever. BleepingComputer reports: The researcher shared a proof-of-concept exploit on Tuesday afternoon in a self-hosted Git repository after saying that GitHub and GitLab repositories hosting their exploits had previously been removed by Microsoft. "The exploit is a race condition, so it's a hit or miss. I have managed to get a 100% success rate on some machines while it struggled to work on others," Nightmare Eclipse wrote in the repository.
 
[...] Cybersecurity firm ThreatLocker told BleepingComputer that they successfully reproduced the flaw in their testing and confirmed the exploit worked against fully patched Windows 11 systems with KB5094126 installed, and shared a video demonstrating it. "Our initial analysis confirms that the RoguePlanet exploit is viable and performs as described. Organizations using application allowlisting can prevent the exploit from executing, providing an effective layer of protection against this attack," Danny Jenkins, CEO of ThreatLocker, told BleepingComputer.
 
According to Nightmare Eclipse, RoguePlanet was originally developed as a remote code execution vulnerability that exploited Microsoft Defender's handling of files hosted on remote SMB shares. "In initial development, it was confirmed that this vulnerability was a remote code execution," the researcher explained in a blog post. "It required an attacker to coerce a victim to open a .vhd(x) in a remote SMB server, succesful exploitation resulted in defender overwriting its own files and obviously the end outcome was an RCE."
 
The researcher says another attack scenario could lead to remote code execution simply by coercing a victim into opening an SMB share if symlink evaluation settings were enabled. However, the researcher claims Microsoft silently hardened Defender in mid-May by patching "mpengine!SysIO*" API, which blocked junction attacks. "Rewriting RoguePlanet to make it functional again drained my soul and I couldn't complete the other scenarios and for now it remains unclear if RoguePlanet is limited to LPE or there is some sort of way to turn it into an RCE," the researcher wrote.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Microsoft+Defender+'RoguePlanet'+Zero-Day+Grants+SYSTEM+Privileges%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F06%2F10%2F2053232%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F06%2F10%2F2053232%2Fmicrosoft-defender-rogueplanet-zero-day-grants-system-privileges%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/26/06/10/2053232/microsoft-defender-rogueplanet-zero-day-grants-system-privileges?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Buildroot 2026.05 released]]></title>
<description><![CDATA[Version
2026.05 of the Buildroot tool
has been released. Buildroot simplifies and automates the process of
building embedded Linux systems using cross-compilation. Notable
changes in this release include support for Arm Neoverse cores,
addition of XFS rootfs generation, as well as many package up...]]></description>
<link>https://tsecurity.de/de/3587945/linux-tipps/buildroot-202605-released/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587945/linux-tipps/buildroot-202605-released/</guid>
<pubDate>Wed, 10 Jun 2026 16:31:59 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://lore.kernel.org/buildroot/87fr2wpxhj.fsf@dell.be.48ers.dk/T/#u">Version
2026.05</a> of the <a href="https://buildroot.net/">Buildroot</a> tool
has been released. Buildroot simplifies and automates the process of
building embedded Linux systems using cross-compilation. Notable
changes in this release include support for Arm Neoverse cores,
addition of XFS rootfs generation, as well as many package updates and
bug fixes. See the <a href="https://gitlab.com/buildroot.org/buildroot/-/blob/2026.05/CHANGES"><tt>CHANGES</tt></a>
file for the full list.</p>

<p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft feud escalates as researcher drops new Windows zero-day]]></title>
<description><![CDATA[The long-running feud between Microsoft and security researcher Nightmare Eclipse has entered a new chapter.



Eclipse, who has spent the past several months publicly releasing unpatched Windows vulnerabilities while sparring with Microsoft over vulnerability disclosure practices, has published ...]]></description>
<link>https://tsecurity.de/de/3587554/it-security-nachrichten/microsoft-feud-escalates-as-researcher-drops-new-windows-zero-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587554/it-security-nachrichten/microsoft-feud-escalates-as-researcher-drops-new-windows-zero-day/</guid>
<pubDate>Wed, 10 Jun 2026 14:11:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The long-running feud between Microsoft and security researcher Nightmare Eclipse has entered a new chapter.</p>



<p>Eclipse, who has spent the past several months publicly releasing unpatched Windows vulnerabilities while sparring with Microsoft over vulnerability disclosure practices, has published exploit code for a new zero-day flaw dubbed RoguePlanet.</p>



<p>The researcher said their exploit uses a race condition problem affecting Microsoft Defender, giving attackers less than a hundred percent odds at success, which can potentially allow SYSTEM-level privilege on even freshly updated Windows.</p>



<p>As <a href="https://www.csoonline.com/article/4160275/caught-quarantined-re-installed-redsun-turns-microsoft-defender-on-itself.html">before</a>, the exploit arrives just after Microsoft issued its <a href="https://blog.talosintelligence.com/microsoft-patch-tuesday-for-june-2026-snort-rules-and-prominent-vulnerabilities/" target="_blank" rel="noreferrer noopener">June 2026</a> Tuesday patches, where the company issued fixes for over 200 security flaws, including 32 critical ones. “The timing is a giveaway, MiniPlasma was released on May 13, 2026—exactly one day after Microsoft’s May Patch Tuesday cycle, ensuring defenders have no official vendor patch for weeks,” Agnidipta Sarkar, chief evangelist at ColorTokens, had said about Eclipse’s previous “MiniPlasma” <a href="https://www.csoonline.com/article/4172320/patched-windows-bug-resurfaces-6-years-later-as-working-system-level-exploit.html">disclosure</a>.</p>



<p>The exploit was dropped in a new GitHub repository, “MSNightmare,” surely a pointed reference to Microsoft, after GitHub (owned by Microsoft) removed Eclipse’s original repositories recently. Several earlier Eclipse disclosures were reportedly incorporated into <a href="https://www.csoonline.com/article/4175970/microsoft-patches-two-zero-day-flaws-in-defender.html">real-world attacks</a> shortly after exploit code became available, prompting warnings from Microsoft and multiple security vendors.</p>



<h2 class="wp-block-heading">The bug allows code execution through SYSTEM access</h2>



<p>In a June 9 blog <a href="https://deadeclipse666.blogspot.com/2026/06/rogueplanet-quick-history.html" target="_blank" rel="noreferrer noopener">post</a> titled “RoguePlanet, a quick history,” Eclipse wrote of an initial iteration of the Windows Defender bug. While technical details remain scarce, the blog did mention that it has to do with getting a victim to open a “.vhd(x) on a remote SMB server.”</p>



<p>Doing that, the writeup explained, would result in “Defender overwriting its own files and obviously the end outcome was an RCE.” A rough interpretation of the description is that the bug allows executing malicious metadata from a specially crafted virtual hard disk (.vhd) image stored on a remote Server Message Block (SMB) server.</p>



<p>Eclipse’s <a href="https://github.com/MSNightmare/RoguePlanet" target="_blank" rel="noreferrer noopener">PoC</a> exploit ultimately spawns a SYSTEM shell, allowing arbitrary code to be executed by a potential attacker.</p>



<p>A mid-May patch to Defender reportedly sealed the initial attack path detailed by Eclipse, making “junction attacks useless,” which had them re-write RoguePlanet to work around the fix. The current version of the exploit allegedly works against Windows 11 (official channel + Canary) and Windows 10 with the June 2026 patch installed.</p>



<p>The PoC code, however, gave out against Windows Server installations since standard users “Cannot mount an ISO image”. While Eclipse was “too drained” to redesign an exploit for this exception, they are certain an exploit is possible.</p>



<h2 class="wp-block-heading">The feud behind the flaws</h2>



<p>Microsoft recently <a href="https://github.com/Nightmare-Eclipse" target="_blank" rel="noreferrer noopener">removed</a> Eclipse’s GitHub accounts and also disabled their Microsoft Security Response Center (MSRC) access. Following the ban, GitLab also <a href="https://gitlab.com/nightmare-eclipse" target="_blank" rel="noreferrer noopener">suspended</a> the researcher’s secondary mirrors.</p>



<p>In a May 27 blog <a href="https://www.microsoft.com/en-us/msrc/blog/2026/05/a-shared-responsibility-protecting-customers-through-coordinated-vulnerability-disclosure?source=post_page-----0946117940a4---------------------------------------" target="_blank" rel="noreferrer noopener">post</a>, Microsoft criticized the lack of coordinated vulnerability disclosure and threatened legal action, stating that the public disclosures aided attackers and involved a digital crimes unit coordinating with law enforcement.</p>



<p>“The vulnerabilities known as <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091">RedSun</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45498">UnDefend</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33825">BlueHammer</a>, <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585">YellowKey</a>, GreenPlasma, and MiniPlasma were not responsibly disclosed,” the company wrote on Eclipse-disclosed bugs. “Uncoordinated disclosures that put proof-of-concept code for unpatched vulnerabilities into the hands of bad actors are never justifiable and have real-world consequences.”</p>



<p>Cybersecurity analyst Kevin Beamount <a href="https://doublepulsar.com/microsofts-stance-on-zero-day-exploits-is-a-dumpster-fire-of-their-own-making-0946117940a4">called</a> Microsoft’s response a “dumpster fire of their own making.” Writing of a previous researcher going by the name “SandboxEscaper,” who similarly disclosed Microsoft bugs and published exploit codes, Beaumont pointed to Microsoft’s precedent for hiring such researchers in 2019.</p>



<p>“I’m making the point that Microsoft has very publicly hired somebody for doing the same thing Microsoft’s latest blog alleges is criminal behaviour,” Beaumont said.</p>



<p>Microsoft did not immediately respond to CSO’s request for a comment.</p>



<p>Eclipse announced its return on GitHub on June 9. “Yes, it’s GitHub again, Microsoft forgot that even if they banned my GitLab and GitHub accounts, they cannot unwrite my code. Once it’s public, you can’t remove it.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Terminal Tower of Hanoi, in Bash]]></title>
<description><![CDATA[https://gitlab.com/christosangel/hanoi Hanoi is a simple terminal version of the known classical game Tower of Hanoi, written in Bash. During the game, the user can move left and right, pick disks and drop them in other stacks. The aim is to move all the disks from the ORIGIN pile to the DESTINAT...]]></description>
<link>https://tsecurity.de/de/3587417/linux-tipps/terminal-tower-of-hanoi-in-bash/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587417/linux-tipps/terminal-tower-of-hanoi-in-bash/</guid>
<pubDate>Wed, 10 Jun 2026 13:10:50 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><a href="https://gitlab.com/christosangel/hanoi">https://gitlab.com/christosangel/hanoi</a></p> <p><strong>Hanoi</strong> is a simple terminal version of the known classical game <a href="https://en.wikipedia.org/wiki/Tower_of_Hanoi">Tower of Hanoi</a>, written in <strong>Bash</strong>.</p> <p>During the game, the user can move left and right, pick disks and drop them in other stacks.</p> <p>The aim is to move all the disks from the <strong>ORIGIN</strong> pile to the <strong>DESTINATION</strong> pile, in as little moves as possible.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/christos_71"> /u/christos_71 </a> <br> <span><a href="https://i.redd.it/k1x6yu4cqf6h1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1u1yp7z/terminal_tower_of_hanoi_in_bash/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[v3.9.0]]></title>
<description><![CDATA[What's Changed
🎉 New Features

Added support for protocol redirects by @Mzack9999 in #7296
Added impacket integration by @Mzack9999 in #7356
Added wmi, tsch, scmr, and dcom helper modules for JS by @dwisiswant0 in #7388
Added mirroring of -config, -report-config, and -dashboard flags for SDK call...]]></description>
<link>https://tsecurity.de/de/3587300/it-security-tools/v390/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587300/it-security-tools/v390/</guid>
<pubDate>Wed, 10 Jun 2026 12:34:24 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<h3>🎉 New Features</h3>
<ul>
<li>Added support for protocol redirects by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4130433144" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7296" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7296/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7296">#7296</a></li>
<li>Added impacket integration by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295839541" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7356" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7356/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7356">#7356</a></li>
<li>Added wmi, tsch, scmr, and dcom helper modules for JS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416005251" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7388" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7388/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7388">#7388</a></li>
<li>Added mirroring of -config, -report-config, and -dashboard flags for SDK callers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ShubhamRasal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ShubhamRasal">@ShubhamRasal</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4421244220" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7393" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7393/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7393">#7393</a></li>
</ul>
<h3>🐞 Bug Fixes</h3>
<ul>
<li>Fixed DNS variables resolving issue by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379990622" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7379" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7379/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7379">#7379</a></li>
<li>Fixed expressions to prefer exact placeholders over expressions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4424530577" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7397" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7397/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7397">#7397</a></li>
<li>Fixed an issue in JS where runtimes that outlive the interrupt grace period are not abandoned, by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379927978" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7378" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7378/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7378">#7378</a></li>
<li>Fixed an issue in reporting/jira where status-not was not matched against the transition target status name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/knakul853/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/knakul853">@knakul853</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324093179" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7361" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7361/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7361">#7361</a></li>
<li>Fixed runner to write unsigned-templates warning (WRN) to stderr by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ChrisJr404/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ChrisJr404">@ChrisJr404</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372196340" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7371" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7371/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7371">#7371</a></li>
<li>Fixed <code>InternalEvent</code> access serialization in interactsh by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4191610828" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7322" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7322/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7322">#7322</a></li>
<li>Fixed workflow to ensure context is properly propagated to child and race steps by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4401642548" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7383" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7383/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7383">#7383</a></li>
<li>Fixed reporting/gitlab by bumping client-go to v1.9.1 and widening IDs to int64 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ShubhamRasal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ShubhamRasal">@ShubhamRasal</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4428259573" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7398" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7398/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7398">#7398</a></li>
<li>Fixed memogen to skip context correctly and auto-push scope to upstream by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4489253031" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7419" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7419/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7419">#7419</a></li>
<li>Fixed a slice-bounds panic in telnetmini's ParseNTLMResponse when handling truncated NTLM challenges by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tejgokani/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tejgokani">@tejgokani</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515807786" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7425" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7425/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7425">#7425</a></li>
<li>Fixed SMBv1 probing in JS to occur after SMB2 negotiation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4533452973" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7430" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7430/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7430">#7430</a></li>
<li>Fixed templates to reject unknown fields when loading JSON templates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tejgokani/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tejgokani">@tejgokani</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4613949876" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7453" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7453/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7453">#7453</a></li>
<li>Fixed persistence of QueryAuthStrategy parameters in ApplyAuthStrategy by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akhilesharora/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akhilesharora">@akhilesharora</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463287445" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7410" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7410/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7410">#7410</a></li>
<li>Fixed loader to warn when templates are excluded by <code>.nuclei-ignore</code> tags by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4612509981" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7452" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7452/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7452">#7452</a></li>
</ul>
<h3>Other Changes</h3>
<ul>
<li>Splitted exact matches and pattern handling in catalog for improved performance by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mikhail5555/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mikhail5555">@mikhail5555</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4255332284" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7340" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7340/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7340">#7340</a></li>
<li>Updated README_PT-BR.md to reflect current project description and features by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gugacyber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gugacyber">@gugacyber</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456081035" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7405" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7405/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7405">#7405</a></li>
<li>Fixed broken cloud scanning link by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469255793" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7413" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7413/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7413">#7413</a></li>
<li>Bumped pdsec modules + govaluate/aurora migration by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469862647" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7414" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7414/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7414">#7414</a></li>
<li>Dropped vulnerable docker/docker dependency by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4587466787" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7447" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7447/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7447">#7447</a></li>
<li>Used path-aware filesystem containment checks by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4503116067" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7420" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7420/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7420">#7420</a></li>
<li>Centralized runtime session handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4610350261" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7449" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7449/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7449">#7449</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ChrisJr404/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ChrisJr404">@ChrisJr404</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372196340" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7371" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7371/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7371">#7371</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gugacyber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gugacyber">@gugacyber</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456081035" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7405" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7405/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7405">#7405</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akhilesharora/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akhilesharora">@akhilesharora</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463287445" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7410" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7410/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7410">#7410</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tejgokani/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tejgokani">@tejgokani</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515807786" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/7425" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/7425/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/7425">#7425</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/projectdiscovery/nuclei/compare/v3.8.0...v3.9.0"><tt>v3.8.0...v3.9.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The first release of ReterminateVT is out! (along with a demo ISO)]]></title>
<description><![CDATA[Hi  I have decided to tag a release of ReterminateVT, which used to be called fakekmscon, until I renamed it when kmscon became active again. fakekmscon has been around since 2020, with kmscon actually being brought back, I have renamed it to ReterminateVT.  I don't know the best mailing list to ...]]></description>
<link>https://tsecurity.de/de/3583417/linux-tipps/the-first-release-of-reterminatevt-is-out-along-with-a-demo-iso/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583417/linux-tipps/the-first-release-of-reterminatevt-is-out-along-with-a-demo-iso/</guid>
<pubDate>Tue, 09 Jun 2026 05:24:38 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi </p> <p>I have decided to tag a release of <a href="https://gitlab.freedesktop.org/n3rdopolis/reterminatevt/-/tags/1.2026.06.02">ReterminateVT</a>, which used to be called fakekmscon, until I renamed it when kmscon became active again. fakekmscon has been around since 2020, with kmscon actually being brought back, I have renamed it to ReterminateVT. </p> <p>I don't know the best mailing list to announce this in, I am not sure which one is most relevant. </p> <p>While kmscon is starting to get integrated into Fedora, ReterminateVT is similar but different, kmscon maintains its own terminal emulator, and maintains how it handles modesetting, but ReterminateVT uses foot, and the wlroots based cage to do so. Also, Fedora as of now has not disabled VTs in the kernel, but uses kmscon to replace the VT console on text mode TTYs. ReterminateVT used to do this too, but with vtty-seatmanager, is probably in a better position for true VT-less kernels as of now. </p> <p>ReterminateVTs consoles (when not running in recovery mode) do not run as root, (although kmscon <em>is</em> working on that too) and ReterminateVT also has more integration with using the Fenrir screen reader for accessibility, As ReterminateVT is client server, (through socat) it allows the getty to not run as root, under the underprivileged terminal emulator and display server, it ALSO allows resiliency from possible crashes of Cage or Foot from stopping the user's shell or subprocesses. </p> <p>I also have a <a href="https://github.com/n3rdopolis/vtless/releases/download/2026-05-31/VTless_amd64.iso">demo ISO</a> with ReterminateVT installed. It is just over 400MB, and has no Desktops, other than a pixman-only Weston. (to demonstrate <code>vtty-launch weston</code>). This is meant to show how I see desktop VT-less distros working </p> <p>The user is "vtless", (the same as the hostname), and has no password </p> <p>The buildscripts have only one commit, but this is because I took the buildscripts from my <a href="https://sourceforge.net/p/rebeccablackos/code/HEAD/tree/">other distro</a> ripped out the desktops, and some other features, and instead of waylandloginmanager, it starts to vtty-seatmanager as the display-manger.service. meaning despite the scripts being long but new, they were not vibe-coded or anything overnight</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/n3rdopolis"> /u/n3rdopolis </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1u0tjey/the_first_release_of_reterminatevt_is_out_along/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1u0tjey/the_first_release_of_reterminatevt_is_out_along/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tim @BorgNetzWerk: Gemeinsam Wissens-Infrastruktur bauen: föderierte Wikibase für Video- und Podcast]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 0x - Views:10 https://media.ccc.de/v/gpn24-666-gemeinsam-wissens-infrastruktur-bauen-foderierte-wikibase-fur-video-und-podcasts

Das WissKomm Wiki hat Förderung, einen laufenden Prototypen und 100.000+ identifizierte Videos. Dieser Talk zeigt, was schon läuft: fö...]]></description>
<link>https://tsecurity.de/de/3579361/it-security-video/tim-borgnetzwerk-gemeinsam-wissens-infrastruktur-bauen-foederierte-wikibase-fuer-video-und-podcast/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579361/it-security-video/tim-borgnetzwerk-gemeinsam-wissens-infrastruktur-bauen-foederierte-wikibase-fuer-video-und-podcast/</guid>
<pubDate>Sun, 07 Jun 2026 14:32:48 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 0x - Views:10 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/OR8_cD-p4ek?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://media.ccc.de/v/gpn24-666-gemeinsam-wissens-infrastruktur-bauen-foderierte-wikibase-fur-video-und-podcasts<br />
<br />
Das WissKomm Wiki hat Förderung, einen laufenden Prototypen und 100.000+ identifizierte Videos. Dieser Talk zeigt, was schon läuft: föderierte Wikibase, automatische Transkription per Whisper, SPARQL-Queries über Wissenschaftsmedien. <br />
Mit Arrrrrmin haben wir LanzMining von der GPN23 zu SpeakerMining aufgebaut und ins WissKomm Wiki integriert - eine vollständige Pipeline, die aus ZDF-Archiv-PDFs einen verlinkten Wissensgraph erzeugt: 10.000+ Personenerwähnungen, 120.000+ Wikidata-Triples, OpenRefine-Kuration. Genau das skalieren wir im WissKomm Wiki auf Wissenschaftsvideos und -podcasts. Plus die offenen Probleme, an denen wir gemeinsam arbeiten möchten, am besten gleich im GPN24 Hackathon.<br />
<br />
2021: Idee<br />
GPN22: Präsentation im CCC.<br />
GPN23: Prototyp, Antrag in der Schwebe, Arrrrrmin stellt LanzMining vor.<br />
GPN24: Das Projekt läuft: Gefördert durch FDM-NDS dürfen wir jetzt zeigen, wie LanzMining, WissKomm Wiki und viele ähnliche Projekte zusammenpassen.<br />
<br />
Ein Einblick: [GPN23, media.ccc.de](https://media.ccc.de/v/gpn23-299-ctrl-f-for-facts-mit-dem-wisskomm-wiki-filterblasen-erkennen-und-fakten-sichtbar-machen). <br />
Im Talk gehen wir endlich über Konzepte hinaus in die Anwendung!<br />
<br />
<br />
Auf der GPN23 hat Arrrrrmin mit LanzMining gezeigt, was möglich ist, wenn man TV-Archivdaten strukturiert erschließt. Wir haben das weitergebaut zur vollständigen Pipeline Speaker Mining. Ausgangspunkt: ZDF-Archiv-PDFs des Markus-Lanz-Talks. <br />
Semantisch disambiguiert mit OpenRefine, dedupliziert auf Wikibase bereitgestellt und letztlich nachhaltig frei verfügbar.<br />
Wer mag, kann live über SPARQL-Queries Fragen stellen: - wer war wie oft zu Gast? Mit welcher Rollenverteilung? <br />
Wir gehen noch tiefer in die Analyse: Visualisierung der Rollenverteilung, wie von LanzMining bereits vorgemacht: Indem wir Klassen wie Rollen und Instanzen wie Markus Lanz statistisch unter die Lupe nehmen, können wir mit Speaker Mining bildlich machen, was unsere Medienlandschaft ausmacht.<br />
<br />
<br />
Die aktuelle WissKomm-Wiki-Infrastruktur besteht aus einer föderierten Wikibase via Wikibase.cloud (wie ein eigenes Wikidata), langfristig verknüpft mit einem Full Text Wiki für Transkripte. Via SPARQL kann nach Properties und Datenquellen gefiltert werden. <br />
<br />
Speaker Mining zeigt, wohin das führt: Wenn Sendungsarchiv-Metadaten maschinenlesbar in einer Wikibase liegen, kann man fragen: Wer war wann zu Gast, mit welcher Rolle, aus welcher Institution?<br />
<br />
Whisper läuft noch lokal, transkribiert offline, und die Ergebnisse landen vorerst nicht im Wiki - bis wir im Projekt die Rechtsfragen geklärt haben. Ziel dafür: Ende Juni steht der Fragenkatalog, und im September haben wir unser Rechtsgutachten.<br />
Experimentell haben wir so schon mal 230+ Folgen Lanz & Precht transkribiert und analysiert - die ersten Ergebnisse sind ganz spannend. Der Blick auf die beiden *sozusagen*-Experten ist nur ein erster Einblick in das, was langfristig möglich sein soll. Der nächste Schritt geht gen Wissenschafts-Podcasts, wie dem jüngst mit dem ÖFG-Preis für Wissenschaftsjournalismus ausgezeichneten Podcast [Das Klima](https://dasklima.podigee.io/) von u.a. FuzzyLeapfrog, die von Beginn an bei Speaker Mining mitgewirkt hat.<br />
<br />
<br />
Jetzt geht es darum, die Community aufzubauen: Der [Matrix-Channel](https://matrix.to/#/#wisskomm.wiki:matrix.org) ist aufgesetzt, das Community-Team steht bereit und arbeitet fleißig mit unserem gemeinnützigen Verein daran, die gewachsenen Strukturen der vergangenen fünf Jahre auf bleibende Strukturen zu stellen. Das Open Science Lab aus Hannover übernimmt die fundamentale Infrastruktur, und der Verein übernimmt experimentellere Interfaces wie Gamification oder Plugins.<br />
<br />
* Föderierte Wiki-Architektur: Wikibase + Full Text Wiki, verbunden über interne Queries<br />
* Module für Datenakquise, Zwischenspeicherung, Transkription (Whisper ASR, lokal)<br />
* Interfaces: nicht nur für Forschende und Entwickler\*innen, sondern auch für Urheber\*innen und Plattformbetreibende<br />
* Federation mit Wikidata, ORKG, TIB AV-Portal - ohne deren Infrastruktur zu überlasten<br />
<br />
Wer mitmachen will: Wir vom WissKomm Wiki sind auf der GPN, sprecht uns an :) Zum Talk gibts hoffentlich noch den Workshop. <br />
<br />
**Links**<br />
<br />
* [GPN23: CTRL+F for Facts (WissKomm Wiki)](https://media.ccc.de/v/gpn23-299-ctrl-f-for-facts-mit-dem-wisskomm-wiki-filterblasen-erkennen-und-fakten-sichtbar-machen)<br />
* [GPN23: LanzMining (Arrrrrmin)]([https://media.ccc.de/v/gpn23](https://media.ccc.de/v/gpn23-213-lanzmining-wer-spricht-denn-da-))<br />
* [Projekt](https://borgnetzwerk.org/wisskomm-wiki)<br />
* SciCom Wiki: [Code](https://gitlab.com/wisskomm-wiki), [Paper](https://arxiv.org/abs/2511.09248),<br />
* Speaker Mining: [Code](https://github.com/borgnetzwerk/speaker-mining), [Paper](<br />
https://doi.org/10.48550/arXiv.2606.02905))<br />
<br />
Tim @BorgNetzWerk<br />
<br />
https://cfp.gulas.ch/gpn24/talk/G9VCNN/<br />
<br />
#gpn24 #Science<br />
<br />
Licensed to the public under https://creativecommons.org/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gemeinsam Wissens-Infrastruktur bauen: föderierte Wikibase für Video- und Podcasts (gpn24)]]></title>
<description><![CDATA[Das WissKomm Wiki hat Förderung, einen laufenden Prototypen und 100.000+ identifizierte Videos. Dieser Talk zeigt, was schon läuft: föderierte Wikibase, automatische Transkription per Whisper, SPARQL-Queries über Wissenschaftsmedien. 
Mit Arrrrrmin haben wir LanzMining von der GPN23 zu SpeakerMin...]]></description>
<link>https://tsecurity.de/de/3579347/it-security-video/gemeinsam-wissens-infrastruktur-bauen-foederierte-wikibase-fuer-video-und-podcasts-gpn24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579347/it-security-video/gemeinsam-wissens-infrastruktur-bauen-foederierte-wikibase-fuer-video-und-podcasts-gpn24/</guid>
<pubDate>Sun, 07 Jun 2026 14:18:20 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das WissKomm Wiki hat Förderung, einen laufenden Prototypen und 100.000+ identifizierte Videos. Dieser Talk zeigt, was schon läuft: föderierte Wikibase, automatische Transkription per Whisper, SPARQL-Queries über Wissenschaftsmedien. 
Mit Arrrrrmin haben wir LanzMining von der GPN23 zu SpeakerMining aufgebaut und ins WissKomm Wiki integriert - eine vollständige Pipeline, die aus ZDF-Archiv-PDFs einen verlinkten Wissensgraph erzeugt: 10.000+ Personenerwähnungen, 120.000+ Wikidata-Triples, OpenRefine-Kuration. Genau das skalieren wir im WissKomm Wiki auf Wissenschaftsvideos und -podcasts. Plus die offenen Probleme, an denen wir gemeinsam arbeiten möchten, am besten gleich im GPN24 Hackathon.

2021: Idee
GPN22: Präsentation im CCC.
GPN23: Prototyp, Antrag in der Schwebe, Arrrrrmin stellt LanzMining vor.
GPN24: Das Projekt läuft: Gefördert durch FDM-NDS dürfen wir jetzt zeigen, wie LanzMining, WissKomm Wiki und viele ähnliche Projekte zusammenpassen.

Ein Einblick: [GPN23, media.ccc.de](https://media.ccc.de/v/gpn23-299-ctrl-f-for-facts-mit-dem-wisskomm-wiki-filterblasen-erkennen-und-fakten-sichtbar-machen). 
Im Talk gehen wir endlich über Konzepte hinaus in die Anwendung!


Auf der GPN23 hat Arrrrrmin mit LanzMining gezeigt, was möglich ist, wenn man TV-Archivdaten strukturiert erschließt. Wir haben das weitergebaut zur vollständigen Pipeline Speaker Mining. Ausgangspunkt: ZDF-Archiv-PDFs des Markus-Lanz-Talks. 
Semantisch disambiguiert mit OpenRefine, dedupliziert auf Wikibase bereitgestellt und letztlich nachhaltig frei verfügbar.
Wer mag, kann live über SPARQL-Queries Fragen stellen: - wer war wie oft zu Gast? Mit welcher Rollenverteilung? 
Wir gehen noch tiefer in die Analyse: Visualisierung der Rollenverteilung, wie von LanzMining bereits vorgemacht: Indem wir Klassen wie Rollen und Instanzen wie Markus Lanz statistisch unter die Lupe nehmen, können wir mit Speaker Mining bildlich machen, was unsere Medienlandschaft ausmacht.


Die aktuelle WissKomm-Wiki-Infrastruktur besteht aus einer föderierten Wikibase via Wikibase.cloud (wie ein eigenes Wikidata), langfristig verknüpft mit einem Full Text Wiki für Transkripte. Via SPARQL kann nach Properties und Datenquellen gefiltert werden. 

Speaker Mining zeigt, wohin das führt: Wenn Sendungsarchiv-Metadaten maschinenlesbar in einer Wikibase liegen, kann man fragen: Wer war wann zu Gast, mit welcher Rolle, aus welcher Institution?

Whisper läuft noch lokal, transkribiert offline, und die Ergebnisse landen vorerst nicht im Wiki - bis wir im Projekt die Rechtsfragen geklärt haben. Ziel dafür: Ende Juni steht der Fragenkatalog, und im September haben wir unser Rechtsgutachten.
Experimentell haben wir so schon mal 230+ Folgen Lanz &amp; Precht transkribiert und analysiert - die ersten Ergebnisse sind ganz spannend. Der Blick auf die beiden *sozusagen*-Experten ist nur ein erster Einblick in das, was langfristig möglich sein soll. Der nächste Schritt geht gen Wissenschafts-Podcasts, wie dem jüngst mit dem ÖFG-Preis für Wissenschaftsjournalismus ausgezeichneten Podcast [Das Klima](https://dasklima.podigee.io/) von u.a. FuzzyLeapfrog, die von Beginn an bei Speaker Mining mitgewirkt hat.


Jetzt geht es darum, die Community aufzubauen: Der [Matrix-Channel](https://matrix.to/#/#wisskomm.wiki:matrix.org) ist aufgesetzt, das Community-Team steht bereit und arbeitet fleißig mit unserem gemeinnützigen Verein daran, die gewachsenen Strukturen der vergangenen fünf Jahre auf bleibende Strukturen zu stellen. Das Open Science Lab aus Hannover übernimmt die fundamentale Infrastruktur, und der Verein übernimmt experimentellere Interfaces wie Gamification oder Plugins.

* Föderierte Wiki-Architektur: Wikibase + Full Text Wiki, verbunden über interne Queries
* Module für Datenakquise, Zwischenspeicherung, Transkription (Whisper ASR, lokal)
* Interfaces: nicht nur für Forschende und Entwickler\*innen, sondern auch für Urheber\*innen und Plattformbetreibende
* Federation mit Wikidata, ORKG, TIB AV-Portal - ohne deren Infrastruktur zu überlasten

Wer mitmachen will: Wir vom WissKomm Wiki sind auf der GPN, sprecht uns an :) Zum Talk gibts hoffentlich noch den Workshop. 

**Links**

* [GPN23: CTRL+F for Facts (WissKomm Wiki)](https://media.ccc.de/v/gpn23-299-ctrl-f-for-facts-mit-dem-wisskomm-wiki-filterblasen-erkennen-und-fakten-sichtbar-machen)
* [GPN23: LanzMining (Arrrrrmin)]([https://media.ccc.de/v/gpn23](https://media.ccc.de/v/gpn23-213-lanzmining-wer-spricht-denn-da-))
* [Projekt](https://borgnetzwerk.org/wisskomm-wiki)
* SciCom Wiki: [Code](https://gitlab.com/wisskomm-wiki), [Paper](https://arxiv.org/abs/2511.09248),
* Speaker Mining: [Code](https://github.com/borgnetzwerk/speaker-mining), [Paper](
https://doi.org/10.48550/arXiv.2606.02905))

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://cfp.gulas.ch/gpn24/talk/G9VCNN/]]></content:encoded>
</item>
<item>
<title><![CDATA[Von Markdown zu PDF auf die harte Weise (noname_ev)]]></title>
<description><![CDATA[Ich mag Markdown zum Schreiben von Notizen oder längeren Texten, aber leider gefällt manchen Menschen das Anstarren von Textdateien nicht. In der Vergangenheit habe ich darum mit pandoc und latex meine Markdown Dokumente in PDFs verwandelt.

Kürzlich habe ich beschlossen, dass ich typst viel lieb...]]></description>
<link>https://tsecurity.de/de/3577795/it-security-video/von-markdown-zu-pdf-auf-die-harte-weise-nonameev/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577795/it-security-video/von-markdown-zu-pdf-auf-die-harte-weise-nonameev/</guid>
<pubDate>Sat, 06 Jun 2026 15:32:45 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Ich mag Markdown zum Schreiben von Notizen oder längeren Texten, aber leider gefällt manchen Menschen das Anstarren von Textdateien nicht. In der Vergangenheit habe ich darum mit pandoc und latex meine Markdown Dokumente in PDFs verwandelt.<br>
<br>
Kürzlich habe ich beschlossen, dass ich typst viel lieber mag als latex. Drum zeige ich euch heute, wie ich mittlerweile Dokumente von Markdown über pandoc und typst zu PDFs konvertiere.<br>
<br>
Spoiler: Es ist ein bisschen bash-Code involviert.<br></p>
<p>
Aufgrund eines Fehlers bei der Aufnahme und Durchführung ist der Bildschirminhalt samt Präsentation leider nicht sichtbar.
</p>

<p>
Links und Quellen:
</p><ul>
  <li><a href="https://www.noname-ev.de/chaotische_viertelstunde.html#c14h_670">Vortrag auf der Vereinsseite</a></li>
  <li><a href="https://gitlab.com/hartang/typst/md2pdf">Projekt 'md2pdf'</a></li>
  <li><a href="https://gitlab.com/hartang/c14h/2026-01-08_von-markdown-zu-pdf-auf-die-harte-weise">Repo &amp; Folien</a></li>
</ul>

about this event: https://www.noname-ev.de/chaotische_viertelstunde.html#c14h_670]]></content:encoded>
</item>
<item>
<title><![CDATA[Weekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer Enum]]></title>
<description><![CDATA[When Open Source is a bit too OpenSeveral fun modules landed this week, including an Apache RCE, Windows Kernel pointer collection, and Gogs RCE via naming. Leading off is Gogs' RCE that allows an attacker to execute commands by naming their branch --exec  and requesting a rebase.Another useful p...]]></description>
<link>https://tsecurity.de/de/3576745/it-security-nachrichten/weekly-metasploit-update-apache-activemq-rce-gogs-rebase-rce-and-windows-kernel-pointer-enum/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576745/it-security-nachrichten/weekly-metasploit-update-apache-activemq-rce-gogs-rebase-rce-and-windows-kernel-pointer-enum/</guid>
<pubDate>Sat, 06 Jun 2026 01:22:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>When Open Source is a bit too Open</h2><p>Several fun modules landed this week, including an Apache RCE, Windows Kernel pointer collection, and Gogs RCE via naming. Leading off is Gogs' RCE that allows an attacker to execute commands by naming their <span data-type="inlineCode">branch </span><span data-type="inlineCode">--exec &lt;command&gt;</span> and requesting a rebase.</p><p>Another useful post module by CharlesQuinnDev enumerates the Kernel pointers leaked via the popular <span data-type="inlineCode">NtQuerySystemInformation</span> technique. Those exposed pointers, combined with a good write primitive, make local privilege escalation easier to accomplish. Several local privilege escalations already use that technique, so exposing just that technique was a great call!</p><h2>New module content (3)</h2><h3>Apache ActiveMQ RCE via Jolokia addNetworkConnector</h3><p><strong>Authors:</strong> dinosn and h00die<br><strong>Type:</strong> Exploit<br><strong>Pull request:</strong> <a href="https://github.com/rapid7/metasploit-framework/pull/21497">#21497</a> contributed by <a href="https://github.com/h00die">h00die</a><br><strong>Path:</strong> <span data-type="inlineCode">multi/http/apache_activemq_jolokia_rce</span><br><strong>AttackerKB reference:</strong> <a href="https://attackerkb.com/search?q=CVE-2026-34197&amp;referrer=blog">CVE-2026-34197</a></p><p>Adds a new exploit module exploit/multi/http/apache_activemq_jolokia_rce targeting CVE-2026-34197 in Apache ActiveMQ. The module abuses the Jolokia JMX-over-HTTP API exposed at <span data-type="inlineCode">/api/jolokia/</span> by calling the <span data-type="inlineCode">addNetworkConnector()</span> MBean operation with a crafted <span data-type="inlineCode">brokerConfig=xbean:http://...</span><span data-type="inlineCode"> </span>URI. ActiveMQ fetches the attacker-controlled URL and instantiates it as a Spring XML application context, achieving remote code execution via a <span data-type="inlineCode">java.lang.ProcessBuilder</span> bean. Authentication is required to exploit this vulnerability.</p><h3>Gogs Git Rebase Argument Injection RCE</h3><p><strong>Author:</strong> Crypto-Cat<br><strong>Type:</strong> Exploit<br><strong>Pull request:</strong> <a href="https://github.com/rapid7/metasploit-framework/pull/21515">#21515</a> contributed by <a href="https://github.com/jburgess-r7">jburgess-r7</a><br><strong>Path:</strong> <span data-type="inlineCode">multi/http/gogs_rebase_rce</span></p><p>This adds an exploit module for the Gogs rebase Remote Code Execution (RCE) vulnerability. The module leverages an argument injection flaw residing in the pull request merge workflow of Gogs versions &lt;= 0.14.2 and &lt;= 0.15.0+dev.</p><h3>Windows Kernel Pointer Exposure Enumerator</h3><p><strong>Author:</strong> CharlesQuinnDev<br><strong>Type:</strong> Post<br><strong>Pull request:</strong> <a href="https://github.com/rapid7/metasploit-framework/pull/21039">#21039</a> contributed by <a href="https://github.com/CharlesQuinnDev">CharlesQuinnDev</a><br><strong>Path:</strong> <span data-type="inlineCode">windows/gather/windows_kernel_pointer_enum</span></p><p>Adds a new post module for Windows that enumerates kernel object pointers exposed through <span data-type="inlineCode">NtQuerySystemInformation</span> on <span data-type="inlineCode">x64</span> systems. The module collects observable handle metadata and provides analysis of pointer distribution, object types, and ALPC usage, then saves the results to a CSV loot file for review. Also introduces a reusable Windows kernel handle-enumeration library.</p><h2>Enhancements and features (7)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/20881">#20881</a> from <a href="https://github.com/h00die">h00die</a> - This adds support for cracking Kerberos type hashes in Metasploit, specifically timeroasting, krb5tgs* and krb5asrep.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21087">#21087</a> from <a href="https://github.com/jbx81-1337">jbx81-1337</a> - The new payloads_manager plugin lets you maintain a local archive of custom payloads and stage them into the data directory. Use the <span data-type="inlineCode">fetch</span> or <span data-type="inlineCode">add</span> subcommands to download or import a payload, then select to symlink it into place so it's available to other modules. The plugin tracks each payload's name, hash, tags, and description in a database.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21412">#21412</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Updates Metasploit's post modules to now run by default against the last opened alive session, unless explicitly specified.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21429">#21429</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Removes the now redundant Linux-specific method for finding the arch so there's a single source of truth that works in a superset of platform / session-type combinations.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21488">#21488</a> from <a href="https://github.com/sjanusz-r7">sjanusz-r7</a> - Updates HTTP login scanners to report the detected service hierarchy.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21504">#21504</a> from <a href="https://github.com/h00die">h00die</a> - Adds missing CVE references to seven existing modules: gladinet_storage_access_ticket_forge (CVE-2025-14611), cassandra_web_file_read (CVE-2020-36939), pretalx_file_read_cve_2023_28459 (CVE-2023-28459 and CVE-2023-28458), centreon_pollers_auth_rce (CVE-2019-19699), wp_responsive_thumbnail_slider_upload (CVE-2015-10144), xerte_unauthenticated_template_import_rce (CVE-2026-32985), and solarwinds_storage_manager_sql (CVE-2012-2576).</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21526">#21526</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Makes stability and logging improvements to the ipmi_cipher_zero, ipmi_dumphashes, and ipmi_version modules.</li></ul><h2>Bugs fixed (7)</h2><ul><li><a href="https://github.com/rapid7/metasploit-framework/pull/21432">#21432</a> from <a href="https://github.com/4ravind-b">4ravind-b</a> - Fixes a bug in modules that invoke other modules that prevented datastore options from being validated.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21448">#21448</a> from <a href="https://github.com/kx7m2qd">kx7m2qd</a> - Fixes an issue where CIDR range filters in the addresses parameter of the db.hosts RPC endpoint were not processed correctly.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21484">#21484</a> from <a href="https://github.com/zeroSteiner">zeroSteiner</a> - Fixes python ssl command shell payloads that failed with AttributeError: module 'ssl' has no attribute 'wrap_socket'.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21489">#21489</a> from <a href="https://github.com/h00die">h00die</a> - Improves the GitLab version scanner by handling additional exceptions in the scanner for non-GitLab targets and adding additional version fingerprints for real GitLab targets.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21502">#21502</a> from <a href="https://github.com/h00die">h00die</a> - Fixes a crash in the scanner/snmp/snmp_enum module when the system date was read as Null.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21506">#21506</a> from <a href="https://github.com/h00die">h00die</a> - Adds a guard clause when running <span data-type="inlineCode">uname -r</span> in WSL startup_folder persistence.</li><li><a href="https://github.com/rapid7/metasploit-framework/pull/21514">#21514</a> from <a href="https://github.com/orbit-bot">orbit-bot</a> - Fixes a couple of references to outdated msfvenom options.</li></ul><h2>Documentation</h2><p>You can find the latest Metasploit documentation on our docsite at <a href="https://docs.metasploit.com/">docs.metasploit.com</a>.</p><h2>Get it</h2><p>As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:</p><ul><li><a href="https://github.com/rapid7/metasploit-framework/pulls?q=is:pr+merged:%222026-05-26T12%3A02%3A08Z..2026-06-04T12%3A43%3A08Z%22">Pull Requests 6.4.135...6.4.136</a></li><li><a href="https://github.com/rapid7/metasploit-framework/compare/6.4.135...6.4.136">Full diff 6.4.135...6.4.136</a></li></ul><p>If you are a git user, you can clone the <a href="https://github.com/rapid7/metasploit-framework">Metasploit Framework repo</a> (master branch) for the latest. To install fresh without using git, you can use the open-source-only <a href="https://github.com/rapid7/metasploit-framework/wiki/Nightly-Installers">Nightly Installers</a> or the commercial edition <a href="https://www.rapid7.com/products/metasploit/download/">Metasploit Pro</a>.</p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[10 MCP-Server für DevOps]]></title>
<description><![CDATA[DevOps ist mit Aufwand und Kosten verbunden. Mit MCP aufzurüsten, macht deshalb Sinn.PeopleImages | shutterstock.com



KI-Agenten für Programmierer haben sich zu einem beeindruckenden Hilfsmittel entwickelt. Allerdings sind diese Agenten nur begrenzt einsetzbar, wenn sie nicht auch mit modernen ...]]></description>
<link>https://tsecurity.de/de/3571393/it-security-nachrichten/10-mcp-server-fuer-devops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571393/it-security-nachrichten/10-mcp-server-fuer-devops/</guid>
<pubDate>Thu, 04 Jun 2026 06:06:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/12/PeopleImages_shutterstock_2546315777_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Dev Discussion 16z9" class="wp-image-4103991" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">DevOps ist mit Aufwand und Kosten verbunden. Mit MCP aufzurüsten, macht deshalb Sinn.</figcaption></figure><p class="imageCredit">PeopleImages | shutterstock.com</p></div>



<p><a href="https://www.computerwoche.de/article/4039804/schone-neue-multi-agenten-welt.html" target="_blank">KI-Agenten für Programmierer</a> haben sich zu einem beeindruckenden Hilfsmittel entwickelt. Allerdings sind diese Agenten nur begrenzt einsetzbar, wenn sie nicht auch mit modernen DevOps-Tools kompatibel sind. An dieser Stelle kommt das Model Context Protocol (<a href="https://www.computerwoche.de/article/4031227/was-ist-model-context-protocol.html">MCP</a>) ins Spiel. Der von Anthropic Ende 2024 veröffentlichte Standard verbindet KI-Systeme mit externen Tools und Daten. </p>



<p>Mit Blick auf <a href="https://www.computerwoche.de/article/2834426/10-grobe-devops-schnitzer.html" target="_blank">DevOps</a> stehen KI-Agenten damit neue Fähigkeiten offen – etwa:</p>



<ul class="wp-block-list">
<li><a href="https://www.computerwoche.de/article/2833711/version-control-systems-ein-ratgeber.html" target="_blank">Versionskontrollen</a> mit Git,</li>



<li>Continuous Integration &amp; Deployment (<a href="https://www.computerwoche.de/article/2834524/6-massnahmen-fuer-bessere-ci-cd-pipelines.html">CI/</a><a href="https://www.computerwoche.de/article/2834524/6-massnahmen-fuer-bessere-ci-cd-pipelines.html" target="_blank">CD</a>),</li>



<li>Infrastructure as Code (<a href="https://www.computerwoche.de/article/2808916/was-ist-infrastructure-as-code.html" target="_blank">IaC</a>),</li>



<li><a href="https://www.computerwoche.de/article/2820175/4-best-practices-fuer-devops-observability.html" target="_blank">Observability</a>, oder</li>



<li>Zugriff auf <a href="https://www.computerwoche.de/article/4077044/technische-dokumentation-mit-genai-so-gehts.html" target="_blank">Dokumentationen</a>.</li>
</ul>



<p>Im Folgenden werfen wir einen Blick auf zehn offizielle MCP-Server, die populären DevOps-Tools und -Plattformen entsprungen sind und jeweils unterschiedliche Funktionalitäten abdecken. Diese lassen sich innerhalb MCP-kompatibler KI-Entwicklungs-Tools relativ einfach konfigurieren und mit Berechtigungen ausstatten. Offizielle MCP-Server zu nutzen, hat zudem den Vorteil, dass deren Lebensdauer sehr wahrscheinlich länger ist – und sie durchgängig gewartet und aktualisiert werden.</p>



<h2 class="wp-block-heading">1. GitHub MCP-Server</h2>



<p>Kaum ein Entwickler nutzt <a href="https://www.computerwoche.de/article/2824356/26-softwareperlen-fuer-windows-pcs.html" target="_blank">GitHub</a> nicht in irgendeiner Form. Deshalb entwickelt sich der <a href="https://github.com/github/github-mcp-server" target="_blank" rel="noreferrer noopener">offizielle MCP-Server</a> der Plattform zu einer immer beliebteren Methode, um KI-Agenten zu befähigen, mit Code-Repositories zu interagieren – etwa, indem sie Issues erstellen und kommentieren oder Pull Requests zusammenführen.</p>



<p>Außerdem enthält dieser MCP-Server auch Endpunkte für das CI/CD-Management über <a href="https://www.infoworld.com/article/2338562/what-is-github-actions-automated-cicd-for-github.html" target="_blank">GitHub Actions</a>. So könnte etwa ein natürlichsprachlicher Befehl wie “Aktuelle Aktion abbrechen” das <code>cancel_workflow_run</code>-Tool innerhalb von GitHub Actions aufrufen.</p>



<p>Der offizielle MCP-Server von GitHub bietet vergleichsweise umfangreiche Funktionen, die die <a href="https://docs.github.com/en/rest" target="_blank" rel="noreferrer noopener">APIs der Plattform</a> widerspiegeln.  Damit dabei die Sicherheit nicht zu kurz kommt und KI-Agenten keine Mutationen durchführen, lassen sich jederzeit <code>--read-only</code>-Flags konfigurieren.</p>



<h2 class="wp-block-heading">2. Notion MCP-Server</h2>



<p>Notion ist eher ein KI-Collaboration- als ein DevOps-Tool und hat sich mittlerweile fachbereichsübergreifend etabliert, wenn es darum geht, teamintern Transparenz zu schaffen. Der <a href="https://github.com/makenotion/notion-mcp-server" target="_blank" rel="noreferrer noopener">offizielle MCP-Server von Notion</a> ist jedoch auch aus DevOps-Perspektive nützlich. Damit lassen sich Agenten beispielsweise anweisen, interne Stilrichtlinien oder Betriebshandbücher zu konsultieren, die in Notion gespeichert sind.</p>



<p>Der Remote-MCP-Server von Notion ist über eine IDE abrufbar – kann aber mit dem <a href="https://hub.docker.com/r/mcp/notion" target="_blank" rel="noreferrer noopener">offiziellen Docker-Image</a> auch lokal aufgesetzt und ausgeführt werden. Dieser MCP-Server ist als risikoarm zu betrachten, da er über konfigurierbare Scopes und Tokens verfügt, um Notion-Seiten und -Blöcke zu managen.</p>



<h2 class="wp-block-heading">3. Atlassian Remote MCP-Server</h2>



<p>Atlassians <a href="https://support.atlassian.com/atlassian-rovo-mcp-server/docs/getting-started-with-the-atlassian-remote-mcp-server/" target="_blank" rel="noreferrer noopener">Remote MCP-Server</a> verbindet IDEs oder Agentic-AI-Plattformen mit den Cloud-Produkten des Unternehmens. Beispielsweise dem Projektmanagement-Tool Jira. Anzumerken ist dabei, dass sich dieser MCP-Server derzeit in der Beta-Phase befindet und Atlassian-Cloud-Kunden vorbehalten ist.</p>



<p>Damit ist es denkbar, einen Agenten anzuweisen, ein Jira-Issue zum Benutzertesting für eine BezahlApp auf der Grundlage eines aktuellen Bug Report zu aktualisieren – und dabei auf die relevanten Protokolle zu verweisen. Die Aktualisierung von Jira läuft anschließend über den MCP-Server.  </p>



<p>Der MCP-Server von Atlassian unterstützt diverse Clients und gewährleistet mit Oauth-2.1-Support auch sicheren Zugriff.</p>



<h2 class="wp-block-heading">4. Argo CD MCP-Server</h2>



<p>Auch die Entwickler des populären Open-Source-Tools Argo CD stellen einen <a href="https://github.com/argoproj-labs/mcp-for-argocd" target="_blank" rel="noreferrer noopener">MCP-Server</a> zur Verfügung. Dieser fasst Calls an die Argo-CD-API zusammen und enthält Tools, mit denen die Benutzer über natürliche Sprache mit Argo CD interagieren können:</p>



<ul class="wp-block-list">
<li>Mit dem <strong>Application-Management-Tool</strong> können KI-Agenten Anwendungsinformationen abrufen, Anwendungen erstellen und löschen sowie weitere Prozesse ausführen.</li>



<li>Über das <strong>Resource-Management-Tool</strong> rufen KI-Agenten Ressourceninformationen, Protokolle und Ereignisse für bestimmte Anwendungen ab und führen spezifische Aktionen für bestimmte Ressourcen aus.</li>
</ul>



<p>Mit Hilfe dieses MCP-Servers lassen sich viele Tasks “natürlichsprachlich” ausführen, die auch über das User Interface oder das CLI-Tool von Argo CD verfügbar sind. Eine Staging-App zu synchronisieren, geht so beispielsweise flotter von der Hand. Damit das auch funktioniert, muss der MCP-Server von Argo CD aber auch ordentlich integriert werden – und benötigt Zugriff auf eine laufende Argo-CD-Instanz inklusive korrekt konfigurierter Anmeldedaten.</p>



<h2 class="wp-block-heading">5. Grafana MCP-Server</h2>



<p>Das Datenvisualisierungs- und Monitoring-Tool Grafana gehört für viele DevOps- und SRE-Teams zum Standardrepertoire. Der offizielle <a href="https://github.com/grafana/mcp-grafana" target="_blank" rel="noreferrer noopener">MCP-Server für Grafana</a> befähigt KI-Agenten dazu, Observability-Daten bereitzustellen, um Entwicklungs- oder Betriebsprozesse zu optimieren.</p>



<p>Über diesen MCP-Server können Agenten außerdem vollständige oder teilweise Details aus Dashboards abfragen, die Metriken zur Systemleistung und Health-Daten aus verschiedenen Quellen kombinieren. Darüber hinaus lassen sich über den Grafana MCP-Server auch Informationen zu Datenquellen abrufen, weitere Monitoring-Systeme oder Details zu spezifischen Vorfällen abfragen.</p>



<p>Das Toolset ist dabei konfigurierbar, die Berechtigungen der Agenten können durch den Benutzer definiert werden. Darüber hinaus hat Grafana auch die Antwortstruktur seines MCP-Servers optimiert. Das soll die Nutzung des Kontextfensters minimieren und die Kosten für Token senken. Beispielsweise kann ein MCP-Client das <code>get_dashboard_property</code>-Tool aufrufen, um einen bestimmten Part eines Dashboards anhand seiner UID abzurufen.</p>



<h2 class="wp-block-heading">6. Terraform MCP-Server</h2>



<p>HashiCorp Terraform ist – <a href="https://www.computerwoche.de/article/3853753/opentofu-der-killer-fork.html" target="_blank">Alternativen</a> zum Trotz – weiterhin die erste Adresse, wenn es um Infrastructure as Code (IaC) geht. Entsprechend ist der <a href="https://github.com/hashicorp/terraform-mcp-server" target="_blank" rel="noreferrer noopener">offizielle MCP-Server</a> eine interessante Option, um Terraform-Konfigurationen über KI-Agenten zu generieren und zu managen. Der MCP-Server lässt sich dabei sowohl in die <a href="https://developer.hashicorp.com/terraform/registry/api-docs" target="_blank" rel="noreferrer noopener">Registry APIs</a> als auch in die <a href="https://developer.hashicorp.com/terraform/enterprise" target="_blank" rel="noreferrer noopener">Enterprise/HCP-Services</a> von Terraform integrieren. Das ermöglicht KI-Agenten etwa:</p>



<ul class="wp-block-list">
<li>Modul- und Anbieter-Metadaten abzufragen,</li>



<li>den Status von Workspaces zu überprüfen, und</li>



<li>Tasks (mit menschlicher Genehmigung) auszulösen.</li>
</ul>



<p>Ein Befehl wie “Generiere Terraform-Code für einen neuen Run” könnte so die <code>create_run</code>-Operation aufrufen, woraufhin der KI-Agent die Konfiguration validiert und plant, bevor er sie anwendet.</p>



<p>Der Terraform MCP-Server wird mit der Readme-Datei <a href="http://agents.md/" target="_blank" rel="noreferrer noopener">AGENTS.md</a> ausgeliefert. Diese erleichtert es Agenten, Tools zu interpretieren. Aktuell (Stand Dezember 2025) ist der Terraform MCP-Server ausschließlich für die lokale Nutzung verfügbar. Er ist ausdrücklich nicht für Remote- oder gehostete Deployments vorgesehen.</p>



<h2 class="wp-block-heading">7. GitLab MCP-Server</h2>



<p>Auch die GitLab-Plattform stellt – ihren Premium- und Ultimate-Kunden – einen <a href="https://docs.gitlab.com/user/gitlab_duo/model_context_protocol/mcp_server/" target="_blank" rel="noreferrer noopener">MCP-Server</a> bereit. Dieser befindet sich aktuell in der Beta-Phase und befähigt KI-Agenten dazu, Projetinformationen zu sammeln und Operationen über GitLab-APIs sicher auszuführen.  </p>



<p>Der GitLab MCP-Server erlaubt einige Statusänderungen, etwa Issues zu erstellen oder Merge Requests. Die anderen Funktionen dienen hauptsächlich der Datenabfrage – also etwa Informationen zu Issues, Merge-Anfragen, Commits, Diffs und Pipelines abzufragen. Enthalten ist zudem ein allgemeines Suchwerkzeug.</p>



<p>Die <a href="https://docs.gitlab.com/user/gitlab_duo/model_context_protocol/mcp_server/" target="_blank" rel="noreferrer noopener">Dokumentation</a> des GitLab MCP-Servers ist sehr ausführlich und enthält zahlreiche Beispiele für natürlichsprachliche Ausdrücke, die verarbeiten werden können. Der Server unterstützt zudem die dynamische Client-Registrierung über OAuth 2.0.</p>



<h2 class="wp-block-heading">8. Snyk MCP-Server</h2>



<p>Snyk bietet eine Security-Plattform für Entwickler an – und einen <a href="https://docs.snyk.io/integrations/snyk-studio-agentic-integrations">MCP-</a><a href="https://docs.snyk.io/integrations/snyk-studio-agentic-integrations" target="_blank" rel="noreferrer noopener">Server</a>. Dieser kann dazu genutzt werden, mit Hilfe von KI-Agenten (IaC-)Code, Open-Source-Abhängigkeiten, Container sowie SBOMs oder auch AIBOMs auf Schwachstellen zu scannen und diese zu beheben. Den Snyk MCP-Server zu integrieren, ist also dazu geeignet, Sicherheitsscans automatisch im Rahmen eines CI/CD-Workflows mit KI-Agenten durchzuführen. Diese Scans lassen sich sogar über andere MCP-Server hinweg koordinieren, beispielsweise indem Repository-Details über den GitHub MCP-Server abgerufen werden, bevor ein Snyk-Scan gestartet wird.</p>



<p>Ein Prompt wie “Scanne das Authentication-Microservice-Repo auf Sicherheitslücken” könnte einen Agenten anweisen, das Repository mit GitHub MCP zu lokalisieren und dann Snyk-Tools wie <code>snyk_sca_scan</code> oder <code>snyk_code_scan</code> nutzen, um bekannte Schwachstellen, geleakte Anmeldedaten und andere Risiken zu identifizieren.</p>



<p>Dieser MCP-Server wird lokal ausgeführt und verwendet die Snyk-CLI, um Befehle wie diese über authentifizierte API-Calls auszuführen. Das Unternehmen bietet keine gehostete Remote-Version seines MCP-Servers an.</p>



<h2 class="wp-block-heading">9. AWS MCP-Server</h2>



<p>Die Cloud-Hyperscaler haben besonders eifrig daran gearbeitet, schnell MCP-Server auf die Beine zu stellen, die sich in ihre Ökosysteme integrieren lassen. Amazon Web Services (AWS) hat beispielsweise Dutzende spezialisierter <a href="https://github.com/awslabs/mcp">MCP-Server</a> eingeführt, die KI-Agenten ermöglichen, mit sämtlichen Arten von AWS-Services zu interagieren. Einige davon werden als vollständig gemanagte Dienste angeboten, andere können hingegen nur lokal ausgeführt werden.</p>



<ul class="wp-block-list">
<li>So können KI-Agenten über den <a href="https://github.com/awslabs/mcp/blob/main/src/lambda-tool-mcp-server" target="_blank" rel="noreferrer noopener">Lambda Tool MCP-Server</a> beispielsweise Lambda-Funktionen auflisten und aufrufen.</li>



<li>Der <a href="https://github.com/awslabs/mcp/tree/main/src/s3-tables-mcp-server" target="_blank" rel="noreferrer noopener">AWS S3 Tables MCP-Server</a> lässt sich hingegen von einem Agenten nutzen, um S3-Buckets abzufragen oder neue Tabellen aus CSV-Dateien zu erstellen.</li>



<li>Der <a href="https://github.com/awslabs/mcp/tree/main/src/aws-knowledge-mcp-server" target="_blank" rel="noreferrer noopener">AWS Knowledge MCP-Server</a> verbindet Agenten mit den neuesten AWS-Dokumentationen, API-Referenzen und Architekturleitfäden.</li>
</ul>



<p>Eine Query an letztgenannten Knowledge-Server könnte etwa die Anweisung beinhalten, eine API-Referenz für das von AWS gemanagte Prometheus-Tool aufzurufen. Das würde die richtigen aktuellen Informationen liefern – optimiert für die Nutzung durch KI-Agenten.</p>



<h2 class="wp-block-heading">10. Pulumi MCP-Server</h2>



<p>Pulumi ist eine weitere beliebte IaC-Option – und hat ebenfalls einen <a href="https://www.pulumi.com/docs/iac/guides/ai-integration/mcp-server/" target="_blank" rel="noreferrer noopener">offiziellen MCP-Server</a> eingeführt. Dieser ermöglicht es KI-Agenten,</p>



<ul class="wp-block-list">
<li>Pulumi-Registries abzufragen,</li>



<li>auf Cloud-Ressourcen und -Infrastruktur zuzugreifen, und</li>



<li>Pulumi-Befehle auszuführen.</li>
</ul>



<p>Wie Entwickler diesen MCP-Server nutzen können, um einen Azure Kubernetes Service (AKS)-Cluster bereitzustellen, erklärt Pulumi beispielhaft in einer ausführlichen <a href="https://www.pulumi.com/blog/mcp-server-ai-assistants/#the-goal-provisioning-an-aks-cluster">Schritt-für-Schritt-Anleitung</a>. (fm)</p>



<p><strong>Dieser Artikel ist <a href="https://www.infoworld.com/article/4096223/10-mcp-servers-for-devops.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab baut 14 Prozent der Stellen ab und verlässt 22 Länder]]></title>
<description><![CDATA[Das Softwareunternehmen GitLab entlässt im Zuge einer Neuausrichtung 14 Prozent seiner Belegschaft und reduziert seine geografische Präsenz weltweit.

Tags: #GitLab | #Künstliche Intelligenz | #Stellenabbau]]></description>
<link>https://tsecurity.de/de/3570591/it-security-nachrichten/gitlab-baut-14-prozent-der-stellen-ab-und-verlaesst-22-laender/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570591/it-security-nachrichten/gitlab-baut-14-prozent-der-stellen-ab-und-verlaesst-22-laender/</guid>
<pubDate>Wed, 03 Jun 2026 20:53:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2026/02/GitLab-Quelle-logoboom-Shutterstock-2470680723-1920.jpg" class="attachment-full size-full wp-post-image" alt="GitLab" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2026/02/GitLab-Quelle-logoboom-Shutterstock-2470680723-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2026/02/GitLab-Quelle-logoboom-Shutterstock-2470680723-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2026/02/GitLab-Quelle-logoboom-Shutterstock-2470680723-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2026/02/GitLab-Quelle-logoboom-Shutterstock-2470680723-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2026/02/GitLab-Quelle-logoboom-Shutterstock-2470680723-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="GitLab baut 14 Prozent der Stellen ab und verlässt 22 Länder 1"></p>
    Das Softwareunternehmen GitLab entlässt im Zuge einer Neuausrichtung 14 Prozent seiner Belegschaft und reduziert seine geografische Präsenz weltweit.

<p>Tags: <a href="https://www.it-daily.net/thema/gitlab">#GitLab</a> | <a href="https://www.it-daily.net/thema/kuenstliche-intelligenz">#Künstliche Intelligenz</a> | <a href="https://www.it-daily.net/thema/stellenabbau">#Stellenabbau</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab cuts 14% of staff as it scales its platform to serve AI workloads]]></title>
<description><![CDATA[The company is reducing its workforce as it exits 22 countries, reduces management layers, and invests in its infrastructure to scale its platform.]]></description>
<link>https://tsecurity.de/de/3570040/it-nachrichten/gitlab-cuts-14-of-staff-as-it-scales-its-platform-to-serve-ai-workloads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570040/it-nachrichten/gitlab-cuts-14-of-staff-as-it-scales-its-platform-to-serve-ai-workloads/</guid>
<pubDate>Wed, 03 Jun 2026 17:03:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The company is reducing its workforce as it exits 22 countries, reduces management layers, and invests in its infrastructure to scale its platform.]]></content:encoded>
</item>
<item>
<title><![CDATA[Auditing GitLab: The CI/CD Kill Chain]]></title>
<description><![CDATA[Welcome to GoGatoZ — a purpose-built Go tool for GitLab CI/CD security auditing that can perform and automate the entire CI/CD kill chain along with everything those one-off scripts did and then some. 
The post Auditing GitLab: The CI/CD Kill Chain appeared first on Black Hills Information Securi...]]></description>
<link>https://tsecurity.de/de/3569452/it-security-nachrichten/auditing-gitlab-the-cicd-kill-chain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569452/it-security-nachrichten/auditing-gitlab-the-cicd-kill-chain/</guid>
<pubDate>Wed, 03 Jun 2026 14:08:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1280" height="720" src="https://www.blackhillsinfosec.com/wp-content/uploads/2026/06/cicd_header-1.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.blackhillsinfosec.com/wp-content/uploads/2026/06/cicd_header-1.png 1280w, https://www.blackhillsinfosec.com/wp-content/uploads/2026/06/cicd_header-1-500x281.png 500w, https://www.blackhillsinfosec.com/wp-content/uploads/2026/06/cicd_header-1-1024x576.png 1024w, https://www.blackhillsinfosec.com/wp-content/uploads/2026/06/cicd_header-1-768x432.png 768w" sizes="(max-width: 1280px) 100vw, 1280px"></p>
<p>Welcome to GoGatoZ — a purpose-built Go tool for GitLab CI/CD security auditing that can perform and automate the entire CI/CD kill chain along with everything those one-off scripts did and then some. </p>
<p>The post <a href="https://www.blackhillsinfosec.com/auditing-gitlab-the-ci-cd-kill-chain/">Auditing GitLab: The CI/CD Kill Chain</a> appeared first on <a href="https://www.blackhillsinfosec.com/">Black Hills Information Security, Inc.</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Auf ins „Zeitalter der Agenten“: GitLab feuert 14 Prozent der Angestellten]]></title>
<description><![CDATA[GitLab will sich umstrukturieren, Hierarchie-Ebenen streichen und fürs KI-Agenten-Zeitalter aufstellen. 14 Prozent der Belegschaft müssen gehen.]]></description>
<link>https://tsecurity.de/de/3569302/it-nachrichten/auf-ins-zeitalter-der-agenten-gitlab-feuert-14-prozent-der-angestellten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569302/it-nachrichten/auf-ins-zeitalter-der-agenten-gitlab-feuert-14-prozent-der-angestellten/</guid>
<pubDate>Wed, 03 Jun 2026 13:17:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[GitLab will sich umstrukturieren, Hierarchie-Ebenen streichen und fürs KI-Agenten-Zeitalter aufstellen. 14 Prozent der Belegschaft müssen gehen.]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4653: Starting the Habit of Reading]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.





Openreads is a privacy oriented and open source cross-platform app written in Flutter available for Android and iOS for keeping track of your books.


There are four lists provided so you won't get confused:


books you finished,
books you are...]]></description>
<link>https://tsecurity.de/de/3567899/podcasts/hpr4653-starting-the-habit-of-reading/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567899/podcasts/hpr4653-starting-the-habit-of-reading/</guid>
<pubDate>Wed, 03 Jun 2026 02:02:52 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>
<p><a href="https://github.com/mateusz-bak/openreads/releases/latest"><img alt="Get it on Github" src="https://raw.githubusercontent.com/mateusz-bak/openreads/master/doc/github/get-it-on-github.png" height="70"></a>
<a href="https://f-droid.org/en/packages/software.mdev.bookstracker" rel="nofollow"><img alt="Get it on F-Droid" src="https://camo.githubusercontent.com/5702f84de955c553161db1d6ce6fa114679af1dab8ec4037a7cbf9b0ff8b5c82/68747470733a2f2f6664726f69642e6769746c61622e696f2f617274776f726b2f62616467652f6765742d69742d6f6e2e706e67" data-canonical-src="https://fdroid.gitlab.io/artwork/badge/get-it-on.png" height="70"></a>
<a href="https://play.google.com/store/apps/details?id=software.mdev.bookstracker" rel="nofollow"><img alt="Get it on Google Play" src="https://camo.githubusercontent.com/1fe86ca33ef309648abb9f19c703e571dd7d97d5a9f64156ffa1f0ae3302b14a/68747470733a2f2f706c61792e676f6f676c652e636f6d2f696e746c2f656e5f75732f6261646765732f696d616765732f67656e657269632f656e5f62616467655f7765625f67656e657269632e706e67" data-canonical-src="https://play.google.com/intl/en_us/badges/images/generic/en_badge_web_generic.png" height="70"></a>
<a href="https://apps.apple.com/app/id6476542305" rel="nofollow"><img alt="Download on App Store" src="https://raw.githubusercontent.com/mateusz-bak/openreads/master/doc/app_store/download_on_app_store.png" height="70"></a></p>

<h3>Openreads is a privacy oriented and open source cross-platform app written in Flutter available for Android and iOS for keeping track of your books.</h3>
<a aria-label="Permalink: Openreads is a privacy oriented and open source cross-platform app written in Flutter available for Android and iOS for keeping track of your books." href="https://github.com/mateusz-bak/openreads#openreads-is-a-privacy-oriented-and-open-source-cross-platform-app-written-in-flutter-available-for-android-and-ios-for-keeping-track-of-your-books"></a>

<h4>There are four lists provided so you won't get confused:</h4>
<a aria-label="Permalink: There are four lists provided so you won't get confused:" href="https://github.com/mateusz-bak/openreads#there-are-four-lists-provided-so-you-wont-get-confused"></a>
<ul>
<li>books you finished,</li>
<li>books you are currently reading,</li>
<li>books you want to read later,</li>
<li>books you didn't finish.</li>
</ul>
<p>You can use custom tags and filter through them.</p>

<h4>A book can be added by:<a aria-label="Permalink: A book can be added by:" href="https://github.com/mateusz-bak/openreads#a-book-can-be-added-by"><svg data-component="Octicon" class="octicon octicon-link" viewbox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"></svg></a></h4>

<ul>
<li>looking it up in the Open Library database,</li>
<li>scanning its barcode,</li>
<li>adding its details manually.</li>
</ul>

<h4>You can also view some cool statistics!</h4>

<h3>Links:</h3>
<ul>
  <li><a href="https://www.sarna.net/wiki/Mercenary%27s_Star_(novel)">       Battletech: Mercenary's Star by William H. Keith</a></li>
  <li><a href="https://newsociety.com/book/permaculture-for-the-rest-of-us/">
      Permaculture for the Rest of Us by Jenni Blackmore</a></li>
  <li><a href="https://en.wikipedia.org/wiki/Piranesi_(novel)">
      Piranesi by Susanna Clarke</a></li>
  <li><a href="https://www.sarna.net/wiki/The_Price_of_Glory">
      Battletech: The Price of Glory by William H. Keith</a></li>
  <li><a href="https://hackerpublicradio.org/eps/hpr4653/The%20Urban%20Homestead%20by%20Kelly%20Coyne">
      The Urban Homestead by Kelly Coyne</a></li>
  <li><a href="https://www.sarna.net/wiki/The_Sword_and_the_Dagger">
      Battletech: The Sword and the Dagger by Ardath Mayhar</a></li>
  <li><a href="https://www.sarna.net/wiki/Warrior:_En_Garde">
      Battletch: Warrior En Garde by Michal A. Stackpole</a></li>
  <li><a href="https://en.wikipedia.org/wiki/Sisterhood_of_Dune">
      Sisterhood of Dune by Brian Herbert and Kevin J. Anderson</a></li>
  <li><a href="https://www.goodreads.com/book/show/26596785-fundamentals-of-the-wudang-sword-method---selected-translations-with-com">Fundamentals of       the Wudang Sword Method by Scott M. Rodell</a></li>
  <li><a href="https://www.sarna.net/wiki/Warrior:_Riposte">
      Battletech: Warrior Riposte by Michal A. Stackpole</a></li>
  <li><a href="https://www.goodreads.com/book/show/26087493-the-cardio-code">
      The Cardio Code by Kenneth Jay</a></li>
  <li><a href="https://en.wikipedia.org/wiki/Mentats_of_Dune">
      Mentats of Dune by Brian Herbert and Kevin J. Anderson</a></li>
  <li><a href="https://johnjeavons.org/books-and-videos/">
      How to Grow More Vegtables by John Jeavons</a></li>
</ul>
<p><a href="https://hackerpublicradio.org/eps/hpr4653/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v3.95.5]]></title>
<description><![CDATA[What's Changed

[INS-461] Add test to ensure new detectors are registered in defaults.go by @mustansir14 in #4915
[INS-455] Unify common logic in Atlassian Data Center detectors by @mustansir14 in #4907
fix(github): cache repo info under original URL on redirect by @kashifkhan0771 in #4958
Added ...]]></description>
<link>https://tsecurity.de/de/3566852/it-security-tools/v3955/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566852/it-security-tools/v3955/</guid>
<pubDate>Tue, 02 Jun 2026 18:19:07 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>[INS-461] Add test to ensure new detectors are registered in defaults.go by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mustansir14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mustansir14">@mustansir14</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4314890061" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4915" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4915/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4915">#4915</a></li>
<li>[INS-455] Unify common logic in Atlassian Data Center detectors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mustansir14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mustansir14">@mustansir14</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307817050" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4907" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4907/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4907">#4907</a></li>
<li>fix(github): cache repo info under original URL on redirect by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kashifkhan0771/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kashifkhan0771">@kashifkhan0771</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4429479859" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4958" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4958/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4958">#4958</a></li>
<li>Added GitLab OAuth Detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shahzadhaider1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shahzadhaider1">@shahzadhaider1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3897526835" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4729" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4729/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4729">#4729</a></li>
<li>Box Detector: Extract Subject ID for Analyzer Integration by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shahzadhaider1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shahzadhaider1">@shahzadhaider1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3979683905" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4761" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4761/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4761">#4761</a></li>
<li>[INS-346] SpectralOps Personal API Key Detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3993708741" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4770" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4770/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4770">#4770</a></li>
<li>[INS-335] Added AWS Appsync Detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052107264" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4803" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4803/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4803">#4803</a></li>
<li>fix(twilio): deduplicate matches to prevent O(N×M) result explosion by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kashifkhan0771/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kashifkhan0771">@kashifkhan0771</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4418402073" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4954" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4954/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4954">#4954</a></li>
<li>Automate corpora testing in CI by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mustansir14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mustansir14">@mustansir14</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348956148" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4927" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4927/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4927">#4927</a></li>
<li>Enable errcheck and staticcheck for golangci-lint v2 and resolve all issues by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amanfcp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amanfcp">@amanfcp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335817759" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4924" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4924/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4924">#4924</a></li>
<li>feat: add host, db and username to ExtraData for database detectors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariocj89/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariocj89">@mariocj89</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4172142501" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4849" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4849/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4849">#4849</a></li>
<li>Remove over speculation from Corpora CI workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mustansir14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mustansir14">@mustansir14</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4476119470" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4974" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4974/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4974">#4974</a></li>
<li>Fix line numbers for duplicate secrets within a chunk by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amanfcp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amanfcp">@amanfcp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310555727" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4910" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4910/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4910">#4910</a></li>
<li>Add feature flags for Pinecone, Cloudinary, and GitLab OAuth detectors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/camgunz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/camgunz">@camgunz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4438236689" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4961" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4961/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4961">#4961</a></li>
<li>Update Go security dependencies by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/cursor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cursor">@cursor</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535615521" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4986" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4986/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4986">#4986</a></li>
<li>Pin GitHub Actions to SHA digests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bryanbeverly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bryanbeverly">@bryanbeverly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535383560" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4985" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4985/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4985">#4985</a></li>
<li>Update CODEOWNERS: replace 5 slugs with scanning + integrations by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bryanbeverly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bryanbeverly">@bryanbeverly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4530341444" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4983" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4983/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4983">#4983</a></li>
<li>Added source config flags to sharepoint proto by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4470068596" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4972" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4972/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4972">#4972</a></li>
<li>[SCAN-795] HTML decoder: ASPX and entity-encoded HTML support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mustansir14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mustansir14">@mustansir14</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515100633" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4981" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4981/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4981">#4981</a></li>
<li>adds some debugging info for APKs and fixes issues parsing obfuscated APKs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/johannestaas-trufflesec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/johannestaas-trufflesec">@johannestaas-trufflesec</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542558175" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4991" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4991/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4991">#4991</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariocj89/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariocj89">@mariocj89</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4172142501" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4849" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4849/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4849">#4849</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/cursor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cursor">@cursor</a>[bot] made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535615521" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4986" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4986/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4986">#4986</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/johannestaas-trufflesec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/johannestaas-trufflesec">@johannestaas-trufflesec</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542558175" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4991" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4991/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4991">#4991</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/trufflesecurity/trufflehog/compare/v3.95.3...v3.95.5"><tt>v3.95.3...v3.95.5</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v3.95.4]]></title>
<description><![CDATA[What's Changed

[INS-461] Add test to ensure new detectors are registered in defaults.go by @mustansir14 in #4915
[INS-455] Unify common logic in Atlassian Data Center detectors by @mustansir14 in #4907
fix(github): cache repo info under original URL on redirect by @kashifkhan0771 in #4958
Added ...]]></description>
<link>https://tsecurity.de/de/3565105/it-security-tools/v3954/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565105/it-security-tools/v3954/</guid>
<pubDate>Tue, 02 Jun 2026 08:33:03 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>[INS-461] Add test to ensure new detectors are registered in defaults.go by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mustansir14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mustansir14">@mustansir14</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4314890061" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4915" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4915/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4915">#4915</a></li>
<li>[INS-455] Unify common logic in Atlassian Data Center detectors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mustansir14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mustansir14">@mustansir14</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307817050" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4907" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4907/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4907">#4907</a></li>
<li>fix(github): cache repo info under original URL on redirect by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kashifkhan0771/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kashifkhan0771">@kashifkhan0771</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4429479859" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4958" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4958/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4958">#4958</a></li>
<li>Added GitLab OAuth Detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shahzadhaider1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shahzadhaider1">@shahzadhaider1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3897526835" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4729" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4729/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4729">#4729</a></li>
<li>Box Detector: Extract Subject ID for Analyzer Integration by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shahzadhaider1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shahzadhaider1">@shahzadhaider1</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3979683905" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4761" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4761/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4761">#4761</a></li>
<li>[INS-346] SpectralOps Personal API Key Detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3993708741" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4770" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4770/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4770">#4770</a></li>
<li>[INS-335] Added AWS Appsync Detector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052107264" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4803" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4803/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4803">#4803</a></li>
<li>fix(twilio): deduplicate matches to prevent O(N×M) result explosion by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kashifkhan0771/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kashifkhan0771">@kashifkhan0771</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4418402073" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4954" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4954/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4954">#4954</a></li>
<li>Automate corpora testing in CI by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mustansir14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mustansir14">@mustansir14</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348956148" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4927" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4927/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4927">#4927</a></li>
<li>Enable errcheck and staticcheck for golangci-lint v2 and resolve all issues by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amanfcp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amanfcp">@amanfcp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335817759" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4924" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4924/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4924">#4924</a></li>
<li>feat: add host, db and username to ExtraData for database detectors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariocj89/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariocj89">@mariocj89</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4172142501" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4849" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4849/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4849">#4849</a></li>
<li>Remove over speculation from Corpora CI workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mustansir14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mustansir14">@mustansir14</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4476119470" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4974" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4974/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4974">#4974</a></li>
<li>Fix line numbers for duplicate secrets within a chunk by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amanfcp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amanfcp">@amanfcp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310555727" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4910" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4910/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4910">#4910</a></li>
<li>Add feature flags for Pinecone, Cloudinary, and GitLab OAuth detectors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/camgunz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/camgunz">@camgunz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4438236689" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4961" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4961/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4961">#4961</a></li>
<li>Update Go security dependencies by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/cursor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cursor">@cursor</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535615521" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4986" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4986/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4986">#4986</a></li>
<li>Pin GitHub Actions to SHA digests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bryanbeverly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bryanbeverly">@bryanbeverly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535383560" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4985" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4985/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4985">#4985</a></li>
<li>Update CODEOWNERS: replace 5 slugs with scanning + integrations by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bryanbeverly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bryanbeverly">@bryanbeverly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4530341444" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4983" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4983/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4983">#4983</a></li>
<li>Added source config flags to sharepoint proto by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MuneebUllahKhan222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MuneebUllahKhan222">@MuneebUllahKhan222</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4470068596" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4972" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4972/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4972">#4972</a></li>
<li>[SCAN-795] HTML decoder: ASPX and entity-encoded HTML support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mustansir14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mustansir14">@mustansir14</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515100633" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4981" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4981/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4981">#4981</a></li>
<li>adds some debugging info for APKs and fixes issues parsing obfuscated APKs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/johannestaas-trufflesec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/johannestaas-trufflesec">@johannestaas-trufflesec</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542558175" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4991" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4991/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4991">#4991</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariocj89/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariocj89">@mariocj89</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4172142501" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4849" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4849/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4849">#4849</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/cursor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cursor">@cursor</a>[bot] made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535615521" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4986" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4986/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4986">#4986</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/johannestaas-trufflesec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/johannestaas-trufflesec">@johannestaas-trufflesec</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542558175" data-permission-text="Title is private" data-url="https://github.com/trufflesecurity/trufflehog/issues/4991" data-hovercard-type="pull_request" data-hovercard-url="/trufflesecurity/trufflehog/pull/4991/hovercard" href="https://github.com/trufflesecurity/trufflehog/pull/4991">#4991</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/trufflesecurity/trufflehog/compare/v3.95.3...v3.95.4"><tt>v3.95.3...v3.95.4</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT-Security und KI: Kontrollverlust in Sekundenschnelle]]></title>
<description><![CDATA[Angreifer patchen in Sekunden, Unternehmen in Monaten. KI macht Cyberangriffe schneller, präziser und erschreckend skalierbar.AIBooth – shutterstock.com



Zwischen dem Bekanntwerden einer Schwachstelle und ihrem ersten Exploit vergehen heute oft nur noch Stunden. Die Mean Time to Exploit sinkt w...]]></description>
<link>https://tsecurity.de/de/3564866/it-security-nachrichten/it-security-und-ki-kontrollverlust-in-sekundenschnelle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564866/it-security-nachrichten/it-security-und-ki-kontrollverlust-in-sekundenschnelle/</guid>
<pubDate>Tue, 02 Jun 2026 06:07:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/08/shutterstock_2517566697.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Cybersecurity" class="wp-image-4038028" width="1024" height="585" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Angreifer patchen in Sekunden, Unternehmen in Monaten. KI macht Cyberangriffe schneller, präziser und erschreckend skalierbar.</p></figcaption></figure><p class="imageCredit">AIBooth – shutterstock.com</p></div>



<p>Zwischen dem Bekanntwerden einer Schwachstelle und ihrem ersten Exploit vergehen heute oft nur noch Stunden. Die Mean Time to Exploit sinkt weiter dramatisch – und dass sich dieses Zeitfenster weiter schließt, liegt vor allem an KI. Sie ermöglicht es Angreifern, Schwachstellen in Sekunden zu identifizieren und maßgeschneiderte Exploits in bisher unbekanntem Ausmaß zu skalieren. Diese Risikolage ist bekannt und wird trotzdem unterschätzt.</p>



<p>Anlass für die Experten des COMPUTERWOCHE-Roundtable zum Thema „IT- und Cloud-Security” über Angriffsvektoren, sinkende Reaktionszeiten und blinde Flecken in der Infrastruktur zu diskutieren. Vor allem in einem Punkt herrscht unter den Experten schnell Einigkeit: Was wir bisher erlebt haben, könnte erst der Anfang sein.</p>



<p>So sieht es auch Alexander Goller, Principal Solution Architect bei Illumio. Er blickt mit Sorge auf das, was noch kommt: „Der eigentliche Schock steht uns vermutlich erst noch bevor – mit den nächsten Modellgenerationen wie GPT-5.5 oder Claude Mythos.” Das sei eine Welle, die gerade erst anrollt. André Braun, VP for Central Europe bei GitLab, bestätigt diese Beobachtung und zeigt sich überrascht, wie wenig das in der Praxis angekommen zu sein: „Ich beobachte derzeit eine regelrechte Explosion neuer Angriffsvektoren.” Besonders erstaunlich sei, wie viele noch immer glauben, man könne Angriffe einfach erkennen, sobald sie stattfinden, und damit sei das Problem gelöst, anstatt in Prävention und agentische KI-Tools für eine stärker automatisierte Cybersicherheit zu investieren.</p>



<h2 class="wp-block-heading"><a></a>Ein Wettrennen gegen die Zeit</h2>



<p>Selbst wer Angriffe erkennt, steht vor einem fundamentalen Problem: der Zeit. „Die Time-to-Exploit sinkt gegen null – das wird passieren und ist schon passiert,” mahnt Alexander Goller. Das Problem sieht der Experte darin, dass die meisten Unternehmen nicht innerhalb von Stunden patchen könnten. „Oft reden wir über Tage, Wochen oder sogar Monate. Und in dieser Zeit bewegen sich Angreifer längst lateral durchs Netzwerk, nutzen Identitäten aus und breiten sich aus.” Detection sei zwar gut, aber hier sei die zeitliche Lücke das Problem. Auch Goller sieht deshalb die einzige Lösung darin, bereits von einem erfolgreichen Breach auszugehen: „Segmentierung, Isolation und saubere Netzwerk-Policies müssen vorher stehen – nicht erst dann, wenn der Angriff bereits läuft.”</p>



<p>Die Zeit fehlt aber nicht nur beim Patching, sondern auch bei der Prävention. Schwachstellen entstehen oft schon im Entwicklungsprozess, lange bevor ein Angriff stattfindet. Ein Grund, warum der Ansatz, Cybersecurity erst unter dem Druck eines laufenden Angriffs zu denken, zu kurz greift. Gefragt ist ein Umdenken entlang des gesamten Softwareentwicklungszyklus – und bei den Mitarbeitenden in den Unternehmen. Denn diese sind und bleiben ein großes Einfallstor.</p>



<h2 class="wp-block-heading"><a></a>Shadow AI und der Wildwuchs im Code</h2>



<p>Der eine aktiviert Office Copilot, die andere nutzt ChatGPT im Browser, der nächste ein nicht auditiertes Plugin: Viele Unternehmen haben kaum Transparenz darüber, welche KI-Systeme intern genutzt werden und vor allem welche Berechtigungen sie besitzen. KI-Systeme landen oft ohne Isolation, ohne Guardrails und ohne Kontrolle auf produktiven Systemen. Bequemlichkeit wird so zum neuen Angriffsvektor.</p>



<p>Das ist die eine Ebene des Problems. Die andere ist noch grundlegender: KI senkt die Hürde, Software zu bauen, auf null. Malte Vollandt, Chief Information Security Officer bei Logicalis, sieht darin ein strukturelles Sicherheitsrisiko: „Heute kann jeder innerhalb kürzester Zeit irgendeine App oder Automation bauen – oft ohne Freigaben, ohne Governance und ohne echtes Sicherheitsverständnis.” Und genau dadurch entstehen laut dem Experten neue Einfallstore für spätere Angriffe. Beide Entwicklungen zusammen erzeugen einen gefährlichen Wildwuchs an unkontrollierten Tools auf der einen, an fehleranfälligem Code auf der anderen Seite.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Studie “IT- und Cloud Security”: Sie können sich noch beteiligen!</strong></td></tr><tr><td>Zum Thema IT- und Cloud Security führt die COMPUTERWOCHE derzeit eine Multi-Client-Studie unter IT-Verantwortlichen durch. Haben Sie Fragen zu dieser Studie oder wollen Partner bei dieser Studie werden, helfen wir Ihnen unter <a href="mailto:research-sales@foundryco.com" target="_blank" rel="noreferrer noopener">research-sales@foundryco.com</a> gerne weiter. </td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading"><a></a>OT: Das vergessene Risiko</h2>



<p>Die Frage, die sich stellt: Mitarbeitende gewähren lassen und Sicherheitsrisiken in Kauf nehmen oder alles verbieten und die Produktivität bremsen? Einen einfachen Ausweg gibt es nicht. Eins ist allerdings sicher: Isolierte KI-Umgebungen mit definierten Zugriffsrechten und klaren Guardrails sind der einzig gangbare Weg. Doch während der Trend-Bereich KI gerade sehr viel Aufmerksamkeit bekommt, verbirgt sich ein besonders großes Risiko dort, wo niemand so genau hinschaut: in der Operational Technology.</p>



<p>Während IT-Systeme zumindest theoretisch schnell gepatcht werden können, ticken die Uhren dort völlig anders. Windows-XP-basierte Maschinensteuerungen hängen offen im Netzwerk, teilweise direkt aus dem Office erreichbar. Das ist im Mittelstand keine Ausnahme, sondern die Regel. Ein ernsthaftes Risiko, das schnell größer wird: Wenn KI-Agenten Schwachstellen in Sekunden identifizieren können, sind OT-Systeme das leichteste Ziel. “Die Systeme sind oft alt und schwer abzusichern – während die Angriffsmöglichkeiten unverändert bleiben,” gibt Malte Vollandt zu bedenken und richtet damit den Blick auf einen Bereich, der in vielen Sicherheitsstrategien noch zu kurz kommt. Denn besonders in der OT verstärke KI laut dem Experten vor allem die Seite der Angreifer, während die Defence kaum hinterherkommt. Christoph Klaus, Director Global Network Defense bei Myra Security, plädiert dabei für eine auf Schadensminimierung ausgerichtete Grundhaltung: „Wir gehen grundsätzlich davon aus, dass es irgendwann zu einem Breach kommen wird. Deshalb lautet der Ansatz: nicht nur Angriffe verhindern, sondern die Auswirkungen im Vorfeld so stark wie möglich eindämmen.”</p>



<h2 class="wp-block-heading"><a></a>Wer adaptiert, gewinnt</h2>



<p>Doch anstatt mit dem Nachrüsten zu beginnen, sieht die Realität in der Praxis häufig anders aus. Oft braucht es erst einen konkreten Vorfall, damit Unternehmen wirklich handeln. “Dann dient idealerweise ein anderes Unternehmen als Role Model. Erst dann, wenn ein Unternehmen wochenlang nicht produzieren oder handeln kann, entsteht im eigenen Umfeld schnell die Frage: ‚Was müssen wir tun, damit uns das nicht auch passiert?'” beschreibt Dominik Schön, Executive Senior Manager bei noris Network, den fehlenden Tatendrang. Die Geschäftsführung lässt er dabei nicht aus der Verantwortung und erwartet Bereitschaft, in Sicherheit zu investieren: “Wenn Risiken bewusst abgewogen und akzeptiert werden, ist das eine unternehmerische Entscheidung. Was jedoch nicht akzeptabel ist: wenn nach einem Vorfall Betroffenheit signalisiert wird, obwohl die IT über Jahre hinweg wiederholt auf bestehende Schwachstellen hingewiesen hat.”</p>



<p>Dabei verschiebt sich auch die grundlegende Frage, die die Branche stellen muss. Marc Meckel, Senior Manager Domain Consulting at Palo Alto Networks, sieht einen Paradigmenwechsel, der noch längst nicht überall angekommen zu sein scheint: „Früher sprach man vor allem über ‚AI for Security’. Heute müssen wir zunehmend auch über ‚Security for AI’ sprechen.” KI ist eben nicht nur Werkzeug – sie ist selbst Angriffsfläche. „AI kann selbst zum Risiko werden. Wenn automatisierte Entscheidungen kritische Prozesse beeinflussen, können Halluzinationen oder Fehlverhalten reale wirtschaftliche Schäden verursachen, die größer sind als die eigentliche Malware selbst”, warnt der Experte.</p>



<p>Die Diskussion macht deutlich: Es gibt keine einfachen Antworten. Weder lässt sich KI aus der Sicherheitsstrategie heraushalten, noch kann man ihr blind vertrauen. Unternehmen, die das ignorieren – sei es aus Unwissenheit, Bequemlichkeit oder weil die Geschäftsführung das Risiko unterschätzt – werden das spüren. Allerdings oft erst dann, wenn es zu spät ist.</p>



<p>Am Ende läuft es auf eine schlichte, aber unbequeme Erkenntnis hinaus, die André Braun auf den Punkt bringt: „Diejenigen, die das am schnellsten adaptieren, werden diesen Wettlauf gewinnen – unabhängig davon, auf welcher Seite sie stehen.”</p>



<h2 class="wp-block-heading">Teilnehmer des Round-Tables “IT- und Cloud Security 2026”</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/Andre-Braun-crossed-arms-Square-BRICK.jpg?quality=50&amp;strip=all&amp;w=1024" alt="André Braun, GitLab" class="wp-image-4178266" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>André Braun, GitLab:</p>
<p>„Wir müssen Cybersecurity entlang des gesamten Softwareentwicklungszyklus berücksichtigen. Die entscheidende Frage ist doch: Wie verhindern wir, dass diese Schwachstellen überhaupt erst entstehen? Genau hier kann agentische KI-Unterstützung künftig eine große Rolle spielen.”</p>
</figcaption></figure><p class="imageCredit">Mark Garner / GitLab Inc.</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/Alexander-Goller-Principal-Solutions-Architect-bei-Illumio_16.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Alexander Goller, Illumio" class="wp-image-4178259" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Alexander Goller, Illumio:</p>
<p>„Mit dem Angriffsspektrum eines AI-gestützten Angreifers werden eine vollständige CMDB, eine saubere SBOM und insgesamt eine klare Sicht auf die eigene IT-Landschaft essenziell. Hier sieht man in vielen Unternehmen nicht nur Lücken – oft ist diese Transparenz faktisch gar nicht vorhanden.“</p>
</figcaption></figure><p class="imageCredit">Illumio Inc.</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/03/Logicalis_mvollandt_foto_16.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Malte Vollant, Logicalis GmbH" class="wp-image-3842669" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Malte Vollant, Logicalis:</p>
<p>„In der Praxis braucht es häufig erst einen konkreten Sicherheitsvorfall, um ein Umdenken in Unternehmen auszulösen. Diese Dynamik wird durch den aktuellen Druck, KI schnell und flächendeckend einzusetzen, noch zusätzlich verstärkt. Wenn dieser Hype einmal greift, besteht die Gefahr, dass über Jahre mühsam etablierte Sicherheitsprinzipien – wie etwa Zero Trust – wieder aufgeweicht werden.”</p></figcaption></figure><p class="imageCredit">Logicalis GmbH</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/Christof-Klaus_Head-of-Global-Network-Defense_Myra-Security-Querformat.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Christof Klaus, Myra Security" class="wp-image-4178277" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Christof Klaus, Myra Security:</p>
<p>„Wenn lokal installierte Agents E-Mails scannen und eigenständig Aktionen ausführen dürfen, entsteht durch Bequemlichkeit ein neuer Angriffsvektor. Deshalb bleibt Awareness für mich zentral – nicht nur im Umgang mit Phishing-Links, sondern auch bei der Frage, welche Berechtigungen Software auf dem eigenen System tatsächlich besitzt.”</p>
</figcaption></figure><p class="imageCredit">Myra Security GmbH</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/Portrait-Dominik-Schon.png?w=1024" alt="Dominik Schön, noris network" class="wp-image-4178252" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Dominik Schön, noris network:</p>
<p>“Wenn man sich vorstellt, dass Angreifer heute nicht mehr manuell nach Schwachstellen suchen müssen, sondern KI-Agenten das in Sekunden übernehmen, wird klar, wie schnell solche Systeme identifiziert und ausgenutzt werden können – bis hin zur OT-Maschinensteuerung. Gerade im Kontext von NIS2 wird das zu einem ernsthaften Risiko und im Worst Case zu einem echten Albtraumszenario.”</p>
</figcaption></figure><p class="imageCredit">noris network AG</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/Thomas-Heinz-Senior-Manager-Solutions-Engineering-hochskaliert_16x9.png?w=1024" alt="Thomas Heinz, Okta" class="wp-image-4178274" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Thomas Heinz, Okta:</p>
<p>„Wir sollten KI-Agenten genauso behandeln wie menschliche Nutzer – ausgestattet mit digitalen Identitäten, klaren Guardrails, definiertem Zugriff und durchgängigem Identitätsmanagement. Das ist die Grundlage. Alles andere wäre fahrlässig.”</p>
</figcaption></figure><p class="imageCredit">Okta Inc.</p></div>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/08/Portrait_Marc-Meckel_Palo-Alto.png" alt="Marc Meckel, Palo Alto" class="wp-image-4043797" width="576" height="324" sizes="auto, (max-width: 576px) 100vw, 576px"><figcaption class="wp-element-caption"><p>Marc Meckel, Palo Alto:</p>
<p>„Viele Unternehmen sind sich der tatsächlichen Gefahren nicht bewusst und vertrauen darauf, als Angriffsziel schlicht uninteressant zu sein. Genau das ist jedoch ein Trugschluss. Mit KI lässt sich heute schnell und gezielt großer Schaden anrichten – unabhängig von Größe oder Branche. Die Annahme, die eigene Infrastruktur sei schon nicht betroffen, wiegt Unternehmen in falscher Sicherheit.”</p></figcaption></figure><p class="imageCredit">Palo Alto Networks (Germany) GmbH</p></div>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[BSI warnt vor GitLab-Schwachstelle CVE-2026-9807: Umgehen von Sicherheitsvorkehrungen]]></title>
<description><![CDATA[BONN / LONDON (IT BOLTWISE) – Das BSI hat am 28.05.2026 einen Sicherheitshinweis für GitLab veröffentlicht: Eine Schwachstelle mit CVE-2026-9807 kann von einem entfernten, authentisierten Angreifer genutzt werden, um Sicherheitsvorkehrungen zu umgehen. Obwohl die Risikostufe als niedrig (Risikoka...]]></description>
<link>https://tsecurity.de/de/3560806/it-security-nachrichten/bsi-warnt-vor-gitlab-schwachstelle-cve-2026-9807-umgehen-von-sicherheitsvorkehrungen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560806/it-security-nachrichten/bsi-warnt-vor-gitlab-schwachstelle-cve-2026-9807-umgehen-von-sicherheitsvorkehrungen/</guid>
<pubDate>Sun, 31 May 2026 14:52:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-gitlab-security-advisory-cve-2026-9807.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-gitlab-security-advisory-cve-2026-9807.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-gitlab-security-advisory-cve-2026-9807-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-gitlab-security-advisory-cve-2026-9807-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-gitlab-security-advisory-cve-2026-9807-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-gitlab-security-advisory-cve-2026-9807-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-gitlab-security-advisory-cve-2026-9807-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BONN / LONDON (IT BOLTWISE) – Das BSI hat am 28.05.2026 einen Sicherheitshinweis für GitLab veröffentlicht: Eine Schwachstelle mit CVE-2026-9807 kann von einem entfernten, authentisierten Angreifer genutzt werden, um Sicherheitsvorkehrungen zu umgehen. Obwohl die Risikostufe als niedrig (Risikokategorie 3) geführt wird, zeigt der CVSS-Base Score von 4,3, dass rechtzeitiges Patchen weiterhin wichtig ist. Betroffen sind […]</p>
<div><a href="https://www.it-boltwise.de/bsi-warnt-vor-gitlab-schwachstelle-cve-2026-9807-umgehen-von-sicherheitsvorkehrungen.html">... den vollständigen Artikel <strong>»BSI warnt vor GitLab-Schwachstelle CVE-2026-9807: Umgehen von Sicherheitsvorkehrungen«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/bsi-warnt-vor-gitlab-schwachstelle-cve-2026-9807-umgehen-von-sicherheitsvorkehrungen.html">BSI warnt vor GitLab-Schwachstelle CVE-2026-9807: Umgehen von Sicherheitsvorkehrungen</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Daily Summary 2026-05-30]]></title>
<description><![CDATA[40 posts were published in the last hour 18:2 : GitLab Patches Multiple Duo AI, DoS, and Authorization Flaws in Community and Enterprise Edition 17:32 : Fake Anthropic Sites Deliver Fileless Infostealer to Claude Code Users 17:32 : ShinyHunters Leaks…
Read more →
The post IT Security News Daily S...]]></description>
<link>https://tsecurity.de/de/3559738/it-security-nachrichten/it-security-news-daily-summary-2026-05-30/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559738/it-security-nachrichten/it-security-news-daily-summary-2026-05-30/</guid>
<pubDate>Sun, 31 May 2026 00:04:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>40 posts were published in the last hour 18:2 : GitLab Patches Multiple Duo AI, DoS, and Authorization Flaws in Community and Enterprise Edition 17:32 : Fake Anthropic Sites Deliver Fileless Infostealer to Claude Code Users 17:32 : ShinyHunters Leaks…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-05-30/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-05-30/">IT Security News Daily Summary 2026-05-30</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Criticized for Threatening Legal Action Against Security Researcher]]></title>
<description><![CDATA["A security researcher published a series of unpatched bugs in Microsoft products," reports TechCrunch, "along with code to exploit them." 

Microsoft's response to the researcher? "Threatening to take legal action and call the cops on them."




On Wednesday, Microsoft published a blog post crit...]]></description>
<link>https://tsecurity.de/de/3559585/it-security-nachrichten/microsoft-criticized-for-threatening-legal-action-against-security-researcher/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559585/it-security-nachrichten/microsoft-criticized-for-threatening-legal-action-against-security-researcher/</guid>
<pubDate>Sat, 30 May 2026 21:51:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["A security researcher published a series of unpatched bugs in Microsoft products," reports TechCrunch, "along with code to exploit them." 

Microsoft's response to the researcher? "Threatening to take legal action and call the cops on them."




On Wednesday, Microsoft published a blog post criticizing the researcher, who goes by the handle "Nightmare Eclipse," for publicly disclosing a series of bugs, including BlueHammer, RedSun, UnDefend, and YellowKey. The flaws affected products such as the Windows built-in antivirus engine Defender and the disk-encryption tool BitLocker.



 The core of Microsoft's complaints is that the researcher did not attempt to report the bugs so that the company could fix them. That would have been "responsible," as Microsoft's blog put it. The other side of the company's argument is that by publishing the details of the bugs and how to exploit them before they were patched, Nightmare Eclipse may have aided malicious hackers. Some of the vulnerabilities Nightmare Eclipse disclosed have since been used by hackers in real-world attacks, according to Microsoft, as well as the U.S. cybersecurity agency CISA. "Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity — coordinating as needed with law enforcement around the world," Microsoft wrote...


 In a series of blog posts published in the last couple of weeks — without providing many specific details — Nightmare Eclipse claimed to have been in contact with Microsoft, but the company allegedly mistreated them, including revoking access to their Microsoft Security Response Center account, the portal where researchers can report vulnerabilities to the tech giant. Nightmare Eclipse's implication was that they had no choice but to release the vulnerabilities publicly... The researchers published the bugs on open source repositories GitHub (owned by Microsoft) and GitLab. The researchers' accounts on those platforms have been banned... 

In response to this latest controversy with Nightmare Eclipse, countless researchers have shared their bad experiences reporting bugs to Microsoft.

 

Thanks to long-time Slashdot reader Elektroschock for sharing the news.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Microsoft+Criticized+for+Threatening+Legal+Action+Against+Security+Researcher%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F05%2F30%2F0559243%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F05%2F30%2F0559243%2Fmicrosoft-criticized-for-threatening-legal-action-against-security-researcher%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/26/05/30/0559243/microsoft-criticized-for-threatening-legal-action-against-security-researcher?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft fordert Koordinierte Schwachstellen-Offenlegung nach GitHub-Sperre]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Microsoft wehrt sich gegen öffentlich unkoordinierte Zero-Day-Veröffentlichungen und verlangt von Forschenden eine koordinierte Offenlegung nach dem CVD-Prinzip. Der Streit eskaliert offenbar, nachdem ein GitHub-Account eines Forschers entfernt wurde, obwohl die Exploit-Cod...]]></description>
<link>https://tsecurity.de/de/3559529/it-security-nachrichten/microsoft-fordert-koordinierte-schwachstellen-offenlegung-nach-github-sperre/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559529/it-security-nachrichten/microsoft-fordert-koordinierte-schwachstellen-offenlegung-nach-github-sperre/</guid>
<pubDate>Sat, 30 May 2026 20:49:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-microsoft-cvd-zeroday-github-gitlab.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-microsoft-cvd-zeroday-github-gitlab.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-microsoft-cvd-zeroday-github-gitlab-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-microsoft-cvd-zeroday-github-gitlab-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-microsoft-cvd-zeroday-github-gitlab-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-microsoft-cvd-zeroday-github-gitlab-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-microsoft-cvd-zeroday-github-gitlab-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Microsoft wehrt sich gegen öffentlich unkoordinierte Zero-Day-Veröffentlichungen und verlangt von Forschenden eine koordinierte Offenlegung nach dem CVD-Prinzip. Der Streit eskaliert offenbar, nachdem ein GitHub-Account eines Forschers entfernt wurde, obwohl die Exploit-Codes später auf GitLab auftauchten. Im Mittelpunkt stehen mehrere Lücken in Windows-Komponenten wie Defender und BitLocker sowie die Frage, wie schnell […]</p>
<div><a href="https://www.it-boltwise.de/microsoft-fordert-koordinierte-schwachstellen-offenlegung-nach-github-sperre.html">... den vollständigen Artikel <strong>»Microsoft fordert Koordinierte Schwachstellen-Offenlegung nach GitHub-Sperre«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/microsoft-fordert-koordinierte-schwachstellen-offenlegung-nach-github-sperre.html">Microsoft fordert Koordinierte Schwachstellen-Offenlegung nach GitHub-Sperre</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab Patches Multiple Duo AI, DoS, and Authorization Flaws in Community and Enterprise Edition]]></title>
<description><![CDATA[GitLab has released emergency security updates for both Community Edition (CE) and Enterprise Edition (EE), addressing multiple Duo AI, denial‑of‑service, and authorization flaws in recent versions of the platform. On May 27, 2026, GitLab shipped versions 19.0.1, 18.11.4, and 18.10.7…
Read more →...]]></description>
<link>https://tsecurity.de/de/3559475/it-security-nachrichten/gitlab-patches-multiple-duo-ai-dos-and-authorization-flaws-in-community-and-enterprise-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559475/it-security-nachrichten/gitlab-patches-multiple-duo-ai-dos-and-authorization-flaws-in-community-and-enterprise-edition/</guid>
<pubDate>Sat, 30 May 2026 20:06:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GitLab has released emergency security updates for both Community Edition (CE) and Enterprise Edition (EE), addressing multiple Duo AI, denial‑of‑service, and authorization flaws in recent versions of the platform. On May 27, 2026, GitLab shipped versions 19.0.1, 18.11.4, and 18.10.7…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/gitlab-patches-multiple-duo-ai-dos-and-authorization-flaws-in-community-and-enterprise-edition/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/gitlab-patches-multiple-duo-ai-dos-and-authorization-flaws-in-community-and-enterprise-edition/">GitLab Patches Multiple Duo AI, DoS, and Authorization Flaws in Community and Enterprise Edition</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab Patches Multiple Duo AI, DoS, and Authorization Flaws in Community and Enterprise Edition]]></title>
<description><![CDATA[GitLab has released emergency security updates for both Community Edition (CE) and Enterprise Edition (EE), addressing multiple Duo AI, denial‑of‑service, and authorization flaws in recent versions of the platform. On May 27, 2026, GitLab shipped versions 19.0.1, 18.11.4, and 18.10.7 as security ...]]></description>
<link>https://tsecurity.de/de/3559373/it-security-nachrichten/gitlab-patches-multiple-duo-ai-dos-and-authorization-flaws-in-community-and-enterprise-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559373/it-security-nachrichten/gitlab-patches-multiple-duo-ai-dos-and-authorization-flaws-in-community-and-enterprise-edition/</guid>
<pubDate>Sat, 30 May 2026 18:36:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GitLab has released emergency security updates for both Community Edition (CE) and Enterprise Edition (EE), addressing multiple Duo AI, denial‑of‑service, and authorization flaws in recent versions of the platform. On May 27, 2026, GitLab shipped versions 19.0.1, 18.11.4, and 18.10.7 as security patch releases for self‑managed instances. These builds fix several vulnerabilities across Duo AI […]</p>
<p>The post <a href="https://cybersecuritynews.com/gitlab-patches-duo-ai-dos-flaws/">GitLab Patches Multiple Duo AI, DoS, and Authorization Flaws in Community and Enterprise Edition</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab Patches Multiple Duo AI, DoS, and Authorisation Vulnerabilities]]></title>
<description><![CDATA[GitLab has released patch versions 19.0.1, 18.11.4, and 18.10.7 to fix seven security issues affecting GitLab CE and EE, including Duo AI workflow runner access control, a Wiki denial-of-service flaw, and several authorization bugs across GraphQL, Duo Workflows, Operations, Pipelines,…
Read more ...]]></description>
<link>https://tsecurity.de/de/3556744/it-security-nachrichten/gitlab-patches-multiple-duo-ai-dos-and-authorisation-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556744/it-security-nachrichten/gitlab-patches-multiple-duo-ai-dos-and-authorisation-vulnerabilities/</guid>
<pubDate>Fri, 29 May 2026 12:07:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GitLab has released patch versions 19.0.1, 18.11.4, and 18.10.7 to fix seven security issues affecting GitLab CE and EE, including Duo AI workflow runner access control, a Wiki denial-of-service flaw, and several authorization bugs across GraphQL, Duo Workflows, Operations, Pipelines,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/gitlab-patches-multiple-duo-ai-dos-and-authorisation-vulnerabilities/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/gitlab-patches-multiple-duo-ai-dos-and-authorisation-vulnerabilities/">GitLab Patches Multiple Duo AI, DoS, and Authorisation Vulnerabilities</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-05-29 12h : 5 posts]]></title>
<description><![CDATA[5 posts were published in the last hour 10:2 : The Deliverability Problem: How New Platforms Are Solving Inbox Placement 10:2 : GitLab Patches Multiple Duo AI, DoS, and Authorisation Vulnerabilities 10:2 : Infosecurity Europe: CyCOS Project Expands to Support…
Read more →
The post IT Security New...]]></description>
<link>https://tsecurity.de/de/3556742/it-security-nachrichten/it-security-news-hourly-summary-2026-05-29-12h-5-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556742/it-security-nachrichten/it-security-news-hourly-summary-2026-05-29-12h-5-posts/</guid>
<pubDate>Fri, 29 May 2026 12:07:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>5 posts were published in the last hour 10:2 : The Deliverability Problem: How New Platforms Are Solving Inbox Placement 10:2 : GitLab Patches Multiple Duo AI, DoS, and Authorisation Vulnerabilities 10:2 : Infosecurity Europe: CyCOS Project Expands to Support…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-05-29-12h-5-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-05-29-12h-5-posts/">IT Security News Hourly Summary 2026-05-29 12h : 5 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-9807 | GitLab Community Edition/Enterprise Edition up to 18.10.6/18.11.3/19.0.0 Access Token authorization (WID-SEC-2026-1727)]]></title>
<description><![CDATA[A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.10.6/18.11.3/19.0.0. It has been classified as problematic. This impacts an unknown function of the component Access Token Handler. The manipulation leads to incorrect authorization.

This vulnerability is trade...]]></description>
<link>https://tsecurity.de/de/3556711/sicherheitsluecken/cve-2026-9807-gitlab-community-editionenterprise-edition-up-to-18106181131900-access-token-authorization-wid-sec-2026-1727/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556711/sicherheitsluecken/cve-2026-9807-gitlab-community-editionenterprise-edition-up-to-18106181131900-access-token-authorization-wid-sec-2026-1727/</guid>
<pubDate>Fri, 29 May 2026 11:54:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gitlab:community_edition">GitLab Community Edition and Enterprise Edition up to 18.10.6/18.11.3/19.0.0</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This impacts an unknown function of the component <em>Access Token Handler</em>. The manipulation leads to incorrect authorization.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-9807">CVE-2026-9807</a>. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab Patches Duo AI, DoS, and Authorization Vulnerabilities]]></title>
<description><![CDATA[GitLab released security patch versions 19.0.1, 18.11.4, and 18.10.7 on May 27, 2026, addressing seven vulnerabilities, including a high-severity improper access control flaw in its Duo AI workflow runners across both Community Edition (CE) and Enterprise Edition (EE). The most critical fix addre...]]></description>
<link>https://tsecurity.de/de/3556700/it-security-nachrichten/gitlab-patches-duo-ai-dos-and-authorization-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556700/it-security-nachrichten/gitlab-patches-duo-ai-dos-and-authorization-vulnerabilities/</guid>
<pubDate>Fri, 29 May 2026 11:53:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GitLab released security patch versions 19.0.1, 18.11.4, and 18.10.7 on May 27, 2026, addressing seven vulnerabilities, including a high-severity improper access control flaw in its Duo AI workflow runners across both Community Edition (CE) and Enterprise Edition (EE). The most critical fix addresses CVE-2026-4868 (CVSS 8.2), an improper access control vulnerability in GitLab EE’s Duo AI workflow runners. Under […]</p>
<p>The post <a href="https://cyberpress.org/gitlab-patches-duo-ai-dos/">GitLab Patches Duo AI, DoS, and Authorization Vulnerabilities</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitLab Patches Multiple Duo AI, DoS, and Authorisation Vulnerabilities]]></title>
<description><![CDATA[GitLab has released patch versions 19.0.1, 18.11.4, and 18.10.7 to fix seven security issues affecting GitLab CE and EE, including Duo AI workflow runner access control, a Wiki denial-of-service flaw, and several authorization bugs across GraphQL, Duo Workflows, Operations, Pipelines, and authent...]]></description>
<link>https://tsecurity.de/de/3556693/it-security-nachrichten/gitlab-patches-multiple-duo-ai-dos-and-authorisation-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556693/it-security-nachrichten/gitlab-patches-multiple-duo-ai-dos-and-authorisation-vulnerabilities/</guid>
<pubDate>Fri, 29 May 2026 11:53:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>GitLab has released patch versions 19.0.1, 18.11.4, and 18.10.7 to fix seven security issues affecting GitLab CE and EE, including Duo AI workflow runner access control, a Wiki denial-of-service flaw, and several authorization bugs across GraphQL, Duo Workflows, Operations, Pipelines, and authentication endpoints. The company says self-managed installations should upgrade immediately. At the same time, […]</p>
<p>The post <a href="https://gbhackers.com/gitlab-patches-multiple-vulnerabilities-3/">GitLab Patches Multiple Duo AI, DoS, and Authorisation Vulnerabilities</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [niedrig] GitLab: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen]]></title>
<description><![CDATA[Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in GitLab ausnutzen, um Sicherheitsvorkehrungen zu umgehen.]]></description>
<link>https://tsecurity.de/de/3556599/it-security-nachrichten/neu-niedrig-gitlab-schwachstelle-ermoeglicht-umgehen-von-sicherheitsvorkehrungen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556599/it-security-nachrichten/neu-niedrig-gitlab-schwachstelle-ermoeglicht-umgehen-von-sicherheitsvorkehrungen/</guid>
<pubDate>Fri, 29 May 2026 11:08:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in GitLab ausnutzen, um Sicherheitsvorkehrungen zu umgehen.]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,28ms -->